Multiple F5 Flaws Let Attackers Login With User Session & Cause DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two vulnerabilities have been discovered in BIG-IP, which are associated with Insufficient Session Fixation and Expired Pointer Dereference. These vulnerabilities have been assigned to CVE-2024-39809 and CVE-2024-39792, and the severity …

New APT Group BlindEagle Attacking Multiple Organizations Via Weaponized Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BlindEagle (APT-C-36) is a Latin American Advanced Persistent Threat group that has been active since 2018. It targets the governmental, financial, and energy sectors in Colombia, Ecuador, Chile, Panama, and …

Critical WordPress Plugin RCE Vulnerability Impacts 100k+ Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe security flaw has been discovered in GiveWP, a popular WordPress donation plugin with over 100,000 active installations. The vulnerability, classified as an unauthenticated PHP Object Injection leading to …

FBI Investigation Confirms that Iran Hackers Behind Trump Campaign Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Bureau of Investigation (FBI), in collaboration with the Office of the Director of National Intelligence (ODNI) and the Cybersecurity and Infrastructure Security Agency (CISA), has confirmed that Iranian …

PoC Exploit Released for Windows 0-Day Downgrade Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a pair of critical zero-day vulnerabilities in Microsoft Windows that enable a novel “downgrade attack.” The flaws tracked as CVE-2024-38202 and …

Microsoft Azure Kubernetes Services Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mandiant recently disclosed a critical vulnerability in Microsoft Azure Kubernetes Services (AKS) that could have allowed attackers to escalate privileges and access sensitive credentials within affected clusters. The vulnerability impacted …

New Kubernetes Vulnerability Allows Attackers to Access Clusters Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability tracked as CVE-2024-7646, has been uncovered in the widely used ingress-nginx Kubernetes controller. The flaw allows attackers to bypass annotation validation, poses a significant risk to Kubernetes …

FlightAware Data Leak Exposes Users’ Personal Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular flight-tracking website FlightAware discovered a configuration error that exposed the sensitive personal information of its users. The data leak included user IDs, passwords, and email addresses, and depending …