20 Years Old macOS Vulnerability Allow Attackers To Gain Root Access Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher, Gergely Kalman, uncovered a severe macOS vulnerability privilege escalation in Apple’s MallocStackLogging framework, which had remained undetected for approximately 20 years. The bug, tracked as CVE-2023-32428, was …

VMware Aria Operations Vulnerabilities Allow Privilege Escalation & XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware, a leading cloud computing and virtualization software provider, has disclosed multiple critical vulnerabilities in its Aria Operations product. The most severe flaws could allow attackers to escalate privileges to …

Interpol Arrested 1,000+ Cybercriminals and Dismantled 130,000+ Malicious Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A joint operation by INTERPOL and AFRIPOL has led to the arrest of 1,006 suspects and the dismantling of 134,089 malicious infrastructures across 19 African countries. The operation, codenamed Operation …

Windows Zero-days & Firefox Vulnerability Exploited by RomCom Hackers Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian-aligned hacking group RomCom has been discovered exploiting two critical zero-day vulnerabilities affecting Mozilla Firefox and Windows systems in a sophisticated cyber-espionage campaign. The vulnerabilities allowed attackers to execute malicious …

Hackers Weaponizing Typosquatted Libraries To Inject SSH Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack targeting npm users has been recently uncovered by the Socket’s threat research team in a concerning development for the open-source community. The threat actor, identified as “sanchezjosephine180,” …

Kansas City Man Charged for Hacking Computer Systems of Health Clubs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A 31-year-old Kansas City man has been indicted on federal charges for allegedly hacking into the computer systems of a health club chain and a nonprofit organization. Nicholas Michael Kloster …

Palo Alto certification validation Flaw Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has been discovered in Palo Alto Networks’ GlobalProtect app, potentially allowing attackers to escalate privileges on affected systems. The flaw, which stems from insufficient certification validation, …

WordPress Plugin Flaw Exposes 200,000 WordPress Sites To Hacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability was discovered on October 30th, 2024 in the Anti-Spam by CleanTalk WordPress plugin, potentially affecting over 200,000 active installations. This flaw allows unauthenticated attackers to install and …

CISA Details Red Team’s Activity Including TTPs & Network Defense

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A comprehensive Red Team Assessment (RTA) was conducted recently by the Cybersecurity and Infrastructure Security Agency (CISA) on a critical infrastructure organization in the United States. This assessment, which spanned …