Citrix Virtual Apps & Desktops Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered vulnerability in Citrix Virtual Apps and Desktops is being actively exploited in the wild. The flaw, which allows for unauthenticated remote code execution (RCE), poses a significant …

PostgreSQL Security Update, Patch For Multiple Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The PostgreSQL Global Development Group has released a critical security update for all supported versions of PostgreSQL. All the supported versions of PostgreSQL includes 17.1, 16.5, 15.9, 14.14, 13.17, and …

Sonatype Nexus Repository Manager Hit By RCE & XSS Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sonatype has disclosed two significant vulnerabilities in a critical security update released on November 13, 2024, affecting their Nexus Repository Manager 2.x versions. The two vulnerabilities pose serious risks to …

Samba AD Vulnerability Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Samba Active Directory (AD) implementations has been discovered that could allow attackers to escalate privileges and potentially take over entire domains. The flaw, tracked as CVE-2023-3961, …

BrazenBamboo APT Exploiting FortiClient Zero-Day to Steal User Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber espionage campaign conducted by a threat actor known as BrazenBamboo. The group is exploiting an unpatched vulnerability in Fortinet’s FortiClient VPN software for Windows to steal user …

T-Mobile Hacked – China Launched Massive Cyber Attack on U.S. Telecom Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers with ties to Chinese intelligence infiltrated multiple U.S. and international telecom companies, including T-Mobile, in a prolonged cyber-espionage campaign aimed at high-value intelligence targets, sources familiar with the matter …

NSO Continuously Used Pegasus WhatsApp Spyware Even After Blocked

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The NSO Group, an Israeli surveillance technology firm, is facing significant legal challenges after a U.S. court filing revealed damning admissions regarding the company’s involvement in hacking WhatsApp servers. NSO’s …

OpenBSD Double-Free Vulnerability Let Attackers Exploit NFS Client & Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenBSD has released an important bug fix addressing a potential double-free vulnerability within its Network File System (NFS) client and server implementation. OpenBSD is a Unix-like operating system renowned for …

Top 10 Best Password Managers in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Password managers help to securely store and manage passwords, enhancing security and simplifying access across various platforms. Top password management solutions make password protection easy and effective for online security. …

DHCP Vulnerability in TP-Link Lets Attackers Takeover Routers Remotely – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been found in TP-Link VN020-F3v(T) routers with firmware version TT_V6.2.1021 Attackers could take over the devices remotely, leading to DoS attacks or even RCE attacks. …