Critical 0-Click RCE in Windows TCP/IP Stack Impacts All Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released an urgent security update to address a critical remote code execution vulnerability in the Windows TCP/IP stack. The flaw tracked as CVE-2024-38063, affects all supported Windows and …

Zoom Critical Vulnerabilities Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zoom Video Communications has disclosed several critical vulnerabilities affecting its Workplace Apps, SDKs, and Rooms Clients. These vulnerabilities, identified in multiple security bulletins, potentially allow attackers to escalate privileges on …

Microsoft Patches 6 Zero-Days That Threat Actors Actively Exploiting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released its August 2024 Patch Tuesday update to address 90 security vulnerabilities. The update includes fixes for six zero-day flaws actively exploited across various products and services, such …

Operation Uncle Scam – AI-Powered Phishing Attack Steals Microsoft Dynamics 365 Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Perception Point have uncovered a sophisticated phishing campaign, dubbed “Uncle Scam.” In this AI-powered campaign, threat actors impersonate U.S. government agencies to send fraudulent tender invitations to …

0-Click Outlook Vulnerability Triggered RCE When Email is Opened – Technical Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Morphisec researchers have recently uncovered a critical vulnerability in Microsoft Outlook, identified as CVE-2024-30103. It can execute malicious code as soon as an email is opened. We will explore the …

New Banshee MacOS Stealer Attacking Users to Steal Keychain Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

International authorities have successfully seized the servers associated with the notorious Dispossessor ransomware group. This operation marks a critical step in combating ransomware attacks that have plagued individuals, businesses, and …

Zabbix Server Vulnerability Lets Attacker Execute Arbitrary Code Via Ping Script

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability, identified as CVE-2024-22116, has been patched in Zabbix, a popular monitoring solution. The vulnerability allowed an administrator with restricted permissions to execute arbitrary code via the …

Post-Exploitation Tactics Hackers Use After Compromising Ivanti, Fortigate VPN Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Akamai researchers have delved into the often-overlooked threat of VPN post-exploitation, highlighting techniques that threat actors can use to escalate their intrusion after compromising a VPN server. The study focuses …

Beware Of Malicious Typosquat Package That Steals Your Secret Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers often target the Solana Python API ecosystem to exploit vulnerabilities in decentralized applications, access private keys, or manipulate transactions on the Solana blockchain. Recently the Solana Python API ecosystem …