Jfrog Artifactory Flaw Let Attackers Poison Artifact Caches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability identified as CVE-2024-6915 has been discovered in JFrog Artifactory, a widely used repository manager. This flaw, categorized under CWE-20 (Improper Input Validation), allows attackers to poison artifact …

Researchers Jailbreaked Text-To-Image LLM Models Using Atlas Agent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LLM agents, combining large language models with memory and tool usage, have shown promise in diverse domains. While successful in fields like software engineering and industrial automation, their potential in …

Apache OFBiz Zero-Day Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Apache OFBiz, an open-source enterprise resource planning (ERP) system, has been discovered that could allow unauthenticated attackers to execute arbitrary code remotely. The flaw, tracked …

Bloody Wolf Attacking Organizations With $80 Malware From Underground Market

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity experts have uncovered a series of attacks targeting organizations in Kazakhstan by a threat actor dubbed “Bloody Wolf.” The group utilizes STRRAT, an inexpensive but potent malware available on …

APT41 Hackers Attacking Research Institute with ShadowPad and Cobalt Strike

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Talos has unearthed a sophisticated cyber-espionage campaign targeting a Taiwanese government-affiliated research institute. The attack, attributed to the notorious Chinese hacking group APT41, involved the deployment of the ShadowPad …

Rockwell Automation Devices Flaw Let Hackers Gain Unauthorized Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Rockwell Automation’s ControlLogix and GuardLogix controllers has been discovered. This vulnerability could potentially allow attackers to bypass security measures and gain unauthorized access to industrial …

DNSSEC+ – Secure Model That Addresses Security And Downsides Of DNSSEC

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The communication between DNS recursive resolvers and authoritative nameservers is largely unsecured, making it susceptible to on-path and off-path attacks. Though many security proposals have been put forward, they often …

4.6 Million Voter Database & Election Documents Exposed Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researcher Jeremiah Fowler discovered and reported to VpnMentor about 13 non-password-protected databases containing 4.6 million documents, including sensitive voter records and election-related documents. This breach raises significant concerns about …

Threat Actor Groups Using Leaked Ransomware Variants To Launch Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware operators often acquire malware through purchases on the dark web, group affiliations, and leaked source codes rather than developing themselves. They target victims by using common tools and modified …