GitLab Patch XSS Vulnerability that Lets Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released new Community Edition (CE) and Enterprise Edition (EE) versions to address multiple vulnerabilities. Among these, a high-severity cross-site scripting (XSS) vulnerability has garnered particular attention due to …

BIND DNS Vulnerability Lets Attackers Flood Server With DNS Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Internet Systems Consortium (ISC) has released critical security advisories addressing multiple vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 software, a cornerstone of the Domain Name System (DNS) …

Russian Malware Cuts Off Heaters In 600 Apartments During Zero Temperatures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FrostyGoop represents a significant advancement in industrial control systems (ICS) malware, being the ninth ICS-specific threat and the first to leverage Modbus TCP communications for directly impacting Operational Technology (OT).  …

Tag-100 Hacker Group Exploiting Citrix NetScaler & F5 BIG-IP Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat actor, TAG-100, has emerged and is actively targeting government and private sector organizations worldwide and initiates its attacks by exploiting vulnerabilities in internet-facing devices, such as Citrix …

Critical Docker Vulnerability Lets Hacker Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Docker Engine has been discovered, potentially allowing attackers to bypass authentication and gain unauthorized access to systems. The vulnerability, identified as CVE-2024-41110, affects multiple versions …

ERP Provider Exposes 769 Million Records, Including API Keys And Email Addresses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive data breach involving ClickBalance, one of Mexico’s largest Enterprise Resource Planning (ERP) technology providers, has been uncovered by cybersecurity researcher Jeremiah Fowler. The breach exposed a staggering 769,333,246 …

Stargazers Ghost: Network of GitHub Accounts Used to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Check Point have uncovered a sophisticated network of GitHub accounts, dubbed the Stargazers Ghost Network, that has been distributing malware and phishing links since at least June …