SapphireStealer: A .NET Malware Capable of Stealing Sensitive Data from Computers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SapphireStealer is an open-source information stealer that may be utilized for obtaining sensitive information, such as corporate credentials, which are frequently sold to other threat actors who utilize the access for …

North Korea’s Hacker Group Deploys Malicious Version of Python Package in PyPI Repository

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ReversingLabs spotted “VMConnect” in early August, a malicious supply chain campaign with two dozen rogue Python packages on PyPI. It’s been observed that these packages mimicked the following known open-source …

Junos OS Flaw Allows a Network-based Attacker to Launch DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Junos OS and Junos OS Evolved have been found to be vulnerable to a DoS (Denial of Service) condition, which an unauthenticated, network-based attacker can exploit. Juniper Networks has addressed …

AI Coding Platform Sourcegraph Breached Via Leaked Admin Access Token

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On August 30, 2023, a malicious actor gained unauthorized access to specific Sourcegraph(.)com data through a leaked admin access token. Sourcegraph is a code AI platform that makes it easy …

Hackers Abuse Windows Container Isolation Framework to Bypass Security Defences

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recently, cybersecurity researchers at Deep Instinct have asserted that hackers can exploit the Windows container isolation framework to bypass the security defenses and mechanisms of organizations. Containers revolutionize the way …

Cisco Unified Communications Products Flaw Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent discovery has highlighted a privilege escalation vulnerability within Cisco Unified Communications Products. This vulnerability was found during internal security testing. Cisco Unified Communications Manager (CUCM) and Cisco Unified …

No Coding, No Compromise: A Breach Prevention SaaS Security Guide – 2023

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With the growing trend of businesses transitioning their operations to cloud-based Software as a Service (SaaS) platforms, ensuring the security of these systems has become of utmost importance. Cybercriminals become …

Splunk IT Service Intelligence Injection Flaw Let Attacker Inject ANSI Codes in Log Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Splunk has been reported with a Unauthenticated Log injection vulnerability in the Splunk IT Service Intelligence (ITSI) product. This vulnerability exists in Splunk ITSI versions prior to 4.13.3 or 4.15.3.  …

Critical Flaw in Zip Libraries Let Attackers Abuse ZIP archives

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

According to recent reports, a number of vulnerabilities have been discovered in widely used ZIP libraries of Swift and Flutter. These packages are being utilized by numerous developers and applications, …