New Critical and High-Severity SQL Injection Flaw in MOVEit Transfer Software

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical-severity SQL injection flaw and two other high-severity vulnerabilities have been fixed in MOVEit Transfer, the software at the focus of the recent widespread Clop ransomware outbreaks. Progress Software detected SQL injection …

Top Suspect in 2015 Ashley Madison Hack Committed Suicide in 2014

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

When the marital infidelity website AshleyMadison.com learned in July 2015 that hackers were threatening to publish data stolen from 37 million users, the company’s then-CEO Noel Biderman was quick to …

VMware SD-WAN Vulnerability Let Attacker Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An authentication bypass vulnerability exists in VMware SD-WAN (Edge). Upon successful exploitation, unauthorized attackers gain access to the application’s Diagnostic package under VMware SD-WAN Management. “An unauthenticated attacker can download …

Beware of New Phishing Attacks Mimicking Booking.com and Airbnb

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Beware of attackers masquerading as well-known vacation rental websites such as Airbnb and Booking.com. Scammers that prey on tourists for Phishing Attacks are more active once the summer travel season …

Charming Kitten Hacker Group Uses Weaponized Word Documents to Deploy Powershell Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Charming Kitten, also known as TA453, is an Iranian government-based cyberwarfare group that has conducted several attacks since 2017. In the middle of May 2023, these threat actors sent a …