QNAP Warns of OpenSSL Infinite Loop Vulnerability Affecting NAS Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Taiwanese company QNAP this week revealed that a selected number of its network-attached storage (NAS) appliances are affected by a recently-disclosed bug in the open-source OpenSSL cryptographic library. “An infinite …

Unpatched Java Spring Framework 0-Day RCE Bug Threatens Enterprise Web Apps Security

Blog WriterThe Hacker News - Original news source is thehackernews.com

A zero-day remote code execution (RCE) vulnerability has come to light in the Spring framework shortly after a Chinese security researcher briefly leaked a proof-of-concept (PoC) exploit on GitHub before deleting their account. According to cybersecurity …

CISA Warns of Ongoing Cyber Attacks Targeting Internet-Connected UPS Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Energy (DoE) are jointly warning of attacks against internet-connected uninterruptible power supply (UPS) devices by means of default …

Critical Sophos Firewall RCE Vulnerability Under Active Exploitation

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity firm Sophos on Monday warned that a recently patched critical security vulnerability in its firewall product is being actively exploited in real-world attacks. The flaw, tracked as CVE-2022-1040, is rated …

New Hacking Campaign by Transparent Tribe Hackers Targeting Indian Officials

Blog WriterThe Hacker News - Original news source is thehackernews.com

A threat actor of likely Pakistani origin has been attributed to yet another campaign designed to backdoor targets of interest with a Windows-based remote access trojan named CrimsonRAT since at …

Critical SonicOS Vulnerability Affects SonicWall Firewall Appliances

Blog WriterThe Hacker News - Original news source is thehackernews.com

SonicWall has released security updates to contain a critical flaw across multiple firewall appliances that could be weaponized by an unauthenticated, remote attacker to execute arbitrary code and cause a …