Critical Vulnerabilities in Ivanti CSA Let Attackers Bypass Admin Web Console Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has released crucial security updates to address multiple vulnerabilities in its Cloud Services Application (CSA) software, including critical flaws that could allow attackers to bypass authentication and execute remote …

Chrome Security Update, Patch for 3 High-severity Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a critical security update for its Chrome browser, addressing three high-severity vulnerabilities that could potentially expose users to significant risks. The latest update, version 131.0.6778.139/.140 for Windows …

Windows Common Log File System Zero-day (CVE-2024-49138) Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new high-severity security vulnerability, CVE-2024-49138, has been identified in the Windows Common Log File System (CLFS) Driver as a zero-day that was exploited in the wild. Microsoft confirmed that …

Microsoft December 2024 Patch Tuesday – 71 Vulnerabilities Fixed, Including 1 Zero-day & 30 RCEs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released a security as part of the December Patch Tuesday that addressed 72 vulnerabilities, including 30 classified as critical Remote Code Execution (RCE) vulnerabilities. These fixes are crucial for …

Microsoft 365 Down: Web Apps and Admin Center are Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is investigating a widespread outage that disrupted access to Microsoft 365 web applications and the Microsoft 365 admin center earlier today. The issue affected users attempting to connect to …

Cleo Zero-Day RCE Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability (CVE-2024-50623) in Cleo’s file transfer products Harmony, VLTrader, and LexiComis being actively exploited by threat actors, cybersecurity researchers have warned. The flaw, stemming from an unrestricted …

Chinese Hackers Using Visual Studio Code Tunnels & RDP To Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated cyber-espionage campaign dubbed ‘Operation Digital Eye,’ suspected Chinese state-backed hackers targeted major business-to-business IT service providers across Southern Europe between late June and mid-July 2024. The attackers …

RedLine Malware Weaponizing Pirated Corporate Softwares To Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An ongoing RedLine info-stealer effort targets Russian-speaking entrepreneurs using unlicensed corporate software copies to automate business operations. Attackers were distributing a malicious version of the HPDxLIB activator to business process …

SAP NetWeaver Vulnerabilities Let Attackers Upload Malicious PDF Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SAP has issued a crucial security update addressing multiple high-severity vulnerabilities in its NetWeaver Application Server for Java, specifically within the Adobe Document Services component. The patch, released on December …