macOS Gatekeeper Security Feature Bypassed to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Palo Alto Networks’ Unit 42 have uncovered significant vulnerabilities in macOS’s Gatekeeper security mechanism. This discovery reveals how certain third-party applications and even some of Apple’s native …

What is Lumma Stealer: Technical Details and Recent Fake CAPTCHA Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lumma Stealer, also known as LummaC2, is a widely known malware that first surfaced in 2022. Since then, it has steadily evolved, improving its techniques for stealing sensitive information. Lumma …

SAP NetWeaver Code Injection Vulnerability Let Attackers Upload Malicious Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in SAP NetWeaver AS Java has been uncovered, potentially allowing attackers to upload malicious files and execute unauthorized commands. The vulnerability, identified as CVE-2024-22127, affects the …

Sudanese Brothers Arrested in ‘AnonSudan’ Takedown

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The U.S. government on Wednesday announced the arrest and charging of two Sudanese brothers accused of running Anonymous Sudan (a.k.a. AnonSudan), a cybercrime business known for launching powerful distributed denial-of-service …

ANY.RUN’s Upgraded Linux Sandbox for Fast and Secure Malware Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN upgraded its Linux sandbox with features to enhance malware analysis. It now uses a stable Chrome browser for smoother interaction with suspicious websites, while lag in the process tree view is …

Multihomed Linux Devices Flaw Allows Spoof of Internal Communication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in multihomed Linux devices. It allows attackers to spoof and inject packets into internal communication streams via an external or public interface. Security researchers …

Iranian actors selling Login Access to Organizations networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

International security agencies have raised alarms about Iranian cyber actors compromising networks across critical infrastructure sectors. These actors reportedly sell login access to these networks, posing significant risks to global …

Trend Micro Cloud Edge Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Trend Micro has issued an urgent security bulletin warning users of a critical vulnerability in its Cloud Edge appliance that could allow remote attackers to execute arbitrary code without authentication. …

VMware HCX Vulnerability Let Attackers Inject Malicious SQL Queries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has disclosed a critical security vulnerability in its HCX platform, a key component for hybrid cloud extension solutions. The flaw, identified as CVE-2024-38814, allows authenticated users with non-administrator privileges …