Netgear WiFi Extender Vulnerability Let Attackers Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered critical vulnerabilities in several popular Netgear WiFi extender models that could allow attackers to execute malicious commands on affected devices. The flaws, tracked as CVE-2024-35518 and …

Next.js Image Optimization Vulnerability Let Attackers Exhaust CPU Resources

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the popular React framework Next.js, potentially allowing attackers to exhaust CPU resources through its image optimization feature. The flaw, identified on October …

Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Splunk has released patches for several high-severity vulnerabilities in its Enterprise product that could allow attackers to execute remote code on affected systems. The vulnerabilities impact multiple versions of Splunk …

New Supply Chain Attack Leveraging Entry Points in PyPI, npm, Ruby Gems & NuGet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has been identified, leveraging entry points in popular open-source package repositories, including PyPI (Python), npm (JavaScript), Ruby Gems, and NuGet (.NET). This attack vector poses …

CoreWarrior Malware Attacking Windows Machines With Self-replication Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malware targeting Windows machines continues to be a significant threat. While these threats could be in various forms like viruses, worms, and ransomware. These malicious programs can infiltrate systems via …

OilRig Hackers Exploiting Microsoft Exchange Servers To Steal Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OilRig hackers (aka Earth Simnavaz, APT34, OilRig) is a cyber espionage group that was linked to “Iranian” interests. This APT group primarily targets energy, governmental, and critical infrastructure sectors. Cybersecurity …

Popular Java Framework pac4j Vulnerable To RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in the popular Java security framework, pac4j, specifically affecting versions prior to 4.0. This vulnerability tracked as CVE-2023-25581, allows for remote code execution …

TrickMo Malware Attacking Android Devices To Steal Unlock Patterns & PINs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TrickMo is a sophisticated malware that emerged as a “banking Trojan”, and this malware is designed to steal “financial credentials” and “personal information.” Besides this, it has a history of …

Gmail Users Beware Of AI Scam that Takeovers Your Gmail Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new scam targeting Gmail users has emerged, using artificial intelligence to trick victims into surrendering control of their accounts. This “super realistic AI scam call” combines fake account …