Apache Roller CSRF Vulnerability Let Attackers Escalate privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Roller team revealed a critical security update addressing a Cross-Site Request Forgery (CSRF) vulnerability that could allow attackers to escalate privileges. This vulnerability, present in previous versions of …

North Korean Posing as Recruiters to Attack Job Seekers Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target job seekers primarily for financial gain and to obtain sensitive personal information.  Many job seekers are vulnerable due to their enthusiasm for finding employment, which exposes them to …

Zendesk Email Spoofing Flaw Let Attackers Gain Access To Support Tickets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in Zendesk, a widely used customer service tool, has been exposed, allowing attackers to gain unauthorized access to sensitive support tickets of numerous Fortune 500 companies. The …

GitHub Enterprise Server Vulnerability Allows Authentication Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in GitHub Enterprise Server, posing significant security risks by allowing attackers to bypass authentication mechanisms. This flaw, tracked as CVE-2024-9487, was discovered in the …

87,000+ FortiOS Devices Vulnerable to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability affecting over 87,000 FortiOS devices has been discovered, leaving them exposed to potential remote code execution (RCE) attacks. The flaw, identified as CVE-2024-23113, impacts multiple versions …

HashiCorp Cloud Vault Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HashiCorp, a leading provider of cloud infrastructure automation software, has disclosed a critical security vulnerability in its Vault secret management platform. The flaw, identified as CVE-2024-9180, could allow privileged attackers …

OpenAI Confirms Hackers Using ChatGPT to Create Sophisticated Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has confirmed that hackers are exploiting its ChatGPT artificial intelligence model to create malware and conduct cyberattacks. The AI research company released a report detailing over 20 instances where …

PureLogs, Low Cost Infostealer Attacking Chrome Browser

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The world of cyber threats is intricate and ever-changing. Threat actors are always improving their methods, and new strains of infostealer malware frequently surface. Infostealers are very easy to operate, …

Mamba Toolkit Abuses 2FA In Sophisticated Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attacks are stealthy cyber threats where threat actors impersonate reputable entities to trick individuals into revealing sensitive information (“passwords” or “financial details”).  These types of attacks are executed via …

New Exclusive Report Reveals Administrators Of BreachForums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The administrators behind the infamous dark web data breach forum, BreachForums, have been exposed. Established in March 2022, BreachForums quickly became a hub for cybercriminals trading in stolen data. The …