GitLab Urges Organizations To Patch For Authentication Bypass Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab, the popular DevOps platform, has issued a critical security advisory urging organizations to immediately patch their self-managed GitLab instances to address a severe authentication bypass vulnerability. The flaw tracked …

Google Password Manager PIN Feature Let Users Sync Passkeys Across Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has unveiled a new feature in its Password Manager that allows users to sync passkeys across multiple devices. This update promises enhanced security and convenience, making accessing favorite sites …

UNC1860 Hackers Use Specialized Tools & Backdoors To Penetrate Victims’ Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mandiant exposed the activities of UNC1860, a sophisticated Iranian state-sponsored cyber group. This group, believed to be affiliated with Iran’s Ministry of Intelligence and Security (MOIS), has been actively infiltrating …

Operation Kaerb, Masterminds Behind iserver Phishing-As-A-Service Platform Arrested

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Operation Kaerb resulted in the arrest of 17 cybercriminals in Argentina, Chile, Colombia, Ecuador, Peru, and Spain. This international operation is coordinated by Europol, Group-IB, and Ameripol. These individuals were …

Ivanti Warns of CSA Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has warned about a critical vulnerability in its Cloud Services Appliance (CSA) 4.6, which has been actively exploited in attacks. The vulnerability, identified as CVE-2024-8963, is a path traversal …

Why Cynet’s All-in-One Platform Is a Game-Changer for MSPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Managed Services Providers (MSPs) are increasingly looking to provide cybersecurity services based on heightened demand from their current clients. Though the revenue potential is lucrative, the road for many MSPs …

Threat Actors Weaponized Splinter Post-Exploitation Red Team Tool Discovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Unit 42 cybersecurity researchers have identified a new post-exploitation red team tool, Splinter, using Advanced WildFire’s memory scanning tools. This tool, developed in Rust, a programming language known for its …

Attention Travelers! Beware of Booking.com Themed Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attacks are a type of social engineering scam where attackers trick victims into revealing sensitive information.  In phishing attacks, the attackers often impersonate trusted entities like banks or companies …