Windows Smart App Control Zero-Day (CVE-2024-38217) Exploited Since 2018 Finally Fixed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed a critical zero-day vulnerability affecting its Windows Smart App Control (SAC) and SmartScreen security features. This vulnerability was fixed at Microsoft’s September 2024 Patch Tuesday, which addressed …

Microsoft Security Update, 4 Zero-days & 79 Vulnerabilities Fixed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s September 2024 Patch Tuesday has addressed a significant number of security vulnerabilities, including four zero-day exploits and a total of 79 vulnerabilities across various products. This monthly update is …

Chinese Hackers Using Open Source Tools Like Nmap to Launch Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Natto Thoughts recently discovered that Chinese hackers have been actively abusing open-source tools like Nmap to launch cyber attacks. Nmap (Network Mapper) is a free and open-source …

Ivanti Endpoint Manager RCE Vulnerabilities Let Attackers Gain Server Access Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has issued security updates for its Endpoint Manager (EPM) 2024 and 2022 SU6 versions, addressing several critical and high-severity vulnerabilities that could lead to unauthorized access to the EPM …

Flipper Zero Firmware 1.0 Released After 3 Years of Development

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

After three years of intensive development, Flipper Zero has released its highly anticipated firmware version 1.0. This major milestone marks the completion of numerous features that have been in the …

Payment Gateway Platform SLIM CD Data Breach, 1.7 Million Users Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Slim CD, Inc., a prominent payment processing gateway for US and Canadian merchants, has disclosed a data breach affecting approximately 1.7 million users. The unauthorized access between August 17, …

BreachSeek, AI-Based Automated Multi-Platform Penetration Testing Tool

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI is significantly evolving penetration testing by enhancing automation, accuracy, and adaptability.  AI-driven tools can simulate sophisticated attack techniques, analyze vast datasets for vulnerabilities, and determine genuine threats from false …

Quad7 Botnet Operators Compromising Several Routers & VPN Appliances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Quad7 botnet (aka 7777 botnet, xlogin botnet) has gained attention for its use of compromised TP-Link routers to conduct attacks on Microsoft 365 accounts.  This botnet primarily employs password-spraying …