Atlassian Bamboo Data Center & Server Flaw Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian has issued a security advisory for a newly discovered high-severity vulnerability affecting its Bamboo Data Center and Server products. The vulnerability, identified as CVE-2024-21689, has a CVSS score of 7.6, …

New UULoader Attacking Users Via Weaponized PDF Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious .msi installers disguised as legitimate software actively target Korean and Chinese speakers by dubbing UULoader, contain a loader likely developed by a Chinese speaker, and evade detection by most …

Outlook Zero-click RCE Vulnerability Technical Details Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Morphisec have uncovered critical technical details about the recently discovered zero-click remote code execution (RCE) vulnerability in Microsoft Outlook, identified as CVE-2024-38021. This vulnerability poses a significant security …

Android & iOS Users Targeted with New Phishing Attack Using PWAs & WebAPKs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel type of phishing attack has been discovered, targeting both Android and iOS users. This attack combines traditional social engineering techniques with the use of Progressive Web Applications (PWAs) …

Apache DolphinScheduler Vulnerability Let Hackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in Apache DolphinScheduler, a popular open-source workflow orchestration platform. This security flaw, designated as CVE-2024-43202, allows hackers to execute remote code, posing a significant …

Multiple F5 Flaws Let Attackers Login With User Session & Cause DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two vulnerabilities have been discovered in BIG-IP, which are associated with Insufficient Session Fixation and Expired Pointer Dereference. These vulnerabilities have been assigned to CVE-2024-39809 and CVE-2024-39792, and the severity …

New APT Group BlindEagle Attacking Multiple Organizations Via Weaponized Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BlindEagle (APT-C-36) is a Latin American Advanced Persistent Threat group that has been active since 2018. It targets the governmental, financial, and energy sectors in Colombia, Ecuador, Chile, Panama, and …

Critical WordPress Plugin RCE Vulnerability Impacts 100k+ Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe security flaw has been discovered in GiveWP, a popular WordPress donation plugin with over 100,000 active installations. The vulnerability, classified as an unauthenticated PHP Object Injection leading to …