IBM Aspera Shares Vulnerability Let Attackers Login as Any User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

IBM has disclosed a vulnerability in its Aspera Shares software, CVE-2023-38018. This flaw in user session handling could potentially allow attackers to impersonate any user within the system, posing a …

Critical OpenSSH Vulnerability in FreeBSD Let’s Attackers Gain Root Access Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in OpenSSH implementations on FreeBSD systems, potentially allowing attackers to execute remote code without authentication. The vulnerability, identified as CVE-2024-7589, affects all supported …

Best Active Directory Monitoring Tools – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Monitoring an Active Directory (AD) involves tracking and analyzing business AD events and activity. Windows-based systems store and manage network resources, user accounts, groups, and security rules in Active Directory. …

Critical OpenVPN Vulnerabilities Expose Millions of Devices to RCE Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft researchers have recently uncovered multiple medium-severity vulnerabilities in OpenVPN, a widely used open-source VPN software. OpenVPN is used by thousands of companies across various industries, including information technology, financial …

Microsoft Office Spoofing Vulnerability Let Attackers Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has disclosed a significant security vulnerability in its Office suite, identified as CVE-2024-38200, which could potentially allow attackers to access sensitive information. This spoofing vulnerability affects multiple versions of …

Open Source Firewall pfsense Vulnerable to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A popular open-source firewall software pfSense vulnerability has been identified, allowing for remote code execution (RCE) attacks. The vulnerability, tracked as CVE-2022-31814, highlights potential risks in pfSense installations, particularly those …

Thousands Of Internet-Connected ICS Devices Exposes Critical Infrastructure To Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In November 2023, hackers from Iran hacked the Municipal Water Authority of Aliquippa, Pennsylvania. They targeted a vulnerable control system and damaged it with anti-Israel statements. Two months later, in …

Series Of Solar Power System Vulnerabilities Impacts Millions Of Installations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The giant global electricity network intercrosses the fast-growing solar power infrastructure and ubiquitous Internet of Things, making a complex point of energy and data. This intersection relies on vulnerable inverters …

Critical XSS Vulnerability In Roundcube Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Roundcube, a widely adopted open-source webmail application, is included by default in the popular cPanel web hosting control panel, leading to millions of installations worldwide.  The software is commonly used …