Hackers Leveraging OneDrive & Google Drive To Hide Malicious Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers, including nation-state actors, increasingly leverage legitimate cloud services for espionage operations, exploiting their low-profile and cost-effective nature.  The services, such as Microsoft OneDrive and Google Drive, evade detection by …

1Password Vulnerability Let Attackers Exfiltrate Vault Items

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability, designated as CVE-2024-42219, has been identified in 1Password 8 for Mac. This flaw allows malicious actors to exfiltrate vault items by bypassing the app’s platform security protections. …

RHADAMANTHYS Stealer Weaponizing RAR Archive To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly surfaced cybercampaign targeting Israeli users has thrust the sophisticated RHADAMANTHYS information stealer into the spotlight. Originating from Russian-speaking cybercriminals and offered as a Malware-as-a-Service, RHADAMANTHYS excels at data …

Apache Cloudstack Vulnerability Exposes API & Secret Keys to Admin Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache CloudStack project has announced the release of long-term support (LTS) security updates, versions 4.18.2.3 and 4.19.1.1, which address two critical vulnerabilities, CVE-2024-42062 and CVE-2024-42222. These vulnerabilities pose significant …

Firefox Patches Multiple High Severity Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla has released Firefox 129, addressing multiple high-severity vulnerabilities. These patches are critical for enhancing the browser’s security and protecting users from potential exploits. Detailed Vulnerability Table The latest Firefox …

Critical Kibana Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kibana, a popular open-source data visualization and exploration tool, has identified a critical security flaw that could allow attackers to execute arbitrary code. This vulnerability, tracked as CVE-2024-37287, has a …

Chrome Security Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could allow attackers to execute malicious code on users’ systems. The update, version 127.0.6533.99/.100 …

CrowdStrike Publishes Technical Root Cause Analysis of Faulty Falcon Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity giant CrowdStrike has released a comprehensive technical root cause analysis detailing the events that led to a problematic Falcon sensor update on July 19, 2024. The incident caused system …

Hackers Hijack Anti-Virus Software Using SbaProxy Hacking Tool

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from LevelBlue Labs have uncovered a new tactic threat actors employ to hijack legitimate anti-virus software for malicious purposes. This sophisticated attack leverages a tool named SbaProxy, which masquerades …