PoC Exploit Published for Linux Kernel Privilege Escalation Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical use-after-free vulnerability has been discovered in the Linux kernel’s netfilter subsystem. This vulnerability could potentially allow local, unprivileged users with CAP_NET_ADMIN capability to escalate their privileges. The flaw, …

Water Sigbin Hackers Exploit Oracle WebLogic Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers uncovered a sophisticated attack campaign by the Water Sigbin (aka 8220 Gang) threat actor that exploited vulnerabilities in the Oracle WebLogic Server, notably CVE-2017-3506 and CVE-2023-21839, to deploy …

Google Chrome to Block Entrust SSL Certificates Starting November 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced that its Chrome browser will stop trusting TLS server authentication certificates issued by Entrust and AffirmTrust starting November 1, 2024. This decision follows Entrust’s series of compliance …

Hackers Created 250 npm Packages, Mimicking Popular AWS And Microsoft Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target and abuse npm packages to inject malicious code into widely used software libraries, reaching many developers and applications. Sonatype security researchers recently identified more than 250 npm packages …

ISP Sends Malware to Thousands of Customers to Stop Using File-Sharing Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

JTBC, a prominent Korean news organization, has uncovered that KT Corporation, one of South Korea’s largest telecom providers, deliberately infected over 600,000 users with malware to deter them from using …

Beware Of “TRANSLATEXT” Chrome Extension From North Korean Hackers Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers abuse Chrome extensions since they can embed malware on many targets by using common extensions in the browser. These unwanted extensions can gather personal data, display pop-ups, change URLs, …

Juniper Session Smart Router Flaw Let Attackers Bypass Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Juniper Networks has disclosed a critical vulnerability (CVE-2024-2973) affecting its Session Smart Router (SSR) and Session Smart Conductor products. The flaw allows network-based attackers to bypass authentication and gain complete …

Beware of Weaponized Notezilla, RecentX, & Copywhiz Windows Tools that Deliver Stealing Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

 Cybersecurity firm Rapid7 has identified that popular Windows tools Notezilla, RecentX, and Copywhiz have been weaponized to deliver malware. These tools, developed by Conceptworld, an India-based company, are widely used …

TeamViewer Hacked: Attackers Accessed Internal Corporate IT Environment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On Wednesday, June 26, 2024, TeamViewer, a leading provider of remote access software, announced that attackers had compromised its internal corporate IT environment. The company’s security team detected an “irregularity” …