Cisco Webex Meetings Meeting Flaw Let Attackers Gain Unauthorized Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a significant security vulnerability in its Webex Meetings platform that allowed unauthorized access to meeting information and metadata. The issue, identified in early May 2024, affected certain …

Tripwire Enterprise Flaw Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tripwire, a leading provider of integrity monitoring and security solutions, disclosed a critical vulnerability in its Tripwire Enterprise (TE) software. The flaw, identified as CVE-2024-4332, allows unauthenticated attackers to bypass …

Europol Starts Hunting For Emotet Malware Developer And Mastermind

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Europol-led Operation Endgame focuses on the individual threat actors operating behind the botnets. Cyberlaw enforcement is very dedicated to locating who created the once-powerful Emotet malware as a service; …

Telerik Report Server Flaw Let Remote Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Progress-owned Telerik Report Server addressed two vulnerabilities in its system, which were associated with Authentication bypass and Insecure Deserialization. To add a note, the insecure deserialization was marked as 9.9 …

Hackers Employ JavaScript Framework To Trick Users Copy, Paste And Command Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers use JavaScript frameworks since they offer a wide range of functionalities and tools that could be used to bypass detection, hide code, and carry out harmful acts. In addition, …

PoC Exploit Released for Linux Kernel Privilege Escalation Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Proof-of-Concept (PoC) exploit has been released for a critical privilege escalation vulnerability in the Linux kernel. The vulnerability tracked as CVE-2023-3390 has raised alarms due to its potential to …

Hackers Exploited TikTok Zero-Day Vulnerability to Hijack High-Profile Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TikTok has confirmed that hackers exploited a zero-day vulnerability in its direct messaging (DM) feature to hijack several high-profile accounts. The affected accounts include those of celebrities like Paris Hilton …

ANY RUN Sandbox Added New Features to Analyse Sophisticated Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN revamped their user interface for a more streamlined workflow, as the sandbox homepage now features shortcut buttons for launching new analysis sessions, eliminating the need to navigate through the …

Hackers Weaponize Authentication Tools To Deliver NiceRAT Malware via Botnet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Botnets, traditionally used for DDoS attacks with malware like Nitol, are now being built with malware capable of data exfiltration and installing additional malware, confirmed by the discovery of NiceRAT …

Confluence Data Center & Server Flaw Allows Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian disclosed a high-severity vulnerability that exists in multiple versions of their Confluence Data Center and Server. The CVE for this vulnerability was assigned with CVE-2024-21683 and the severity was …