Judge0 Security Flaw Let Attackers Run Arbitrary Code & Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tanto Security has disclosed critical vulnerabilities in the widely-used open-source service Judge0, which could allow attackers to perform a sandbox escape and gain root access to the host machine. The …

HookChain – A New Sophisticated Technique Evades EDR Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the rapidly evolving, complex threat landscape, EDR companies are constantly racing against new vectors. Recently, Helvio Benedito Dias de Carvalho Junior (aka M4v3r1ck) from Sec4US has developed an innovation …

Hackers Took Just 29-Days From IcedID Infection to Dagon Locker Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated cyberattack that unfolded over 29 days, cybersecurity analysts have meticulously traced the steps of threat actors from the initial infection with IcedID malware to the eventual deployment …

Multiple QNAP Vulnerability Let Hackers Hijack Your NAS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP has disclosed multiple vulnerabilities across its network-attached storage (NAS) systems, which could allow hackers to take control of affected devices. The vulnerabilities impact several versions of QNAP’s operating systems …

Find Malware With ANY RUN Threat Intelligence YARA Search by File Contents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

YARA is a rule-based malware detection tool that utilizes regular expressions and textual/binary signatures to create descriptions (rules) for identifying malicious files.  Within ANY.RUN TI, YARA Search allows you to …

Vulnerability in Apache Project  Let Hackers Launch Supply Chain Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers discovered a vulnerability in an archived Apache project, highlighting the risk of using outdated third-party dependencies, where attackers can exploit the way package managers prioritize public repositories to install …

ICICI Bank Data Leak Exposes 17,000 Customers’ Credit Card Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ICICI Bank, one of India’s leading private banks, has confirmed the exposure of sensitive credit card information belonging to thousands of customers. The Mumbai-based bank acknowledged that a technical glitch …

Cactus Ransomware Exploiting Qlik Servers Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cactus ransomware gang has been exploiting vulnerable Qlik sense servers ever since November 2023 using multiple vulnerabilities such as CVE-2023-41266 (Path Traversal), CVE-2023-41265 (HTTP request Tunneling) and CVE-2023-48365 (Unauthenticated …