PoC Exploit Released For Critical Flowmon Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Progress addressed a critical vulnerability last week, which was associated with an unauthenticated Command injection on the Progress Flowmon product. This vulnerability was assigned CVE-2024-2189, and the severity was given …

Chrome Critical Flaw Let Attackers Execute Arbitary Code : Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google announced the release of Chrome 124, which fixes four vulnerabilities, including a critical security issue that allows attackers to execute arbitrary code. Over the next few days or weeks, the …

Hackers Exploit Google Ads to Spread IP Scanner with Concealed Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious actors are distributing a new backdoor, MadMxShell, through a Google Ads campaign that impersonates an IP scanner. This Windows backdoor leverages DNS MX queries for communication with its command-and-control …

Hackers Employ Black Hat SEO Techniques To Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers use black hat SEO methods to manipulate search engine rankings and make malicious or fraudulent websites more visible. Recently, Zscaler cybersecurity researchers have seen a wave of fraudulent sites …

GitLab High-severity Flaw Let Attackers Takeover Account – Update Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab released security patches 16.11.1, 16.10.4, and 16.9.6 for both Community and Enterprise Editions, and upgrading to these versions is strongly recommended to address vulnerabilities.  Scheduled patch releases occur twice …

ArcaneDoor Exploiting Cisco Zero-Days To Attack Government Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target Cisco zero-days as they can abuse the widely used networking equipment that contains vulnerabilities which means they can affect many systems and networks in one shot.  Attackers use …

KnowBe4 to Acquire Egress for Aids in Email Awareness Training

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

KnowBe4, the leader in security awareness training and simulated phishing platforms, has announced its definitive agreement to acquire Egress, a pioneer in adaptive and integrated cloud email security. This acquisition …