Chinese Hackers Exploited Fortinet zero-day Flaw to hack Dutch defense networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese state-sponsored hackers exploited a zero-day vulnerability (CVE-2022-42475) in Fortinet’s virtual private network to gain unauthorized access to the Dutch defense networks. The hackers then deployed COATHANGER malware, a sophisticated …

Linux Shim Bootloader Flaw Expose Most Linux Distros to Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Shim is a small application used by open-source projects and other third parties for verifying and running the bootloader (typically GRUB2). The application was developed specifically to circumvent legal issues …

Two New FortiSIEM Max-severity Flaw Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiSIEM has been discovered with multiple OS command injection vulnerabilities, which could allow an unauthenticated remote threat actor to execute unauthorized commands on FortiSIEM via crafted API requests. The CVEs …

Google’s Open-source Tool Bazel Flaw Let Attackers Insert Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Bazel, an open-source software used for automation of building and testing, has been discovered with a critical supply chain vulnerability that could allow a threat actor to inject malicious code …

Hackers Stolen 2M+ User’s Data Via XSS & SQL Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale cyber attack was launched to steal and market confidential user information, focusing mainly on the APAC region’s employment agencies and retail firms. A group of hackers called ResumeLooters …

11 Best Cyber Secuity Compliance Management Software – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Compliance Management Software’s goal is to ensure that everyone follows the rules and laws. Governments, regulatory and industry bodies, employee unions, and other organizations set these requirements. Businesses use software …

Best SOC 2 Type 2 Certified Complaint Solutions – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SOC 2 Type 2 certification complaint which stands for System and Organization Controls 2 is an auditing process that confirms service providers securely manage data to safeguard organizations’ interests and …

Hackers Selling AnyDesk Users’ Login Credentials On Cybercriminal Forums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent security breach has exposed AnyDesk’s customer’s credentials, putting their accounts and devices at risk.  On February 3, 2024, Resecurity discovered several threat actors peddling compromised AnyDesk credentials on …