Category: CyberSecurityNews

Next.js Framework Exposes Websites To Cache Poisoning & XSS Attacks
23
Jan
2025

Next.js Framework Exposes Websites To Cache Poisoning & XSS Attacks

A critical vulnerability, identified as CVE-2024-46982, has been discovered in the popular Next.js framework, widely used for building full-stack web…

Researcher Jailbreaking an AI's System Prompt Through Creativity
23
Jan
2025

Researcher Jailbreaking an AI’s System Prompt Through Creativity

In a remarkable display of creativity, a researcher showcased how an artificial intelligence (AI) system’s tightly guarded “system prompt” could…

Rails Apps File Write Vulnerability Let Attackers Execute Code Remotely
23
Jan
2025

Rails Apps File Write Vulnerability Let Attackers Execute Code Remotely

Researchers uncovered a critical security vulnerability in Rails applications that leverages the Bootsnap caching library. This exploit allows attackers to achieve…

Open-Source ClamAV Releases Critical Security Patch Updates – What’s Inside!
23
Jan
2025

Open-Source ClamAV Releases Critical Security Patch Updates – What’s Inside!

The ClamAV team has announced the release of security patch updates for ClamAV versions 1.4.2 and 1.0.8. These updates address…

New Cookie Sandwich Technique Let Attackers Bypass HttpOnly Flag On Servers
23
Jan
2025

New Cookie Sandwich Technique Let Attackers Bypass HttpOnly Flag On Servers

A newly discovered attack technique, dubbed the “cookie sandwich,” enables attackers to bypass the HttpOnly flag on certain servers, exposing…

New Supply Chain Attack Targeting Chrome Extensions To Inject Malicious Code
23
Jan
2025

New Supply Chain Attack Targeting Chrome Extensions To Inject Malicious Code

A sophisticated supply chain attack targeting Chrome browser extensions has compromised at least 35 Chrome extensions, potentially exposing over 2.6…

Helldown Ransomware Exploiting Zyxel Devices Using Zero-Day Vulnerability
22
Jan
2025

Helldown Ransomware Exploiting Zyxel Devices Using Zero-Day Vulnerability

A new ransomware threat dubbed “Helldown” has emerged, actively exploiting vulnerabilities in Zyxel firewall devices to breach corporate networks. Cybersecurity…

Malicious VS Code Mimic As Zoom App Steals Cookies From Chrome
22
Jan
2025

Malicious VS Code Mimic As Zoom App Steals Cookies From Chrome

Cybersecurity researchers have uncovered a new threat targeting developers using Visual Studio Code (VS Code). A malicious extension masquerading as…

AWS Releases Best Security Practices To Mitigate Ransomware Attacks
22
Jan
2025

AWS Releases Best Security Practices To Mitigate Ransomware Attacks

Amazon Web Services (AWS) has announced a set of best practices aimed at helping customers protect their cloud environments against…

Ex-CIA Analyst Pleads Guilty To Leaking National Defense Information
22
Jan
2025

Ex-CIA Analyst Pleads Guilty To Leaking National Defense Information

A former CIA analyst, Asif William Rahman, 34, pleaded guilty today to unlawfully retaining and transmitting Top Secret National Defense…

China Hackers Compromised VPN Service Provider in Supply-Chain Attack
22
Jan
2025

China Hackers Compromised VPN Service Provider in Supply-Chain Attack

A sophisticated supply-chain attack targeting a South Korean VPN provider. The attack has been attributed to a previously undisclosed China-aligned…

Threat Actors Delivering Ransomware Via Microsoft Teams Using Voice Calls
22
Jan
2025

Threat Actors Delivering Ransomware Via Microsoft Teams Using Voice Calls

Sophos Managed Detection and Response (MDR) has uncovered two distinct ransomware campaigns exploiting Microsoft Teams to gain unauthorized access to…