Category: CyberSecurityNews

Japan Airlines System Hit by Cyber Attack, Flight Operations Affected
26
Dec
2024

Japan Airlines System Hit by Cyber Attack, Flight Operations Affected

Japan Airlines (JAL), the nation’s second-largest airline, reported a significant cyberattack on its systems early Thursday morning, causing disruptions to…

New Sophisticated Attack Weaponizes Windows Defender to Bypass EDR
25
Dec
2024

New Sophisticated Attack Weaponizes Windows Defender to Bypass EDR

A sophisticated attack technique that weaponizes Windows Defender Application Control (WDAC) to disable Endpoint Detection and Response (EDR) sensors on…

Apache Traffic Control Vulnerability Let Attackers Inject Malicious SQL Commands
25
Dec
2024

Apache Traffic Control Vulnerability Let Attackers Inject Malicious SQL Commands

A critical SQL injection vulnerability, identified as CVE-2024-45387, has been discovered in Apache Traffic Control, a widely used open-source platform…

Postman Data Leak – 30,000 Publicly Accessible Workspaces Could Lead Massive Hack
25
Dec
2024

Postman Data Leak – 30,000 Publicly Accessible Workspaces Could Lead Massive Hack

Researchers uncovered a widespread and alarming trend involving data leaks from Postman, a widely used cloud-based API development and testing…

Apache HugeGraph-Server Vulnerability
24
Dec
2024

Apache HugeGraph-Server Vulnerability Lets Attackers Bypass Authentication

A new security vulnerability, CVE-2024-43441, has been identified in Apache HugeGraph-Server, a widely used open-source graph database system. This flaw,…

OilRig Hackers Windows Kernel 0-day
24
Dec
2024

OilRig Hackers Exploiting Windows Kernel 0-day to Attack Organizations

The Iranian state-sponsored hacking group OilRig, also known as APT34, has intensified its cyber espionage activities, targeting critical infrastructure and…

Two New Malicious PyPI Packages Attacking Users to Steal Login Details
24
Dec
2024

Two New Malicious PyPI packages Attacking Users to Steal Login Details

Two malicious Python Package Index (PyPI) packages: Zebo-0.1.0 and Cometlogger-0.1, have been identified, posing a significant threat to user security. These packages,…

Adobe ColdFusion Vulnerability Let Attackers Read arbitrary files – PoC Released
24
Dec
2024

Adobe ColdFusion Vulnerability Let Attackers Read arbitrary files

Adobe has issued updates to address a vulnerability in its ColdFusion software that could allow attackers to read arbitrary files…

Brazilian Hacker Charged for Selling Data Stolen From Hacked Computers
24
Dec
2024

Brazilian Hacker Charged for Selling Data Stolen From Hacked Computers

Junior Barros De Oliveira, a 29-year-old resident of Curitiba, Brazil, has been indicted in the United States for orchestrating an…

Node.js
24
Dec
2024

Node.js “systeminformation” Vulnerability Exposes Millions of Systems to RCE Attacks

A critical security vulnerability has been discovered in the widely-used Node.js package “systeminformation,” potentially exposing millions of systems to remote…

deploy Malware Using ScreenConnect
24
Dec
2024

Hackers Deploy AsyncRAT and SectopRAT Malware Using ScreenConnect on Windows

Cybercriminal groups are increasingly blending new and traditional techniques to steal sensitive information from unsuspecting users by deploying remote access…

Webmin RCE Vulnerability
24
Dec
2024

Webmin RCE Vulnerability Let Attackers Execute Arbitrary Code & Gain Server Control

Webmin, the popular web-based system administration tool, has been found to contain a critical security vulnerability that could allow attackers…