Latest Cybersecurity News and Articles

Clop Ransomware is Now Extorting 66 Cleo Data-Theft Victims

The Cleo data theft attack represents another major success for Clop, who leveraged leveraging a zero-day vulnerability in Cleo LexiCom, VLTransfer, and Harmony products to steal data from the networks of breached companies.

CVE-2024-43441: Authentication Bypass Vulnerability Found in Apache HugeGraph-Server

The Apache HugeGraph team has released version 1.5.0, which effectively patches this vulnerability. All users of Apache HugeGraph-Server versions 1.0 through 1.3 are strongly urged to upgrade to 1.5.0 immediately.

Trio of SQL Injection Flaws Strike Amazon Redshift Drivers: Patch Immediately

These flaws affect specific versions of the Amazon Redshift JDBC Driver, Python Connector, and ODBC Driver, highlighting a common weakness in how these tools handle metadata API calls.

Critical SQL Injection Vulnerability Found in Apache Traffic Control

This vulnerability, identified as CVE-2024-45387 and assigned a CVSS score of 9.9, could allow attackers to execute malicious SQL code, potentially compromising sensitive data and disrupting critical services.

Major Biometric Data Farming Operation Uncovered

Security researchers have urged customer-facing businesses to improve their verification checks after discovering a large-scale identity farming operation on the dark web.

North Korean Hackers Pulled Off $308M Bitcoin Heist from Crypto Firm DMM Bitcoin

Japanese and U.S. authorities have formerly attributed the theft of cryptocurrency worth $308 million from cryptocurrency company DMM Bitcoin in May 2024 to North Korean cyber actors.

Malicious Intent Discovered in Two PyPI Packages

Fortinet flagged two malicious Python packages, Zebo-0.1.0 and Cometlogger-0.1, exhibiting behaviors like keylogging, data exfiltration, webhook injection, and anti-VM checks while employing obfuscation to evade detection.

PoC Exploit Released for Windows Elevation of Privilege Vulnerability

Security researcher Alex Birnberg with SSD Secure Disclosure published the technical details and a proof-of-concept (PoC) exploit code for CVE-2024-30085, a Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability.

CISA Adds Acclaim Systems USAHERDS Flaw to its Known Exploited Vulnerabilities Catalog

The vulnerability, tracked as CVE-2021-44207, was exploited by the Chinese cyber-espionage group APT41 to breach multiple U.S. state government networks. The flaw stems from the use of hard-coded credentials.

Critical Webmin Vulnerability Leaves a Million Servers Exposed to RCE

The vulnerability was discovered by Trend Micro’s Zero Day Initiative and has been addressed in Webmin version 2.111. All Webmin and Virtualmin administrators are strongly urged to update their installations immediately.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags