Cyber News - Page 16

Home > Cyber News

This category contains informative articles and news.
Cyber News about data breaches, online privacy and security, computer security threats, cybersecurity reports, vulnerability reports. News about the latest malware attacks.
Hot news about the security of Microsoft (Patch Tuesdays), Google, Android, Apple, Linux, and other big companies and software vendors.

CYBER NEWS
CVE-2022-20777: Cisco Vulnerability Could Allow Unauthorized Root-Level Access

CVE-2022-20777: Cisco Vulnerability Could Allow Unauthorized Root-Level Access

Cisco patched three security vulnerabilities affecting its Enterprise NFV Infrastructure Software. The flaws could allow an attacker to obtain full control of the exposed hosts. It is important to note that the vulnerabilities, tracked as CVE-2022-20777, CVE-2022-20779, and CVE-2022-20780, are…

CYBER NEWS
Black Basta: New Ransomware on the Rise

Black Basta: New Ransomware on the Rise

Black Basta is a new ransomware first detected in the middle of April 2022. According to Minerva researchers, the ransomware “has already caused substantial damage to over ten organizations.” Two of its recent victims include Deutsche Windtechnik and the American…

CYBER NEWS
Security Researcher Discovers Vulnerabilities in Popular Ransomware Families

Security Researcher Discovers Vulnerabilities in Popular Ransomware Families

A security researcher known by the moniker h3perlinx discovered vulnerabilities in some of the most common ransomware families, including Conti, REvil, LockBit, AvosLocker, and the recently discovered Black Basta. Security Researcher Discovers Weaknesses in Popular Malware The discovered weaknesses could…

CYBER NEWS
phishing campaign exploiting google SMTP service

Google’s SMTP Service Exploited in Phishing Attacks

A new phishing attack leveraging Google’s SMTP relay service has been detected delivering phishing emails to users. The attack has been observed by Avanan security researchers. Google’s SMTP Service Abused What is SMTP? This type of service helps businesses send…

CYBER NEWS
New Bumblebee Malware Downloader Used for Initial Network Access

New Bumblebee Malware Downloader Used for Initial Network Access

Bumblebee is the name of a new malware downloader used by multiple threat actors that previously delivered BazaLoader and IcedID. In other words, these threat actors have replaced the two malware pieces with the newer Bumblebee. BazaLoader, in particular, hasn’t…

CYBER NEWS
most-exploited-vulnerabilities-2021-sensorstechforum

The Most Exploited Vulnerabilities in 2021 Include CVE-2021-44228, CVE-2021-26084

Which were the most routinely exploited security vulnerabilities in 2021? A new report released by CISA in cooperation with the authorities of the United States, Australia, Canada, New Zealand, and the United Kingdom revealed an advisory containing the most exploited…

CYBER NEWS
Nimbuspwn Vulnerabilities Allow Root Access to Linux Systems (CVE-2022-29799)

Nimbuspwn Vulnerabilities Allow Root Access to Linux Systems (CVE-2022-29799)

Microsoft discovered several vulnerabilities affecting Linux desktop computers. The vulnerabilities, collectively dubbed Nimbuspwn, can be chained together to achieve elevation of privileges and subsequently execute various malicious payloads, such as a root backdoor, via remote arbitrary root code execution. Identified…

CYBER NEWS
Lazarus Hackers Target Blockchain, Crypto Organizations with Trojanized Apps

Lazarus Hackers Target Blockchain, Crypto Organizations with Trojanized Apps

A new hacking campaign has been initiated by the Lazarus threat group that targets organizations in the cryptocurrency and blockchain industries. The hackers are using trojanized cryptocurrency applications and social engineering tricks to lure employees into downloading and running malicious…

CYBER NEWS
HOMAGE: New Zero-Click iMessage Exploit Used to Install Pegasus Spyware

HOMAGE: New Zero-Click iMessage Exploit Used to Install Pegasus Spyware

A newly disclosed zero-click iMessage exploit could be used to install NSO Group spyware on iPhones of Catalan politicians, journalists, and activities. The discovery comes from Citizen Lab researchers who called the zero-click flaw HOMAGE. The latter affects iOS versions…

CYBER NEWS
CVE-2021-3970: High-Impact Lenovo Notebook BIOS Vulnerabilities

CVE-2021-3970: High-Impact Lenovo Notebook BIOS Vulnerabilities

Three recently disclosed (and patched), high impact BIOS security vulnerabilities in Lenovo could lead to UEFI (Unified Extensible Firmware Interface) attacks. Discovered by security researcher Martin Smolár and assigned with the following identifiers CVE-2021-3970, CVE-2021-3971, and CVE-2021-3972, the flaws could…

CYBER NEWS
CVE-2022-22966: Critical VMware Cloud Director Vulnerability

CVE-2022-22966: Critical VMware Cloud Director Vulnerability

Another critical VMware vulnerability which could put cloud infrastructures at risk of remote code execution attacks. CVE-2022-22966 VMware Cloud Director Vulnerability CVE-2022-22966 is a critical issue in VMware Cloud Director product, with a CVSS score of 9.1 out of 10,…

CYBER NEWS
CVE-2022-1364 Chrome Vulnerability Exploited in the Wild

CVE-2022-1364 Chrome Vulnerability Exploited in the Wild

Did you install the emergency patches for Google Chrome that address two security vulnerabilities, one of which is exploited in the wild? CVE-2022-1364 Exploited in the Wild CVE-2022-1364 is a type confusion vulnerability in the V8 JavaScript engine reported by…

CYBER NEWS
NFT Marketplace Rarible Contains a Dangerous Design Flaw

NFT Marketplace Rarible Contains a Dangerous Design Flaw

Security researchers detected a vulnerability in the Rarible NFT marketplace, which enables users to create, buy and sell digital NFT art pieces. The company has a trading volume of $273 million in 2021, and more than 2.1 million users. This…

CYBER NEWS
Citrix Fixes Severe CVE-2022-27505 Vulnerability in SD-WAN

Citrix Fixes Severe CVE-2022-27505 Vulnerability in SD-WAN

Multiple vulnerabilities in the Citrix product portfolio were patched, including a high-severity bug in SD-WAN. CVE-2022-27505 in SD-WAN The latter has been tracked as CVE-2022-27505, and is a reflected cross-site scripting (XSS) issue which is a result of improper input…

CYBER NEWS
april patch tuesday 2022 CVE-2022-24521

Microsoft Patches CVE-2022-24521 Exploited in the Wild

Microsoft just released its April 2022 Patch Tuesday, containing fixes for one vulnerability exploited in the wild (CVE-2022-24521), and another one that was disclosed publicly. The company patched a total of 128 bugs, among which 10 critical remote code execution…

CYBER NEWS
CVE-2022-23176 Vulnerability Used by Sandworm Russian-Sponsored Hackers

CVE-2022-23176 Vulnerability Used by Sandworm Russian-Sponsored Hackers

WEB WatchGuard Firebox Authentication Vulnerability (CVE-2022-23176) CVE-2022-23176 is a privilege escalation vulnerability in WatchGuard Firebox and XTM appliances. The vulnerability could allow a remote, unprivileged threat actor to access the system with a privileged management session via an exposed management…

CYBER NEWS

JekyllBot:5 Vulnerabilities in Aethon TUG Mobile Robots (CVE-2022-1066)

Five security vulnerabilities, called JekyllBot:5 (CVE-2022-1066, CVE-2022-26423, CVE-2022-1070, CVE-2022-27494, and CVE-2022-1059) were fixed in Aethon TUG smart autonomous mobile robots. Fortunately, the vulnerabilities haven’t been exploited in the wild. JekyllBot:5 Vulnerabilities in Aethon TUG Mobile Robots The mobile robots are…

CYBER NEWS
parrot tds

Parrot TDS Uses Tens of Thousands Infected Sites to Distribute a RAT

Cybersecurity researchers detected a new TDS (Traffic Direction System), called Parrot, that uses tens of thousands of compromised websites. Parrot TDS Uses a Large Network of Infected Sites Parrot TDS has infected multiple web servers that host more than 16,500…

CYBER NEWS
CryptBot Infostealer Distributed by Pirated Software Websites

New META Infostealer Is After Your Passwords and Crypto Wallets

There’s a new information stealer on the rise, and security researchers say that it is currently being distributed in malspam campaigns. In other words, the so-called META infostealer is delivered via malicious spam in email messages (attachments). Since the infamous…

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree