Cyber News - Page 16

Home > Cyber News

This category contains informative articles and news.
Cyber News about data breaches, online privacy and security, computer security threats, cybersecurity reports, vulnerability reports. News about the latest malware attacks.
Hot news about the security of Microsoft (Patch Tuesdays), Google, Android, Apple, Linux, and other big companies and software vendors.

CYBER NEWS
Nimbuspwn Vulnerabilities Allow Root Access to Linux Systems (CVE-2022-29799)

Nimbuspwn Vulnerabilities Allow Root Access to Linux Systems (CVE-2022-29799)

Microsoft discovered several vulnerabilities affecting Linux desktop computers. The vulnerabilities, collectively dubbed Nimbuspwn, can be chained together to achieve elevation of privileges and subsequently execute various malicious payloads, such as a root backdoor, via remote arbitrary root code execution. Identified…

CYBER NEWS
Lazarus Hackers Target Blockchain, Crypto Organizations with Trojanized Apps

Lazarus Hackers Target Blockchain, Crypto Organizations with Trojanized Apps

A new hacking campaign has been initiated by the Lazarus threat group that targets organizations in the cryptocurrency and blockchain industries. The hackers are using trojanized cryptocurrency applications and social engineering tricks to lure employees into downloading and running malicious…

CYBER NEWS
HOMAGE: New Zero-Click iMessage Exploit Used to Install Pegasus Spyware

HOMAGE: New Zero-Click iMessage Exploit Used to Install Pegasus Spyware

A newly disclosed zero-click iMessage exploit could be used to install NSO Group spyware on iPhones of Catalan politicians, journalists, and activities. The discovery comes from Citizen Lab researchers who called the zero-click flaw HOMAGE. The latter affects iOS versions…

CYBER NEWS
CVE-2021-3970: High-Impact Lenovo Notebook BIOS Vulnerabilities

CVE-2021-3970: High-Impact Lenovo Notebook BIOS Vulnerabilities

Three recently disclosed (and patched), high impact BIOS security vulnerabilities in Lenovo could lead to UEFI (Unified Extensible Firmware Interface) attacks. Discovered by security researcher Martin Smolár and assigned with the following identifiers CVE-2021-3970, CVE-2021-3971, and CVE-2021-3972, the flaws could…

CYBER NEWS
CVE-2022-22966: Critical VMware Cloud Director Vulnerability

CVE-2022-22966: Critical VMware Cloud Director Vulnerability

Another critical VMware vulnerability which could put cloud infrastructures at risk of remote code execution attacks. CVE-2022-22966 VMware Cloud Director Vulnerability CVE-2022-22966 is a critical issue in VMware Cloud Director product, with a CVSS score of 9.1 out of 10,…

CYBER NEWS
CVE-2022-1364 Chrome Vulnerability Exploited in the Wild

CVE-2022-1364 Chrome Vulnerability Exploited in the Wild

Did you install the emergency patches for Google Chrome that address two security vulnerabilities, one of which is exploited in the wild? CVE-2022-1364 Exploited in the Wild CVE-2022-1364 is a type confusion vulnerability in the V8 JavaScript engine reported by…

CYBER NEWS
NFT Marketplace Rarible Contains a Dangerous Design Flaw

NFT Marketplace Rarible Contains a Dangerous Design Flaw

Security researchers detected a vulnerability in the Rarible NFT marketplace, which enables users to create, buy and sell digital NFT art pieces. The company has a trading volume of $273 million in 2021, and more than 2.1 million users. This…

CYBER NEWS
Citrix Fixes Severe CVE-2022-27505 Vulnerability in SD-WAN

Citrix Fixes Severe CVE-2022-27505 Vulnerability in SD-WAN

Multiple vulnerabilities in the Citrix product portfolio were patched, including a high-severity bug in SD-WAN. CVE-2022-27505 in SD-WAN The latter has been tracked as CVE-2022-27505, and is a reflected cross-site scripting (XSS) issue which is a result of improper input…

CYBER NEWS
april patch tuesday 2022 CVE-2022-24521

Microsoft Patches CVE-2022-24521 Exploited in the Wild

Microsoft just released its April 2022 Patch Tuesday, containing fixes for one vulnerability exploited in the wild (CVE-2022-24521), and another one that was disclosed publicly. The company patched a total of 128 bugs, among which 10 critical remote code execution…

CYBER NEWS
CVE-2022-23176 Vulnerability Used by Sandworm Russian-Sponsored Hackers

CVE-2022-23176 Vulnerability Used by Sandworm Russian-Sponsored Hackers

WEB WatchGuard Firebox Authentication Vulnerability (CVE-2022-23176) CVE-2022-23176 is a privilege escalation vulnerability in WatchGuard Firebox and XTM appliances. The vulnerability could allow a remote, unprivileged threat actor to access the system with a privileged management session via an exposed management…

CYBER NEWS

JekyllBot:5 Vulnerabilities in Aethon TUG Mobile Robots (CVE-2022-1066)

Five security vulnerabilities, called JekyllBot:5 (CVE-2022-1066, CVE-2022-26423, CVE-2022-1070, CVE-2022-27494, and CVE-2022-1059) were fixed in Aethon TUG smart autonomous mobile robots. Fortunately, the vulnerabilities haven’t been exploited in the wild. JekyllBot:5 Vulnerabilities in Aethon TUG Mobile Robots The mobile robots are…

CYBER NEWS
parrot tds

Parrot TDS Uses Tens of Thousands Infected Sites to Distribute a RAT

Cybersecurity researchers detected a new TDS (Traffic Direction System), called Parrot, that uses tens of thousands of compromised websites. Parrot TDS Uses a Large Network of Infected Sites Parrot TDS has infected multiple web servers that host more than 16,500…

CYBER NEWS
CryptBot Infostealer Distributed by Pirated Software Websites

New META Infostealer Is After Your Passwords and Crypto Wallets

There’s a new information stealer on the rise, and security researchers say that it is currently being distributed in malspam campaigns. In other words, the so-called META infostealer is delivered via malicious spam in email messages (attachments). Since the infamous…

CYBER NEWS
Privacy Guide for Google Chrome Will Help You Manage Your Security Settings

Privacy Guide for Google Chrome Will Help You Manage Your Security Settings

Google has developed a new Privacy Guide for its Chrome browser. Privacy Guide for Google Chrome The feature has been created by the Google Safety Engineering Center (GSEC), and has been described as “a step-by-step guided tour of some existing…

CYBER NEWS
Beware: WhatsApp Voicemail Phishing Attack Coming from Russia

Beware: WhatsApp Voicemail Phishing Attack Coming from Russia

Security researchers detected a new phishing scam targeting various organizations across healthcare, education, and healthcare sectors. Approximately 27,660 mailboxes have been reached by the suspicious email messages. ArmorBlox researchers provided more details about the phishing attack. New Phishing Campaign Uses…

CYBER NEWS
Apple Hasn't Patched Actively Exploited Zero-Days in macOS Catalina, Big Sur

Apple Hasn’t Patched Actively Exploited Zero-Days in macOS Catalina, Big Sur

Apple recently released two emergency patches to fix two actively exploited zero-days in Apple’s macOS and iOS (reported anonymously). The company said the flaws have been exploited in the wild. The vulnerabilities have been fixed in iOS and iPadOS 15.4.1,…

CYBER NEWS
VMware Fixes Eight Serious Security Issues (CVE-2022-22954)

VMware Fixes Eight Serious Security Issues (CVE-2022-22954)

VMware has fixed a total of eight security vulnerabilities in several of its products, including VMware Workspace ONE Access, VMware Identity Manager, VMware vRealize Automation, VMware Cloud Foundation, and vRealize Suite Lifecycle Manager. It is noteworthy that some of the…

CYBER NEWS

Industrial Giant Parker Hannifin Hit by Conti Ransomware, Data Leaked

Several gigabytes of information stolen from US industrial giant Parker Hannifin have been leaked by the Conti ransomware group. Parker Hannifin is an American corporation (and a Fortune 250 company) specializing in motion and control technologies, with corporate headquarters in…

CYBER NEWS
Disconnect D-Link Routers Vulnerable to CVE-2021-45382

Disconnect D-Link Routers Vulnerable to CVE-2021-45382

CVE-2021-45382 is a Remote Code Execution (RCE) vulnerability in D-Link routers. More specifically, all series of H/W revisions D-Link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file, are affected, according to the official…

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree