access?

  • A critical vulnerability in SolarWinds’ Web Help Desk software (CVE-2024-28989) allowed attackers to decrypt sensitive credentials, including database passwords and LDAP/SMTP authentication secrets, through cryptographic weaknesses in its AES-GCM implementation.  Patched in version 12.8.5, the flaw stemmed from predictable encryption keys and nonce reuse, enabling practical decryption of stored secrets even without direct system access.…

    Read More

  • A vulnerability was found in Microsoft Access. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to use after free. This vulnerability was named CVE-2025-26630. The attack can be initiated remotely. There is no exploit available. It is recommended to apply a patch to fix this issue.

    Read More

  • A vulnerability was found in Microsoft Windows 11 22H2/11 23H2/11 24H2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Cross Device Service. The manipulation leads to improper access controls. This vulnerability is known as CVE-2025-24994. The attack needs to be approached locally. There is no exploit…

    Read More

  • A vulnerability, which was classified as critical, was found in Apple macOS up to 14.x. Affected is an unknown function of the component Removable Volume Handler. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2024-54463. It is possible to launch the attack on the local host. There is no exploit available.…

    Read More

  • A vulnerability was found in Pluggabl Booster Elite for WooCommerce Plugin up to 7.1.2 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2023-51511. The attack may be initiated remotely. There is no exploit available. It is…

    Read More

  • Physical penetration testing provides crucial insights into real-world security vulnerabilities that might be overlooked in purely digital assessments. A recent case study conducted by Hackmosphere for a furniture retailer, referred to as ExCorp, revealed how physical access to facilities could compromise internal networks despite robust cybersecurity measures. The penetration test identified four critical vulnerabilities that…

    Read More

  • Threat hunters have shed light on a “sophisticated and evolving malware toolkit” called Ragnar Loader that’s used by various cybercrime and ransomware groups like Ragnar Locker (aka Monstrous Mantis), FIN7, FIN8, and Ruthless Mantis (ex-REvil). “Ragnar Loader plays a key role in keeping access to compromised systems, helping attackers stay in networks for long-term operations,”…

    Read More

  • arXiv:2503.04259v1 Announce Type: new Abstract: The European General Data Protection Regulation (GDPR) grants European users the right to access their data processed and stored by organizations. Although the GDPR contains requirements for data processing organizations (e.g., understandable data provided within a month), it leaves much flexibility. In-depth research on how online services handle data subject…

    Read More

  • A vulnerability was found in Mirotalk. It has been declared as problematic. Affected by this vulnerability is the function roomAction. The manipulation leads to improper access controls. This vulnerability is known as CVE-2024-44734. The attack can only be done within the local network. There is no exploit available. It is recommended to apply a patch…

    Read More

  • The China-lined threat actor behind the zero-day exploitation of security flaws in Microsoft Exchange servers in January 2021 has shifted its tactics to target the information technology (IT) supply chain as a means to obtain initial access to corporate networks. That’s according to new findings from the Microsoft Threat Intelligence team, which said the Silk…

    Read More

  • Cisco Systems has disclosed a security vulnerability in its Webex for BroadWorks unified communications platform that could allow attackers to intercept sensitive credentials and user data under specific configurations. The flaw, tracked as CSCwo20742 and classified as a low-severity issue, impacts organizations using Release 45.2 of the software in Windows-based environments, prompting Cisco to release configuration-based fixes and recommend…

    Read More

  • A critical security flaw in Zoho’s widely used identity management solution, ADSelfService Plus, has been patched after researchers discovered it could enable attackers to hijack user sessions and compromise sensitive enrollment data. Tracked as CVE-2025-1723, the high-severity vulnerability underscores the risks of insufficient session validation in authentication systems, particularly when multi-factor authentication (MFA) safeguards are not…

    Read More

  • Specops Software has launched Specops Secure Access, a new capability that provides multi-factor authentication (MFA) to Windows logon, Remote Desktop Protocol (RDP), and VPN connections. This new innovation adds a layer of security to on-premises or hybrid Active Directory environments, strengthening protection against unauthorized access and credential-based attacks. Password-based threats are on the rise. Specops…

    Read More

  • arXiv:2503.02019v1 Announce Type: new Abstract: The rapid advancements in wireless technology have significantly increased the demand for communication resources, leading to the development of Spectrum Access Systems (SAS). However, network regulations require disclosing sensitive user information, such as location coordinates and transmission details, raising critical privacy concerns. Moreover, as a database-driven architecture reliant on user-provided…

    Read More

  • The European Court of Human Rights ruled on Tuesday that Bulgaria violated the European Convention on Human Rights by denying a journalist access to the acquittal judgment of a former Minister of Internal Affairs in a high-profile criminal case. The court found that Bulgaria’s refusal to provide access to the judgment violated Article 10 of…

    Read More

  • A vulnerability classified as critical was found in Google Android. Affected by this vulnerability is an unknown functionality of the component Kernel File System. The manipulation leads to improper access controls. This vulnerability is known as CVE-2017-13165. Local access is required to approach this attack. There is no exploit available. It is recommended to apply…

    Read More

  • Security researchers from Unit 42 have uncovered an advanced phishing campaign orchestrated by the JavaGhost threat actor group. The post JavaGhost’s Persistent Phishing Attacks: Exploiting Cloud Environments for Long-Term Access appeared first on Cybersecurity News.

    Read More

  • A vulnerability, which was classified as critical, has been found in Red Hat OpenStack 4.0. This issue affects some unknown processing of the component Access Restriction. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2014-0071. The attack may be initiated remotely. There is no exploit available.

    Read More

  • A vulnerability was found in ImageMagick and classified as critical. This issue affects some unknown processing of the file coders/xpm.c of the component XPM File Handler. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2014-9827. The attack may be initiated remotely. There is no exploit available.

    Read More

  • A vulnerability was found in HYPR Workforce Access up to 8.7.0 on macOS. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to link following. This vulnerability was named CVE-2024-0068. Attacking locally is a requirement. There is no exploit available. It is recommended to upgrade the affected component.

    Read More

Post
Filter
Apply Filters