Cybersecurity News

Cacti Command Injection Flaw Enables Remote Execution Of Malicious Code

A serious command injection vulnerability in Cacti, a popular open-source network monitoring tool, allows authenticated attackers to execute arbitrary commands…

4 months ago

Lazarus Group Hacker Captured On Camera Amid IT Worker Scheme Bust

Researchers from BCA LTD, NorthScan, and ANY.RUN trapped North Korean Lazarus Group operatives, linked to the Famous Chollima division, live…

4 months ago

Novel SVG-Based Clickjacking Method Allows Interactive User Manipulation

Security researcher Lyra Rebane has uncovered a powerful new clickjacking technique using SVG filters. This method, dubbed "SVG clickjacking," overlays…

5 months ago

CISA Reports Active Exploitation Of OpenPLC and ScadaBR File Upload Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2021-26828 to its Known Exploited Vulnerabilities (KEV) catalog on December 3,…

5 months ago

Chaining Synology BeeStation Flaws To Gain Root Access via Exploited Task Scheduler

Security researchers chained three vulnerabilities in Synology BeeStation devices to enable unauthenticated attackers to remotely gain root access. Demonstrated initially…

5 months ago

Arizona Attorney General Sues Chinese Retailer Temu Over Alleged Data Theft

Arizona Attorney General Kris Mayes has filed a landmark lawsuit against Chinese e-commerce giant Temu and its parent company, PDD…

5 months ago

India’s New SIM Registration Requirement For WhatsApp, Signal, Telegram, and Other Messaging Apps

India's Department of Telecommunications (DoT) has issued a directive mandating continuous SIM binding for popular messaging apps, requiring an active…

5 months ago

Critical Longwatch RCE Vulnerability Enables High-Privilege Remote Code Execution

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert for a remote code execution (RCE) vulnerability…

5 months ago

Authorities Seize Domains Linked To Tai Chang Cryptocurrency Investment Scam

The U.S. Justice Department has seized a key web domain used in a major cryptocurrency investment fraud scheme tied to…

5 months ago

Angular Platform Flaw Enables Malicious Code Execution Through Weaponized SVG Animations

Security researchers have uncovered a stored cross-site scripting (XSS) vulnerability in Angular's Template Compiler that lets attackers inject and execute…

5 months ago