CISA Breaks Silence on Controversial ‘Airport Security Bypass’ Vulnerability 

Researchers and the TSA have different views on the impact of vulnerabilities in an airport security application that could allegedly allow the bypass of certain airport security systems.

The post CISA Breaks Silence on Controversial ‘Airport Security Bypass’ Vulnerability  appeared first on SecurityWeek.

SecurityWeek – ​Read More

Critical Zero-Click Exploit Discovered in Popular Wi-Fi Chipsets, PoC Published

CVE-2024-20017 is a critical zero-click exploit found in popular Wi-Fi chipsets like MediaTek MT7622/MT7915. The vulnerability allows remote code execution without user interaction, posing a severe risk with a CVSS score of 9.8.

Cyware News – Latest Cyber News – ​Read More

Critical Security Flaw Found in LiteSpeed Cache Plugin for WordPress

Cybersecurity researchers have discovered yet another critical security flaw in the LiteSpeed Cache plugin for WordPress that could allow unauthenticated users to take control of arbitrary accounts.
The vulnerability, tracked as CVE-2024-44000 (CVSS score: 7.5), impacts versions before and including 6.4.1. It has been addressed in version 6.5.0.1. 
“The plugin suffers from an

The Hacker News – ​Read More

Fake OnlyFans Tool Backstabs Cybercriminals, Steals Passwords

A fake OnlyFans tool circulating among hackers promises to help steal accounts but actually infects them with the Lumma stealer malware, as discovered by Veriti Research.

Cyware News – Latest Cyber News – ​Read More

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution

A new security flaw has been addressed in the Apache OFBiz open-source enterprise resource planning (ERP) system that, if successfully exploited, could lead to unauthenticated remote code execution on Linux and Windows.
The high-severity vulnerability, tracked as CVE-2024-45195 (CVSS score: 7.5), affects all versions of the software before 18.12.16.

“An attacker with no valid

The Hacker News – ​Read More

Pavel Durov Criticizes Outdated Laws After Arrest Over Telegram Criminal Activity

Telegram CEO Pavel Durov has broken his silence nearly two weeks after his arrest in France, stating the charges are misguided.
“If a country is unhappy with an internet service, the established practice is to start a legal action against the service itself,” Durov said in a 600-word statement on his Telegram account.
“Using laws from the pre-smartphone era to charge a CEO with crimes committed

The Hacker News – ​Read More

RansomHub Claims Planned Parenthood Hack, Steals 93GB of Sensitive Data

RansomHub claims to have breached Intermountain Planned Parenthood, stealing 93GB of data. The healthcare provider is investigating the…

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

What is the Shared Fate Model?

New threats, an overburdened workforce, and regulatory pressures mean cloud service providers need a more resilient model than the shared responsibility framework. That’s where “shared fate” comes in.

darkreading – ​Read More