Critical SAP Flaw Allows Remote Attackers to Bypass Authentication

SAP has released a security patch package for August 2024, addressing 17 vulnerabilities, including a critical authentication bypass flaw (CVE-2024-41730) in the SAP BusinessObjects Business Intelligence Platform.

Cyware News – Latest Cyber News – ​Read More

Ivanti Patches Critical Vulnerabilities in Neurons for ITSM, Virtual Traffic Manager

Ivanti has released patches for multiple vulnerabilities in Neurons for ITSM, Avalanche, and Virtual Traffic Manager, including critical bugs.

The post Ivanti Patches Critical Vulnerabilities in Neurons for ITSM, Virtual Traffic Manager appeared first on SecurityWeek.

SecurityWeek – ​Read More

The AMD SinkClose security hole is dangerous. Here’s how to protect your systems

The flaw threatens servers, data centers, and clouds more than the PC in front of you.

Latest stories for ZDNET in Security – ​Read More

Manufacturer Orion SA says scammers conned it out of $60M

Orion SA recently disclosed to US regulators that it fell victim to a criminal wire fraud scheme resulting in a $60 million loss. The incident, possibly a BEC scam, involved fraudulent wire transfers to unknown third-party accounts by an employee.

Cyware News – Latest Cyber News – ​Read More

DeathGrip: Emergence of a new Ransomware-as-a-Service

Promoted through Telegram and other underground forums, DeathGrip RaaS offers aspiring threat actors on the dark web sophisticated ransomware tools, including LockBit 3.0 and Chaos builders.

Cyware News – Latest Cyber News – ​Read More

ICS Patch Tuesday: Advisories Released by Siemens, Schneider, Rockwell, Aveva

ICS Patch Tuesday advisories have been published by Siemens, Schneider Electric, Rockwell Automation, Aveva and CISA.

The post ICS Patch Tuesday: Advisories Released by Siemens, Schneider, Rockwell, Aveva appeared first on SecurityWeek.

SecurityWeek – ​Read More

Exploiting pfsense Flaw for Remote Code Execution

During a recent security audit by Laburity researchers, an application with a vulnerability related to pfblockerNG was identified. Attempts using default credentials failed, but an exploit from exploit-db was unsuccessful.

Cyware News – Latest Cyber News – ​Read More

New Banshee MacOS Stealer Attacking Users to Steal Keychain Data

The Banshee Stealer can rob sensitive data, including passwords from macOS Keychain, system information, and data from popular web browsers like Safari, Chrome, and Firefox. It can also access cryptocurrency wallets and plugins.

Cyware News – Latest Cyber News – ​Read More

Vulnerability in Windows Driver Leads to System Crashes

A vulnerability in the Windows CLFS.sys driver, identified as CVE-2024-6768, allows an unprivileged user to crash the system, leading to a Blue Screen of Death. The flaw is due to improper input validation and affects Windows 10 and 11.

Cyware News – Latest Cyber News – ​Read More

DDoS Attacks Surge 46% in First Half of 2024, Gcore Report Reveals

Monitoring evolving DDoS trends is essential for anticipating threats and adapting defensive strategies. The comprehensive Gcore Radar Report for the first half of 2024 provides detailed insights into DDoS attack data, showcasing changes in attack patterns and the broader landscape of cyber threats. Here, we share a selection of findings from the full report.
Key Takeaways
The number of DDoS

The Hacker News – ​Read More