Aggregator
CVE-2024-50086 | Linux Kernel up to 6.1.113/6.6.57/6.11.4 ksmbd session_lock use after free (Nessus ID 213191 / WID-SEC-2024-3289)
CVE-2024-50084 | Linux Kernel up to 6.6.57/6.11.4 vcap_api_encode_rule_test use after free (20b5342de51b/170792097bb2/217a3d98d1e9 / Nessus ID 213018)
CVE-2024-50083 | Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4 request_sock_subflow_v4 net/mptcp/protocol.c denial of service (Nessus ID 212953 / WID-SEC-2024-3289)
Russian Espionage Group Static Tundra Targets Legacy Cisco Flaw
Florida man gets 10 years in prison in first Scattered Spider sentencing
Noah Urban’s sentence stems from a broader conspiracy involving four other defendants who conducted attacks from September 2021 to April 2023.
The post Florida man gets 10 years in prison in first Scattered Spider sentencing appeared first on CyberScoop.
Alleged Sale of RDWeb Access to an Unidentified Software Company in USA
Warlock Ransomware Exploiting SharePoint Vulnerabilities to Gain Access and Steal Credentials
In recent weeks, the cybersecurity community has witnessed the rapid emergence of Warlock, a novel ransomware strain that weaponizes unpatched Microsoft SharePoint servers to infiltrate enterprise networks. Initial analysis reveals that threat actors exploit publicly exposed SharePoint instances via specially crafted HTTP POST requests, deploying web shells that grant remote code execution within the target […]
The post Warlock Ransomware Exploiting SharePoint Vulnerabilities to Gain Access and Steal Credentials appeared first on Cyber Security News.
CIS Controls Ambassador Spotlight: Eric Woodard
CIS Controls Ambassador Spotlight: Eric Woodard
Prepping the Front Line for MFA Social Engineering Attacks
‘Rapper Bot’ hit the Pentagon in at least 3 cyberattacks
The post ‘Rapper Bot’ hit the Pentagon in at least 3 cyberattacks appeared first on CyberScoop.
Why Certified VMware Pros Are Driving the Future of IT
Internet Archive Abused for Hosting Stealthy JScript Loader Malware
Security researchers have uncovered a novel malware delivery chain in recent weeks that leverages the Internet Archive’s legitimate infrastructure to host obfuscated payloads. The attack begins with a seemingly innocuous JScript file delivered via malspam, which in turn invokes a PowerShell loader. This PowerShell script reaches out to the Internet Archive (archive.org) to retrieve a […]
The post Internet Archive Abused for Hosting Stealthy JScript Loader Malware appeared first on Cyber Security News.
Mozilla High Severity Vulnerabilities Enables Remote Code Execution
Mozilla has released Firefox 142 to address multiple high-severity security vulnerabilities that could allow attackers to execute arbitrary code remotely on affected systems. The security advisory, published on August 19, 2025, reveals nine distinct vulnerabilities ranging from sandbox escapes to memory safety bugs, with several classified as high-impact threats capable of enabling remote code execution […]
The post Mozilla High Severity Vulnerabilities Enables Remote Code Execution appeared first on Cyber Security News.