October 11, 2024 | Cybernews
A critical security vulnerability, tracked as CVE-2024-9680, has been identified in Mozilla Firefox, allowing remote attackers to execute arbitrary code, with active exploitation reported in the wild.
October 10, 2024 | Cybernews
Multiple significant security vulnerabilities in the Manufacturing Message Specification (MMS) protocol, affecting MZ Automation’s and Triangle MicroWorks’ libraries, pose serious risks to industrial environments, including potential device crashes and remote code execution.
October 1, 2024 | Cybernews
NVIDIA has patched a severe vulnerability, CVE-2024-0132, allowing threat actors to potentially gain full root privileges on host systems through container escapes.
September 26, 2024 | Cybernews
Google’s adoption of memory-safe languages like Rust has significantly decreased memory safety vulnerabilities in Android over a six-year period.
September 26, 2024 | Cybernews
Attackers exploited a memory feature in ChatGPT to implant spyware, enabling continuous data exfiltration of user input and responses.
September 23, 2024 | Cybernews
Researchers have found a critical-rated zero-click vulnerability in MediaTek Wi-Fi chipsets that allows for remote code execution without user interaction, affecting routers and smartphones from various manufacturers.
September 16, 2024 | Cybernews
Researchers discover GAZEploit exploit in Vision Pro headset, enabling hackers to decipher passwords and messages typed with the eyes.
August 30, 2024 | Cybernews
A zero-day vulnerability in AVTECH AVM1203 security cameras has been actively exploited for five years, posing a high-severity risk to organizations.
August 16, 2024 | Cybernews
ValleyRAT malware poses a significant threat to Chinese-speaking individuals and industries, utilizing shellcode, sleep obfuscation, XOR encoding, AES-256 decryption, reflective DLL loading, API hashing, and callback procedures to evade detection and control victims.
August 12, 2024 | Cybernews
Researchers from NCC Group have identified vulnerabilities in Sonos smart speakers that could allow attackers to eavesdrop on users by exploiting memory corruption and arbitrary code execution flaws.