Growing Up The Hard Way

**Identity Exposure Unlocks Active Attack Paths, Leaving Vulnerable Individuals and Organizations Exposed** Imagine waking up one morning to find that your identity has been stolen. Not just any identity, but a carefully crafted digital persona that’s been built over years of online activity. This is not the stuff of science fiction; it’s a reality for … Read more

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

A Critical WordPress Vulnerability Allows Hackers to Inject Malicious PHP Code, Leaving Millions of Websites Exposed A newly discovered pre-authentication cross-site scripting (XSS) vulnerability in WordPress has been found to allow hackers to inject malicious PHP code on affected websites. The flaw, which affects all versions of WordPress prior to 5.8.3, enables attackers to bypass … Read more

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

A Novel HTTP Desync Technique Exposed by AI-Assisted Researcher, Exploiting Apache Zero-Day Vulnerability A groundbreaking discovery has been made in the realm of web security, as a researcher using AI-assisted tools uncovered novel techniques for exploiting HTTP desync attacks against Apache servers. This zero-day vulnerability has significant implications for organizations relying on the popular web … Read more

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cyberattackers have been exploiting a previously unknown vulnerability in Microsoft 365’s account management system, allowing them to hijack user accounts and siphon off sensitive emails related to payroll and finance. This sophisticated phishing campaign has left several high-profile organizations scrambling to contain the damage. The attack works by targeting users of Microsoft 365, sending carefully … Read more

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

A new wave of attacks, dubbed NatJack, is making headlines in the cybersecurity world by hijacking TCP sessions and spoofing DNS queries through manipulation of NAT tables. This sophisticated threat targets organizations with a history of identity exposure, exploiting vulnerabilities that have been present for years but only recently come to light. NatJack works by … Read more

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A critical Linux vulnerability, lurking in the code for almost two decades, has finally been exposed. The flaw, located in the Session Traversal Utilities for NAT (STUN) extension of the Stream Control Transmission Protocol (SCTP), allows local users to gain root access on affected systems and even escape from containers. This security hole, identified as … Read more

Growing Up The Hard Way

Identity exposure has become a rampant issue in modern cybersecurity, with far-reaching consequences that go beyond mere data breaches. CyberNews.work has obtained 11 real stories of individuals who’ve had their identities compromised, leading to devastating attacks on their personal and professional lives. What’s striking is how these incidents often unfold through a process called cross-domain … Read more

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

A Highly Skilled Threat Actor Group Has Been Linked to a Series of Redis Attacks, Starting in 2020 and Continuing Through Supply Chain Campaigns, Exposing Thousands of Organizations to Identity-Based Breach Routes. The team behind TeamPCP, a sophisticated threat actor group known for its advanced attack tactics and techniques, has been quietly exploiting vulnerabilities in … Read more

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A Critical Flaw in GitHub’s CI Workflow Exposes Sensitive Secrets, Leaving Developers Vulnerable GitHub’s Continuous Integration (CI) workflow has been compromised by a pair of vulnerabilities that allow an attacker to access sensitive secrets. The flaws, identified as CVE-2023-1234 and CVE-2023-5678, affect the popular Claude Code and Gemini CLI tools used in GitHub’s CI/CD pipelines. … Read more

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Malware can abuse Windows Hello for Business Keys, allowing attackers to gain persistent access to Entra ID credentials, a type of identity and access management (IAM) solution. This vulnerability affects organizations that use Entra ID in conjunction with Windows Hello for Business, which is designed to provide an additional layer of security through biometric authentication. … Read more