Thursday , April 24 2025

infosecbulletin

Hackers Exploit AWS Misconfigurations: allegedly 2TB data lost

AWS

Thousands of AWS customers had terabytes of sensitive data, including personal details, AWS credentials, and proprietary code, compromised in a cyber attack linked to the ShinyHunters hacking group. They gained access to sensitive information through poorly set up systems, resulting in over 2 TB of compromised data. Cybersecurity researchers Noam …

Read More »

Microsoft December 2024 Patch Tuesday – 71 Vulnerabilities Fixed, 1 Zero-day

Microsoft

Microsoft published December 2024 Patch Tuesday, which includes security updates for 71 flaws, including one actively exploited zero-day vulnerability. This Patch Tuesday fixed sixteen critical vulnerabilities, all of which are remote code execution flaws. The number of bugs in each vulnerability category is listed below: 27 Elevation of Privilege Vulnerabilities3 …

Read More »

CISA listed Over 270 Critical Vulnerabilities: What’s New!

270 Critical Vulnerabilities

CISA has released a bulletin that lists over 270 Critical vulnerabilities discovered in various software and hardware in the past week. These vulnerabilities impact popular apps, operating systems, IoT devices, and development frameworks, creating significant risks if not fixed. Vulnerabilities have been categorized using the Common Vulnerability Scoring System (CVSS). …

Read More »

Google unveils ‘mindboggling’ quantum computing chip

quantum computing chip

Google has made a quantum computing chip that can finish tasks in five minutes, which would take conventional computers 10 undecillion (10,000,000,000,000,000,000,000,000 years) to complete. That’s 10 septillion years, a number much larger than the age of our universe, leading scientists behind a recent quantum computing breakthrough to describe it …

Read More »

Google’s released “Vanir” Open Sources Security Patch Validation Tool

Google

Google has announced Vanir, an open-source tool for detecting and fixing security vulnerabilities, publicly available for developers. Vanir is a source code-based static analysis tool that automatically identifies the list of missing security patches in the target system. By default, Vanir pulls up-to-date CVEs from Open Source Vulnerabilities (OSV) together …

Read More »

Hacker Claim 1tb, Deloitte denies, What Inside!

deloitte

The spokesperson from Deloitte told two international media that, “No Deloitte systems have been impacted,”. The allegations relate to a single client’s system which sits outside the Deloitte network, according to cybersecurity news and infosecuritynews. Times of India said, “Only a single client’s sensitive was impacted and none of the …

Read More »

New Windows zero-day: Exposes credentials, Gets unofficial patch

windows

A newly found zero-day vulnerability lets attackers steal NTLM credentials by manipulating targets into opening a malicious file in Windows Explorer. The 0patch team found a flaw and reported it to Microsoft, but no official fix has been released yet. 0patch reports that the issue affects all Windows versions from …

Read More »

Patch urgently: Hundred of CISCO switches impacted

CISCO switches

A bootloader vulnerability in Cisco NX-OS affects over 100 switches, enabling attackers to bypass image signature checks. Cisco issued security patches for the vulnerability CVE-2024-20397 (CVSS score of 5.2) in NX-OS software’s bootloader, which could allow attackers to bypass image signature verification. “A vulnerability in the bootloader of Cisco NX-OS …

Read More »