generalnews.media
All World Business Technology Science Health Sports Entertainment Security
318 stories
Exclusive

SASE's AI Blind Spot: Packet Inspection No Longer Sufficient

Security researchers highlight that SASE solutions are failing to address AI-generated threats, as traditional packet inspection cannot detect sophisticated attacks. This gap leaves organizations vulnerable to AI-driven malware and phishing. As cybercriminals increasingly leverage AI, security frameworks must evolve beyond packet inspection to incorporate AI-aware defenses.

Exclusive

Compromised npm Packages Spread Multi-Stage Botnet Malware

Attackers compromised several AsyncAPI npm packages to deliver multi-stage botnet malware. Developers who installed these packages unknowingly integrated malicious code into their systems. This incident highlights ongoing supply chain risks in open-source ecosystems.

security technology

Microsoft Issues Record Security Patches, Including Two Active Zero-Days

Microsoft released a record number of security updates, patching between 570 and 622 flaws—depending on the count—including two zero-day vulnerabilities that are currently being actively exploited. The unprecedented patch volume underscores the growing threat landscape and the urgent need for users to apply updates immediately.

Exclusive

SAP Fixes Critical NetWeaver ABAP Flaw Allowing Data Exposure

SAP has released a security patch for a critical vulnerability in its NetWeaver ABAP platform, rated 9.9 on the CVSS scale. The flaw could allow attackers to expose or modify sensitive data without authentication. Given SAP's widespread use in enterprise systems, this patch is urgent for affected organizations.

Exclusive

RabbitMQ flaws risk leaking OAuth secrets, exposing cross-tenant queue data

Security vulnerabilities in RabbitMQ could allow attackers to leak OAuth authentication secrets and expose queue metadata across different tenants. The flaws affect users of the open-source message broker, particularly in multi-tenant deployments. This matters because it could lead to unauthorized access to sensitive data and breach tenant isolation.

Exclusive

Eleven Old Microsoft-Signed Linux UEFI Shims Can Bypass Secure Boot

Researchers discovered that 11 outdated Microsoft-signed Linux UEFI shims can be exploited to bypass Secure Boot protections. Attackers could use these to load unsigned bootloaders or malware, compromising system security. This matters because it affects millions of devices relying on Secure Boot for trusted startup.

Exclusive

Joint Warning: Russian Cyber Threats Target Critical Infrastructure

CISA, the NSA, FBI, DC3, and international partners issued a joint warning about Russian state-sponsored cyber activity targeting communications, energy, government, and other critical infrastructure sectors. The advisory details tactics used by Russian threat actors and urges organizations to implement mitigations. This highlights ongoing cyber threats to essential services and the need for heightened vigilance.

Exclusive

OAuth Client ID Spoofing Allows Validation of Stolen Microsoft Entra Credentials

Attackers can exploit an OAuth client ID spoofing vulnerability to validate stolen Microsoft Entra credentials, enabling authentication without legitimate authorization. The flaw undermines the security of Microsoft's identity platform, potentially leading to account takeovers and unauthorized access. This issue highlights critical weaknesses in OAuth implementation.

Exclusive

148 npm Packages Pose as Student Proxies, Turn Browsers into DDoS Botnet

Researchers discovered 148 malicious npm packages disguised as student proxy tools. When installed, they hijack browsers to form a distributed denial-of-service (DDoS) botnet. This campaign exposes the risk of supply chain attacks targeting developers and students.