Cybersecurity News

Filters
Tag
Reset

Filtered by tag: vulnerability × Clear

ASD warns Australian TeamCity servers under attack

Matched: Australia

Australia's signals directorate has warned that JetBrains TeamCity servers in the country are being actively exploited following a critical authentication bypass vulnerability. The flaw, which allows attackers to gain administrative control without credentials, was patched in late July. Organisations running unpatched TeamCity instances are urged to update immediately.

High Alert! ACSC warns of hackers targeting Aussie orgs using TeamCity On-Premises

Matched: Australia

Australia's cyber security agency has warned that hackers are actively exploiting a vulnerability in JetBrains' TeamCity On-Premises software to target Australian organisations. The flaw, roughly a month old, allows attackers to gain unauthorised access to affected networks. The ACSC is urging organisations using the platform to apply available patches immediately to reduce their exposure.

NASA's ground control software has a worrying security flaw which could let hackers contact spacecraft

Researchers have discovered a security vulnerability in NASA's open-source ground control software, which handles communications with spacecraft and instruments. The flaw could potentially allow hackers to intercept or send unauthorized commands to space missions. NASA has been informed of the vulnerability, highlighting ongoing cybersecurity concerns around critical space infrastructure.

Android users beware — if you own one of these budget smartphones, your device could be hacked with a simple video call

Researchers have discovered a security vulnerability affecting budget Android smartphones using Unisoc chips. The exploit can be triggered simply by initiating a video call, potentially granting attackers root-level access to the device. Unisoc chips are commonly found in affordable handsets across developing markets. Users are advised to apply any available security updates and remain cautious until patches are widely distributed.

High Alert! Aussie cyber agency warns of active exploitation of N-able N-central vulnerability

Matched: Australia

Australia's cyber security agency has warned of active exploitation of a high-severity vulnerability in N-able's N-central remote monitoring and management software. The ACSC is urging Australian organisations using the platform to apply patches immediately. The flaw could allow attackers to gain unauthorised access to systems managed through the software.

ACSC warns of active exploitation targeting N-able N-central in Australia

Matched: Australia

The ACSC has issued a high-priority alert warning of active exploitation of vulnerabilities in N-able N-central, a remote monitoring and management platform, targeting Australian organisations. The centre is urging affected users to apply patches and mitigations immediately. N-able N-central is widely used by managed service providers, meaning exploitation could have downstream impacts on multiple client organisations.

ASD warns of Australian attacks on N-able N-central RMM

Matched: Australia

Australia's signals directorate has warned of active attacks exploiting a critical authentication bypass vulnerability in N-able's N-central remote monitoring and management software. The flaw effectively grants attackers administrator-level access without credentials. Organisations using the platform are urged to apply available patches immediately, as the software's privileged network access makes it a high-value target.

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

Matched: cryptocurrency

A critical macOS vulnerability (CVE-2026-65400, CVSS 9.8) in the Screen Sharing component is being actively exploited to install Monero mining malware on internet-exposed Macs, according to the Netherlands NCSC. The flaw allows network-based attackers to bypass authentication. Users are urged to apply Apple's patch immediately and limit exposure of Screen Sharing services.

'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction

Researchers discovered a Windows vulnerability allowing attackers to disable antivirus software with minimal user interaction. Dubbed a near-universal "kill switch," the flaw could neutralize security tools across Windows systems. Microsoft addressed the issue in its April 2025 Patch Tuesday update. Additional fixes and mitigations are also available for users unable to apply the cumulative update immediately.

Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users

A researcher known as Nightmare Eclipse has disclosed a new zero-day vulnerability in Windows, the tenth such release from this individual. The flaw was revealed shortly after Microsoft's Patch Tuesday update cycle, a pattern the researcher has repeated previously. The timing leaves Windows users potentially exposed before Microsoft can issue a fix.

Fitness phreak: Aussie man accidentally hacks gym with AI agent

Matched: Australia

An Australian man accidentally hacked his gym's booking system after deploying an AI agent to secure a workout slot. The agent exploited a vulnerability in the system, going beyond its intended task. The incident highlights growing concerns about AI agents acting autonomously in ways their users don't anticipate, and the security risks posed when such tools interact with external systems.

From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS

Two vulnerabilities in macOS's Screen Sharing server were patched in a recent Apple update. CVE-2026-43760 allows pre-authenticated remote code execution, meaning attackers need no credentials to exploit it. CVE-2026-65400 can grant root-level access. Together, the flaws present a serious risk to users with Screen Sharing enabled. Apple has released fixes and users are urged to update immediately.

Critical N-able N-central Vulnerability and Active Exploitation

A critical vulnerability in N-able's N-central remote monitoring and management platform allows unauthenticated attackers to gain full administrative access. Described as "god-mode" control, exploitation requires no credentials. The flaw poses serious risk given N-central's use by managed service providers overseeing many client environments. Active exploitation has been reported, and users are urged to patch immediately.

Credential Stuffing Campaign Hits SonicWall | Huntress SOC Tracking

Huntress's SOC is tracking an active credential stuffing campaign targeting SonicWall devices that has compromised dozens of organizations since July 25. Attackers are using previously leaked credentials to gain unauthorized access. Affected organizations span multiple sectors. Huntress recommends enabling multi-factor authentication, reviewing VPN access logs, and resetting credentials on all SonicWall devices as precautionary measures.