The Breach News

Exploiting Virtual Reality: Researchers Target the Popular Bigscreen VR App

A team of cybersecurity researchers from the University of New Haven has unveiled significant vulnerabilities within a popular virtual reality (VR) application known as Bigscreen. Their findings, shared exclusively with The Hacker News, highlight how these flaws could allow malicious actors to compromise users’ privacy and security during VR interactions,…

Read MoreExploiting Virtual Reality: Researchers Target the Popular Bigscreen VR App

New Vulnerabilities Reactivate DMA Attacks on a Variety of Modern Computers

New Vulnerabilities Expose All Major Operating Systems to DMA Attacks Recent research has unveiled a significant security concern that affects widely-used operating systems, including Microsoft Windows, Apple macOS, Linux, and FreeBSD. These vulnerabilities allow attackers to potentially bypass existing security measures against Direct Memory Access (DMA) attacks by exploiting newly…

Read MoreNew Vulnerabilities Reactivate DMA Attacks on a Variety of Modern Computers

How a USB Speaker Can Infiltrate a PC Without Direct Interaction

In a recent cybersecurity incident involving a speaker model known as the Katana V2X, a researcher successfully manipulated its firmware to explore potential vulnerabilities. After replacing the original firmware with a modified version that displayed the word “patched” on the speaker’s LED, the researcher turned his focus to FreeRTOS—the open-source…

Read MoreHow a USB Speaker Can Infiltrate a PC Without Direct Interaction

New Zero-Day Vulnerability in Google Chrome Discovered and Actively Exploited

A critical security vulnerability has been identified in Google Chrome that poses a significant risk to users. Discovered by Clement Lecigne, a security researcher from Google’s Threat Analysis Group, this flaw could enable remote attackers to execute arbitrary code, potentially giving them complete control over affected systems. Designated as CVE-2019-5786,…

Read MoreNew Zero-Day Vulnerability in Google Chrome Discovered and Actively Exploited

Microsoft Issues Patches for 64 Vulnerabilities, Including Two Currently Under Attack

Microsoft has rolled out a series of crucial updates as part of its monthly “Patch Tuesday” initiative, aiming to address a total of 64 CVE-listed vulnerabilities in its Windows operating systems and various applications. Among these vulnerabilities, 17 have been classified as critical, 45 as important, while one is considered…

Read MoreMicrosoft Issues Patches for 64 Vulnerabilities, Including Two Currently Under Attack

Patched WinRAR Vulnerability Remains Under Active Exploitation Due to Lack of Auto-Updates

Critical Vulnerability in WinRAR Exploited by Cybercriminals Recent reports have highlighted that cybercriminal groups and independent hackers are actively taking advantage of a critical code execution vulnerability in WinRAR, a widely-used file compression tool with a user base of over 500 million. The vulnerability, designated CVE-2018-20250, was patched in the…

Read MorePatched WinRAR Vulnerability Remains Under Active Exploitation Due to Lack of Auto-Updates

Libssh Releases Update to Address Nine Security Vulnerabilities

Libssh2 Addresses Critical Security Vulnerabilities in Latest Update Libssh2, an open-source C library widely utilized for SSHv2 communication, has released a critical update aimed at addressing nine security vulnerabilities. This release underscores the persistent security risks inherent in widely used libraries and highlights the necessity for developers and organizations to…

Read MoreLibssh Releases Update to Address Nine Security Vulnerabilities

Dashlane Reveals How Attackers Successfully Downloaded Encrypted Password Vaults

In a recent cybersecurity incident involving Dashlane, attackers gained access to encrypted user vaults, raising concerns about the robustness of the platform’s security measures. While the strength of users’ master passwords plays a critical role in preventing unauthorized access, it is essential to note that not all users adhere to…

Read MoreDashlane Reveals How Attackers Successfully Downloaded Encrypted Password Vaults