Tag: denial-of-service (DoS)

Fake ad blocker extension crashes the browser for ClickFix attacks
News

Fake ad blocker extension crashes the browser for ClickFix attacks

NexShield is a phony ad-blocking Chrome and Edge extension used in a malvertising campaign that purposefully crashes the browser in advance of ClickFix attacks. The attacks, which were discovered earlier this month, resulted in the deployment of ModeloRAT, a new Python-based remote access tool used in business settings. Raymond Hill, the creator of the authentic uBlock Origin ad blocker with over 14 million users, marketed the NexShield extension, which was taken down from the Chrome Web Store, as a high-performance, lightweight, privacy-focused ad blocker. NexShield causes a denial-of-service (DoS) problem in the browser by repeatedly establishing "chrome.runtime" port connections and depleting its memory resources according to researchers read more about Fake ad blocker extensi...
Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login
News

Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login

A proof-of-concept (PoC) exploit for a high-severity security vulnerability affecting GlobalProtect Gateway and Portal has been provided by Palo Alto Networks. A denial-of-service (DoS) situation affecting GlobalProtect PAN-OS software has been identified as the vulnerability, tagged as CVE-2026-0227 (CVSS score: 7.7), which results from an incorrect check for exceptional conditions (CWE-754). In an advisory published on Wednesday, Palo Alto Networks stated that a flaw in the PAN-OS software allows an unauthorized attacker to launch a denial-of-service (DoS) attack on the firewall. The firewall goes into maintenance mode after multiple efforts to cause this problem. The following versions are impacted by the problem, which was found and reported by an anonymous outside researcher...
Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software
News

Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software

Cisco has alerted users to a high-severity security vulnerability in IOS and IOS XE software that, under certain situations, might cause a denial-of-service (DoS) issue or enable a remote attacker to run arbitrary code. After local Administrator credentials were hacked, the organization discovered that the vulnerability, CVE-2025-20352 (CVSS score: 7.7), had been exploited in the wild. According to the networking equipment major, the problem stems from a stack overflow condition and is based in the Simple Network Management Protocol (SNMP) subsystem. By sending a specially constructed SNMP packet to an impacted device via IPv4 or IPv6 networks, an authenticated remote attacker could take advantage of the vulnerability. If they have low privileges, this could result in DoS attacks...
FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage
News

FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage

A seven-year-old security hole in Cisco IOS and Cisco IOS XE software has been regularly exploited by Static Tundra, a Russian state-sponsored cyber espionage group, to gain continuous access to target networks. According to Cisco Talos, which made the activity public, the attacks target companies in the manufacturing, telecommunications, and higher education sectors in North America, Asia, Africa, and Europe. According to the statement, recent efforts have been made against Ukraine and its allies since the start of the Russo-Ukrainian war in 2022, and prospective victims are selected based on their "strategic interest" to Russia. The vulnerability in question is CVE-2018-0171 (CVSS score: 9.8), a serious weakness in Cisco IOS Software and Cisco IOS XE software's Smart Install capab...
Over 300K Prometheus Instances Exposed Credentials and API Keys Leaking Online
News

Over 300K Prometheus Instances Exposed Credentials and API Keys Leaking Online

Cybersecurity experts are cautioning that the Prometheus monitoring and alerting toolkit's thousands of servers are vulnerable to remote code execution (RCE) and denial-of-service (DoS) assaults, as well as information leaks. In a recent post released to The Hacker News, Aqua security researchers Yakir Kadkoda and Assaf Morag said that because Prometheus servers or exporters frequently lacked adequate authentication, attackers were able to obtain sensitive data, including credentials and API keys, with ease. The cloud security company added that the servers may become inoperable due to DoS attacks if the "/debug/pprof" endpoints, which are used to measure heap memory utilization, CPU usage, and other metrics, were made public. Up to 40,300 Prometheus servers and 296,000 Prometheu...