
OpenVPN Access Server Vulnerabilities: Risk of Information Exposure, D...
OpenVPN Access Server Vulnerabilities: Risk of Information Exposure, DoS, and RCE (CVE-2023-46849, CVE-2023-46850) Last week, OpenVPN Access Server, a widely-used open-source VPN solution, received an...

Lessons Learned From Israel-Hamas Conflict: A Cybersecurity Perspectiv...
Lessons Learned From Israel-Hamas Conflict: A Cybersecurity Perspective The Israel-Hamas conflict, which started with the surprise attack of Hamas militants on Israeli territory on October 7, escalate...

Sumo Logic Security Breach: Unauthorized Access to AWS with Stolen Cre...
Sumo Logic Security Breach: Unauthorized Access to AWS with Stolen Credentials Sumo Logic, a cybersecurity company renowned for its expertise in cloud-based log management, analytics, and insights, re...

Path Traversal Leading to Compromise: SysAid On-Prem Software CVE-2023...
Path Traversal Leading to Compromise: SysAid On-Prem Software CVE-2023-47246 Vulnerability [Update] November 15, 2023: See the subheadings: “Nuclei Template Now Available, Scan for the SysAid Vulnerab...

Surge in Attention Towards Critical Vulnerabilities in QNAP QTS and NA...
Surge in Attention Towards Critical Vulnerabilities in QNAP QTS and NAS Services (CVE-2023-23368, CVE-2023-23369) QNAP recently published advisories for two critical command injection vulnerabilities,...

New Microsoft Exchange Zero-Day Vulnerabilities Could Lead to RCE, SSR...
New Microsoft Exchange Zero-Day Vulnerabilities Could Lead to RCE, SSRF (ZDI-23-1578, ZDI-23-1579, ZDI-23-1580, ZDI-23-1581) The discovery of four new zero-day vulnerabilities in Microsoft Exchange is...

New Gootloader Variant “GootBot” Changes the Game in Malware Tactics...
New Gootloader Variant “GootBot” Changes the Game in Malware Tactics Researchers recently identified a fresh Gootloader malware variant known as “GootBot,” used in SEO poisoning attacks. T...

Critical RCE Vulnerability in Apache ActiveMQ Is Targeted by HelloKitt...
Critical RCE Vulnerability in Apache ActiveMQ Is Targeted by HelloKitty Ransomware (CVE-2023-46604) [Update] December 19, 2023: “Ongoing Exploitation of Apache ActiveMQ Vulnerability: Threat Actors L...

Atlassian CISO Announced: Improper Authorization Vulnerability Detecte...
Atlassian CISO Announced: Improper Authorization Vulnerability Detected on Confluence Data Center and Server (CVE-2023-22518) [Update] April 18, 2023: “Cerber Ransomware Exploits CVE-2023-22518 in Con...

Dark Opinion: Doing Things Under the Rose, Proxy Data Recovery Compani...
Dark Opinion: Doing Things Under the Rose, Proxy Data Recovery Companies for Ransomware Negotiation During the pandemic, a lot of untrue stories spread around. This happened a lot after people started...

New Bulletin by CISA on Rising Vulnerabilities: Apache, BIG-IP, IBM, V...
New Bulletin by CISA on Rising Vulnerabilities: Apache, BIG-IP, IBM, VMware, WordPress, and More The Cybersecurity and Infrastructure Security Agency (CISA) released a summary of new vulnerabilities w...

SIM Swappers Collaborate with Ransomware Gangs
SIM Swappers Collaborate with Ransomware Gangs In today’s digital world, the landscape of cyber threats is changing rapidly. One of the latest developments in this arena is the alliance between ...

High-Severity VMware Tools and vCenter Server Vulnerabilities Addresse...
High-Severity VMware Tools and vCenter Server Vulnerabilities Addressed with Recent Patches (CVE-2023-34057, CVE-2023-34058, CVE-2023-34048) [Update] January 23, 2024: ”VMware Confirms Active Exploit...

Critical Vulnerability in F5 BIG-IP Configuration Utility Allows Reque...
Critical Vulnerability in F5 BIG-IP Configuration Utility Allows Request Smuggling, Leads to RCE: CVE-2023-46747 [Update] November 1, 2023: See the subheading: “F5 Reports Active Exploitation of CVE-2...

KillNet Announces Launch of A New DDoS Service
KillNet Announces Launch of A New DDoS Service During the cyberwarfare caused by the Israel-Palestine conflict and Russia’s invasion of Ukraine in cybersecurity, it’s paramount to stay upd...

On Threat Actors' Radar: PoC Exploits for VMware Aria Operations Vulne...
On Threat Actors’ Radar: PoC Exploits for VMware Aria Operations Vulnerability (CVE-2023-34051), and More Newly discovered vulnerabilities are a constant source of concern for the cybersecurity ...

Security Breach in Okta Support System Continues Sparking Concerns: Cl...
Security Breach in Okta Support System Continues Sparking Concerns: Cloudflare and 1Password Share Disclosures [Update] November 29, 2023: A recent audit uncovered a broader data theft scope in the Oc...

Cyber Awakeness Month: Takedown of Trigona, Hive Ransomware Resurges, ...
Cyber Awakeness Month: Takedown of Trigona, Hive Ransomware Resurges, RansomedForum and New RaaS ‘qBit’ From the takedown of Trigona to the resurgence of Hive Ransomware, and the emergence of a new ha...

SolarWinds Releases Crucial Fixes for ARM Security Vulnerabilities (CV...
SolarWinds Releases Crucial Fixes for ARM Security Vulnerabilities (CVE-2023-35182, CVE-2023-35185, and CVE-2023-35187) In the ever-evolving landscape of cybersecurity, staying ahead of threats is par...

Taking the Power of ChatGPT Behind You for Enhanced Cybersecurity: A G...
Taking the Power of ChatGPT Behind You for Enhanced Cybersecurity: A Guide for CISOs In today’s rapidly evolving digital landscape, Chief Information Security Officers (CISOs) face an uphill bat...