RISK:STATION (CVE-2024-10443) – Unpatched Synology Devices at Risk of ...
RISK:STATION (CVE-2024-10443) – Unpatched Synology Devices at Risk of RCE Researchers have identified a zero-click vulnerability impacting Synology’s DiskStation and BeeStation devices, posing a signi...
November 2024 Android Security Update Fixes Actively Exploited Vulnera...
November 2024 Android Security Update Fixes Actively Exploited Vulnerabilities CVE-2024-43093, CVE-2024-43047 [Updated] November 8, 2024: “CISA Adds Android Vulnerability CVE-2024-43093 to KEV Catalog...
LottieFiles Supply Chain Attack: Compromised npm Package Targets Crypt...
LottieFiles Supply Chain Attack: Compromised npm Package Targets Cryptocurrency Wallets LottieFiles recently disclosed a major supply chain attack affecting its open-source JavaScript library, lottie-...
ServiceNow Now Platform Vulnerabilities Enable RCE and SQL Injection R...
ServiceNow Now Platform Vulnerabilities Enable RCE and SQL Injection Risks (CVE-2024-8923, CVE-2024-8924) – Patch Now ServiceNow’s Now Platform, known for its AI-driven tools that help business proces...
Over 22,000 CyberPanel Servers at Risk from Critical Vulnerabilities E...
Over 22,000 CyberPanel Servers at Risk from Critical Vulnerabilities Exploitation by PSAUX Ransomware Threat actor’s have been actively exploiting three Remote Code Execution (RCE) vulnerabilities in ...
Global Cybersecurity Coalition Brings Down Major Infostealer Malware O...
Global Cybersecurity Coalition Brings Down Major Infostealer Malware Operations In a recent milestone for international cybersecurity, authorities from around the world successfully dismantled the Red...
New Zero-Day Vulnerability in Windows Themes Threatens NTLM Security
New Zero-Day Vulnerability in Windows Themes Threatens NTLM Security A newly discovered zero-day vulnerability in Windows Themes files exposes users’ NTLM credentials, posing serious risks for remote ...
Free ISP Breach Compromises Millions, Threat Actor Threatens Data Leak
Free ISP Breach Compromises Millions, Threat Actor Threatens Data Leak Free, a leading French ISP and subsidiary of Iliad Group, confirmed a major data breach on October 26, 2024, impacting millions o...
Lazarus Exploits Google Chrome Zero-Day to Steal Cryptocurrency in ‘De...
Lazarus Exploits Google Chrome Zero-Day to Steal Cryptocurrency in ‘DeTankZone’ Campaign (CVE-2024-4947) Earlier in 2024, the North Korean Lazarus APT group exploited a critical zero-day vulnerability...
FortiManager Zero-Day ‘FortiJump’ Is Now Publicly Addressed (CVE-2024-...
FortiManager Zero-Day ‘FortiJump’ Is Now Publicly Addressed (CVE-2024-47575) [Update] November 18, 2024: “PoC Released for FortiJump Vulnerability (CVE-2024-47575)” [Update] October 25, 2024: “The Fl...
Roundcube Vulnerability (CVE-2024-37383) Exploited in Phishing Attacks...
Roundcube Vulnerability (CVE-2024-37383) Exploited in Phishing Attacks Targeting Government Agencies for Credential Theft A vulnerability in the popular open-source Roundcube Webmail, CVE-2024-37383, ...
ScienceLogic SL1 0-Day from Rackspace Breach Added to CISA KEV (CVE-20...
ScienceLogic SL1 0-Day from Rackspace Breach Added to CISA KEV (CVE-2024-9537) A critical security vulnerability was recently discovered in the ScienceLogic SL1 Portal (formerly EM7), exploited as a z...
IntelBroker’s Alleged Cisco Breach: A Deep Dive into the Claims and Re...
IntelBroker’s Alleged Cisco Breach: A Deep Dive into the Claims and Responses [Update] December 31, 2024: “Cisco Confirms Data Leak by IntelBroker and Provides Update” [Update] December 25, 2024: “In...
Critical VMware Vulnerability Patched Again in vCenter Server: CVE-202...
Critical VMware Vulnerability Patched Again in vCenter Server: CVE-2024-38812 [Updated] November 19, 2024: “VMware vCenter Server Vulnerabilities (CVE-2024-38812 and CVE-2024-38813) Actively Exploited...
An Overview of Microsoft Digital Defense Report 2024
An Overview of Microsoft Digital Defense Report 2024 The Microsoft Digital Defense Report 2024 offers a detailed view of the increasingly intricate global cybersecurity landscape. The tech giant revea...
Critical Vulnerabilities Affecting GitHub Enterprise Server, Kubernete...
Critical Vulnerabilities Affecting GitHub Enterprise Server, Kubernetes Image Builder, and GiveWP Plugin Recently, several critical vulnerabilities have been disclosed, affecting widely used platforms...
Major Cyber Attacks in Review: September 2024
Major Cyber Attacks in Review: September 2024 September 2024 saw a wave of major cyber attacks hitting critical sectors. BingX and Indodax, two prominent cryptocurrency platforms, suffered combined lo...
Internet Archive Data Breach and DDoS Attacks: What You Need to Know
Internet Archive Data Breach and DDoS Attacks: What You Need to Know [Update] October 21, 2024: “New Breach Hits Internet Archive, API Keys and Source Code Exposed” The Internet Archive has come under...
Critical Vulnerabilities in Palo Alto Networks Expedition Could Expose...
Critical Vulnerabilities in Palo Alto Networks Expedition Could Expose Firewall Credentials, Patch Available [Updated] November 15, 2024: “CISA Alerts of Active Exploitation: CVE-2024-9463 and CVE-202...
New Ivanti CSA Zero-Days Under Active Exploitation; Critical RCE in Co...
New Ivanti CSA Zero-Days Under Active Exploitation; Critical RCE in Connect Secure & Policy Secure [UPDATE] October 14, 2024: “Nation-State Attack Exploits Ivanti CSA Vulnerabilities, More Details...