Zimbra Warns of Critical Zero-Day Flaw in Email Software Amid Active Exploitation

16/07/2023 0 Comments 0 tags

Zimbra has warned of a critical zero-day security flaw in its email software that has come under active exploitation in the wild. “A security vulnerability in Zimbra Collaboration Suite Version

New SOHO Router Botnet AVrecon Spreads to 70,000 Devices Across 20 Countries

16/07/2023 0 Comments 0 tags

A new malware strain has been found covertly targeting small office/home office (SOHO) routers for more than two years, infiltrating over 70,000 devices and creating a botnet with 40,000 nodes

TeamTNT’s Cloud Credential Stealing Campaign Now Targets Azure and Google Cloud

16/07/2023 0 Comments 0 tags

A malicious actor has been linked to a cloud credential stealing campaign in June 2023 that’s focused on Azure and Google Cloud Platform (GCP) services, marking the adversary’s expansion in

AIOS WordPress Plugin Faces Backlash for Storing User Passwords in Plaintext

16/07/2023 0 Comments 0 tags

All-In-One Security (AIOS), a WordPress plugin installed on over one million sites, has issued a security update after a bug introduced in version 5.1.9 of the software caused users’ passwords

Defend Against Insider Threats: Join this Webinar on SaaS Security Posture Management

16/07/2023 0 Comments 0 tags

As security practices continue to evolve, one primary concern persists in the minds of security professionals—the risk of employees unintentionally or deliberately exposing vital information. Insider threats, whether originating from

Critical Security Flaws Uncovered in Honeywell Experion DCS and QuickBlox Services

16/07/2023 0 Comments 0 tags

Multiple security vulnerabilities have been discovered in various services, including Honeywell Experion distributed control system (DCS) and QuickBlox, that, if successfully exploited, could result in severe compromise of affected systems.

Microsoft Bug Allowed Hackers to Breach Over Two Dozen Organizations via Forged Azure AD Tokens

16/07/2023 0 Comments 0 tags

Microsoft on Friday said a validation error in its source code allowed for Azure Active Directory (Azure AD) tokens to be forged by a malicious actor known as Storm-0558 using a Microsoft

WormGPT: New AI Tool Allows Cybercriminals to Launch Sophisticated Cyber Attacks

16/07/2023 0 Comments 0 tags

With generative artificial intelligence (AI) becoming all the rage these days, it’s perhaps not surprising that the technology has been repurposed by malicious actors to their own advantage, enabling avenues

New Vulnerabilities Disclosed in SonicWall and Fortinet Network Security Products

13/07/2023 0 Comments 0 tags

SonicWall on Wednesday urged customers of Global Management System (GMS) firewall management and Analytics network reporting engine software to apply the latest fixes to secure against a set of 15

U.S. Government Agencies’ Emails Compromised in China-Backed Cyber Attack

13/07/2023 0 Comments 0 tags

An unnamed Federal Civilian Executive Branch (FCEB) agency in the U.S. detected anomalous email activity in mid-June 2023, leading to Microsoft’s discovery of a new China-linked espionage campaign targeting two dozen organizations.