Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks

27/06/2024 0 Comments 0 tags

Cybersecurity researchers have disclosed a high-severity security flaw in the Vanna.AI library that could be exploited to achieve remote code execution vulnerability via prompt injection techniques. The vulnerability, tracked as

Russian National Indicted for Cyber Attacks on Ukraine Before 2022 Invasion

27/06/2024 0 Comments 0 tags

A 22-year-old Russian national has been indicted in the U.S. for his alleged role in staging destructive cyber attacks against Ukraine and its allies in the days leading to Russia’s

Critical SQLi Vulnerability Found in Fortra FileCatalyst Workflow Application

27/06/2024 0 Comments 0 tags

A critical security flaw has been disclosed in Fortra FileCatalyst Workflow that, if left unpatched, could allow an attacker to tamper with the application database. Tracked as CVE-2024-5276, the vulnerability

New MOVEit Transfer Vulnerability Under Active Exploitation – Patch ASAP!

26/06/2024 0 Comments 0 tags

A newly disclosed critical security flaw impacting Progress Software MOVEit Transfer is already seeing exploitation attempts in the wild shortly after details of the bug were publicly disclosed. The vulnerability,

Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware

26/06/2024 0 Comments 0 tags

Threat actors with suspected ties to China and North Korea have been linked to ransomware and data encryption attacks targeting government and critical infrastructure sectors across the world between 2021

Practical Guidance For Securing Your Software Supply Chain

26/06/2024 0 Comments 0 tags

The heightened regulatory and legal pressure on software-producing organizations to secure their supply chains and ensure the integrity of their software should come as no surprise. In the last several

Apple Patches AirPods Bluetooth Vulnerability That Could Allow Eavesdropping

26/06/2024 0 Comments 0 tags

Apple has released a firmware update for AirPods that could allow a malicious actor to gain access to the headphones in an unauthorized manner. Tracked as CVE-2024-27867, the authentication issue

New Medusa Android Trojan Targets Banking Users Across 7 Countries

26/06/2024 0 Comments 0 tags

Cybersecurity researchers have discovered an updated version of an Android banking trojan called Medusa that has been used to target users in Canada, France, Italy, Spain, Turkey, the U.K., and

New Credit Card Skimmer Targets WordPress, Magento, and OpenCart Sites

26/06/2024 0 Comments 0 tags

Multiple content management system (CMS) platforms like WordPress, Magento, and OpenCart have been targeted by a new credit card web skimmer called Caesar Cipher Skimmer. A web skimmer refers to

Over 110,000 Websites Affected by Hijacked Polyfill Supply Chain Attack

26/06/2024 0 Comments 0 tags

Google has taken steps to block ads for e-commerce sites that use the Polyfill.io service after a Chinese company acquired the domain and modified the JavaScript library (“polyfill.js”) to redirect