Alert: Ivanti Discloses 2 New Zero-Day Flaws, One Under Active Exploitation

31/01/2024 0 Comments 0 tags

Ivanti is alerting of two new high-severity flaws in its Connect Secure and Policy Secure products, one of which is said to have come under targeted exploitation in the wild.

Telegram Marketplaces Fuel Phishing Attacks with Easy-to-Use Kits and Malware

31/01/2024 0 Comments 0 tags

Cybersecurity researchers are calling attention to the “democratization” of the phishing ecosystem owing to the emergence of Telegram as an epicenter for cybercrime, enabling threat actors to mount a mass

The SEC Won’t Let CISOs Be: Understanding New SaaS Cybersecurity Rules

31/01/2024 0 Comments 0 tags

The SEC isn’t giving SaaS a free pass. Applicable public companies, known as “registrants,” are now subject to cyber incident disclosure and cybersecurity readiness requirements for data stored in SaaS

Italian Businesses Hit by Weaponized USBs Spreading Cryptojacking Malware

31/01/2024 0 Comments 0 tags

A financially motivated threat actor known as UNC4990 is leveraging weaponized USB devices as an initial infection vector to target organizations in Italy. Google-owned Mandiant said the attacks single out multiple industries,

Chinese Hackers Exploiting VPN Flaws to Deploy KrustyLoader Malware

31/01/2024 0 Comments 0 tags

A pair of recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been exploited to deliver a Rust-based payload called KrustyLoader that’s used to drop the

New Glibc Flaw Grants Attackers Root Access on Major Linux Distros

31/01/2024 0 Comments 0 tags

Malicious local attackers can obtain full root access on Linux machines by taking advantage of a newly disclosed security flaw in the GNU C library (aka glibc). Tracked as CVE-2023-6246,

URGENT: Upgrade GitLab – Critical Workspace Creation Flaw Allows File Overwrite

30/01/2024 0 Comments 0 tags

GitLab once again released fixes to address a critical security flaw in its Community Edition (CE) and Enterprise Edition (EE) that could be exploited to write arbitrary files while creating

Brazilian Feds Dismantle Grandoreiro Banking Trojan, Arresting Top Operatives

30/01/2024 0 Comments 0 tags

A Brazilian law enforcement operation has led to the arrest of several Brazilian operators in charge of the Grandoreiro malware. The Federal Police of Brazil said it served five temporary arrest warrants and 13

China-Linked Hackers Target Myanmar’s Top Ministries with Backdoor Blitz

30/01/2024 0 Comments 0 tags

The China-based threat actor known as Mustang Panda is suspected to have targeted Myanmar’s Ministry of Defence and Foreign Affairs as part of twin campaigns designed to deploy backdoors and remote access

Top Security Posture Vulnerabilities Revealed

30/01/2024 0 Comments 0 tags

Each New Year introduces a new set of challenges and opportunities for strengthening our cybersecurity posture. It’s the nature of the field – the speed at which malicious actors carry