Researchers Uncover Flaws in Python Package for AI Models and PDF.js Used by Firefox

21/05/2024 0 Comments 0 tags

A critical security flaw has been disclosed in the llama_cpp_python Python package that could be exploited by threat actors to achieve arbitrary code execution. Tracked as CVE-2024-34359 (CVSS score: 9.7), the flaw has been

Streamlining IT Security Compliance Using the Wazuh FIM Capability

21/05/2024 0 Comments 0 tags

File Integrity Monitoring (FIM) is an IT security control that monitors and detects file changes in computer systems. It helps organizations audit important files and system configurations by routinely scanning

Windows 11 to Deprecate NTLM, Add AI-Powered App Controls and Security Defenses

21/05/2024 0 Comments 0 tags

 Microsoft on Monday confirmed its plans to deprecate NT LAN Manager (NTLM) in Windows 11 in the second half of the year, as it announced a slew of new security

NextGen Healthcare Mirth Connect Under Attack – CISA Issues Urgent Warning

21/05/2024 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a security flaw impacting NextGen Healthcare Mirth Connect to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The flaw,

“Linguistic Lumberjack” Vulnerability Discovered in Popular Logging Utility Fluent Bit

21/05/2024 0 Comments 0 tags

Cybersecurity researchers have discovered a critical security flaw in a popular logging and metrics utility called Fluent Bit that could be exploited to achieve denial-of-service (DoS), information disclosure, or remote

Iranian MOIS-Linked Hackers Behind Destructive Attacks on Albania and Israel

20/05/2024 0 Comments 0 tags

An Iranian threat actor affiliated with the Ministry of Intelligence and Security (MOIS) has been attributed as behind destructive wiping attacks targeting Albania and Israel under the personas Homeland Justice

Foxit PDF Reader Flaw Exploited by Hackers to Deliver Diverse Malware Arsenal

20/05/2024 0 Comments 0 tags

Multiple threat actors are weaponizing a design flaw in Foxit PDF Reader to deliver a variety of malware such as Agent Tesla, AsyncRAT, DCRat, NanoCore RAT, NjRAT, Pony, Remcos RAT,

Defending Your Commits From Known CVEs With GitGuardian SCA And Git Hooks

20/05/2024 0 Comments 0 tags

All developers want to create secure and dependable software. They should feel proud to release their code with the full confidence they did not introduce any weaknesses or anti-patterns into

Cyber Criminals Exploit GitHub and FileZilla to Deliver Cocktail Malware

20/05/2024 0 Comments 0 tags

A “multi-faceted campaign” has been observed abusing legitimate services like GitHub and FileZilla to deliver an array of stealer malware and banking trojans such as Atomic (aka AMOS), Vidar, Lumma

Latrodectus Malware Loader Emerges as IcedID’s Successor in Phishing Campaigns

20/05/2024 0 Comments 0 tags

Cybersecurity researchers have observed a spike in email phishing campaigns starting early March 2024 that delivers Latrodectus, a nascent malware loader believed to be the successor to the IcedID malware. “These