Microsoft Patches 61 Flaws, Including Two Actively Exploited Zero-Days

15/05/2024 0 Comments 0 tags

Microsoft has addressed a total of 61 new security flaws in its software as part of its Patch Tuesday updates for May 2024, including two zero-days which have been actively exploited in the wild. Of the 61

VMware Patches Severe Security Flaws in Workstation and Fusion Products

15/05/2024 0 Comments 0 tags

Multiple security flaws have been disclosed in VMware Workstation and Fusion products that could be exploited by threat actors to access sensitive information, trigger a denial-of-service (DoS) condition, and execute code under

New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation

15/05/2024 0 Comments 0 tags

Google on Monday shipped emergency fixes to address a new zero-day flaw in the Chrome web browser that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2024-4761,

Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code

14/05/2024 0 Comments 0 tags

The maintainers of the Cacti open-source network monitoring and fault management framework have addressed a dozen security flaws, including two critical issues that could lead to the execution of arbitrary code. The

6 Mistakes Organizations Make When Deploying Advanced Authentication

14/05/2024 0 Comments 0 tags

Deploying advanced authentication measures is key to helping organizations address their weakest cybersecurity link: their human users. Having some form of 2-factor authentication in place is a great start, but many organizations may

Ongoing Campaign Bombarded Enterprises with Spam Emails and Phone Calls

14/05/2024 0 Comments 0 tags

Cybersecurity researchers have uncovered an ongoing social engineering campaign that bombards enterprises with spam emails with the goal of obtaining initial access to their environments for follow-on exploitation. “The incident involves a

Apple and Google Launch Cross-Platform Feature to Detect Unwanted Bluetooth Tracking Devices

14/05/2024 0 Comments 0 tags

Apple and Google on Monday officially announced the rollout of a new feature that notifies users across both iOS and Android if a Bluetooth tracking device is being used to

Malicious Python Package Hides Sliver C2 Framework in Fake Requests Library Logo

14/05/2024 0 Comments 0 tags

Cybersecurity researchers have identified a malicious Python package that purports to be an offshoot of the popular requests library and has been found concealing a Golang-version of the Sliver command-and-control (C2) framework within a

MITRE Unveils EMB3D: A Threat-Modeling Framework for Embedded Devices

14/05/2024 0 Comments 0 tags

The MITRE Corporation has officially made available a new threat-modeling framework called EMB3D for makers of embedded devices used in critical infrastructure environments. “The model provides a cultivated knowledge base of cyber

The 2024 Browser Security Report Uncovers How Every Web Session Could be a Security Minefield

14/05/2024 0 Comments 0 tags

With the browser becoming the most prevalent workspace in the enterprise, it is also turning into a popular attack vector for cyber attackers. From account takeovers to malicious extensions to phishing attacks, the