Warning: PyTorch Models Vulnerable to Remote Code Execution via ShellTorch

03/10/2023 0 Comments 0 tags

Cybersecurity researchers have disclosed multiple critical security flaws in the TorchServe tool for serving and scaling PyTorch models that could be chained to achieve remote code execution on affected systems. Israel-based runtime

Over 3 Dozen Data-Stealing Malicious npm Packages Found Targeting Developers

03/10/2023 0 Comments 0 tags

Nearly three dozen counterfeit packages have been discovered in the npm package repository that are designed to exfiltrate sensitive data from developer systems, according to findings from Fortinet FortiGuard Labs.

API Security Trends 2023 – Have Organizations Improved their Security Posture?

03/10/2023 0 Comments 0 tags

APIs, also known as application programming interfaces, serve as the backbone of modern software applications, enabling seamless communication and data exchange between different systems and platforms. They provide developers with

Protecting your IT infrastructure with Security Configuration Assessment (SCA)

03/10/2023 0 Comments 0 tags

Security Configuration Assessment (SCA) is critical to an organization’s cybersecurity strategy. SCA aims to discover vulnerabilities and misconfigurations that malicious actors exploit to gain unauthorized access to systems and data. Regular security

Researcher Reveals New Techniques to Bypass Cloudflare’s Firewall and DDoS Protection

03/10/2023 0 Comments 0 tags

Firewall and distributed denial-of-service (DDoS) attack prevention mechanisms in Cloudflare can be circumvented by exploiting gaps in cross-tenant security controls, defeating the very purpose of these safeguards, it has emerged.

Arm Issues Patch for Mali GPU Kernel Driver Vulnerability Amidst Ongoing Exploitation

03/10/2023 0 Comments 0 tags

Arm has released security patches to contain a security flaw in the Mali GPU Kernel Driver that has come under active exploitation in the wild. Tracked as CVE-2023-4211, the shortcoming impacts

APIs: Unveiling the Silent Killer of Cyber Security Risk Across Industries

03/10/2023 0 Comments 0 tags

Introduction In today’s interconnected digital ecosystem, Application Programming Interfaces (APIs) play a pivotal role in enabling seamless communication and data exchange between various software applications and systems. APIs act as

LUCR-3: Scattered Spider Getting SaaS-y in the Cloud

03/10/2023 0 Comments 0 tags

LUCR-3 overlaps with groups such as Scattered Spider, Oktapus, UNC3944, and STORM-0875 and is a financially motivated attacker that leverages the Identity Provider (IDP) as initial access into an environment

Silent Skimmer: A Year-Long Web Skimming Campaign Targeting Online Payment Businesses

03/10/2023 0 Comments 0 tags

A financially motivated campaign has been targeting online payment businesses in the Asia Pacific, North America, and Latin America with web skimmers for more than a year. The BlackBerry Research

OpenRefine’s Zip Slip Vulnerability Could Let Attackers Execute Malicious Code

03/10/2023 0 Comments 0 tags

A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and transformation tool that could result in arbitrary code execution on affected systems. Tracked as CVE-2023-37476 (CVSS score: 7.8),