Password Reset Hack Exposed in Honda’s E-Commerce Platform, Dealers Data at Risk

12/06/2023 0 Comments 0 tags

Security vulnerabilities discovered in Honda’s e-commerce platform could have been exploited to gain unrestricted access to sensitive dealer information. “Broken/missing access controls made it possible to access all data on

Beware: 1,000+ Fake Cryptocurrency Sites Trap Users in Bogus Rewards Scheme

12/06/2023 0 Comments 0 tags

A previously undetected cryptocurrency scam has leveraged a constellation of over 1,000 fraudulent websites to ensnare users into a bogus rewards scheme since at least January 2021. “This massive campaign

Critical RCE Flaw Discovered in Fortinet FortiGate Firewalls – Patch Now!

12/06/2023 0 Comments 0 tags

Fortinet has released patches to address a critical security flaw in its FortiGate firewalls that could be abused by a threat actor to achieve remote code execution. The vulnerability, tracked

Apple’s Safari Private Browsing Now Automatically Removes Tracking Parameters in URLs

12/06/2023 0 Comments 0 tags

Apple is introducing major updates to Safari Private Browsing, offering users better protections against third-party trackers as they browse the web. “Advanced tracking and fingerprinting protections go even further to help

Researchers Uncover Publisher Spoofing Bug in Microsoft Visual Studio Installer

12/06/2023 0 Comments 0 tags

Security researchers have warned about an “easily exploitable” flaw in the Microsoft Visual Studio installer that could be abused by a malicious actor to impersonate a legitimate publisher and distribute

Why Now? The Rise of Attack Surface Management

12/06/2023 0 Comments 0 tags

The term “attack surface management” (ASM) went from unknown to ubiquitous in the cybersecurity space over the past few years. Gartner and Forrester have both highlighted the importance of ASM recently, multiple solution

Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable

12/06/2023 0 Comments 0 tags

A fully undetectable (FUD) malware obfuscation engine named BatCloak is being used to deploy various malware strains since September 2022, while persistently evading antivirus detection. The samples grant “threat actors the ability

New SPECTRALVIPER Backdoor Targeting Vietnamese Public Companies

11/06/2023 0 Comments 0 tags

Vietnamese public companies have been targeted as part of an ongoing campaign that deploys a novel backdoor called SPECTRALVIPER. “SPECTRALVIPER is a heavily obfuscated, previously undisclosed, x64 backdoor that brings PE

New Critical MOVEit Transfer SQL Injection Vulnerabilities Discovered – Patch Now!

11/06/2023 0 Comments 0 tags

Progress Software, the company behind the MOVEit Transfer application, has released patches to address brand new SQL injection vulnerabilities affecting the file transfer solution that could enable the theft of

Microsoft Uncovers Banking AitM Phishing and BEC Attacks Targeting Financial Giants

09/06/2023 0 Comments 0 tags

Banking and financial services organizations are the targets of a new multi-stage adversary-in-the-middle (AitM) phishing and business email compromise (BEC) attack, Microsoft has revealed. “The attack originated from a compromised