Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency Servers

06/12/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a high-severity Adobe ColdFusion vulnerability by unidentified threat actors to gain initial access to government servers. “The vulnerability in

Atlassian Releases Critical Software Fixes to Prevent Remote Code Execution

06/12/2023 0 Comments 0 tags

Atlassian has released software fixes to address four critical flaws in its software that, if successfully exploited, could result in remote code execution. The list of vulnerabilities is below – CVE-2022-1471 (CVSS score:

Qualcomm Releases Details on Chip Vulnerabilities Exploited in Targeted Attacks

06/12/2023 0 Comments 0 tags

Chipmaker Qualcomm has released more information about three high-severity security flaws that it said came under “limited, targeted exploitation” back in October 2023. The vulnerabilities are as follows – CVE-2023-33063 (CVSS score: 7.8)

Alert: Threat Actors Can Leverage AWS STS to Infiltrate Cloud Accounts

06/12/2023 0 Comments 0 tags

Threat actors can take advantage of Amazon Web Services Security Token Service (AWS STS) as a way to infiltrate cloud accounts and conduct follow-on attacks. The service enables threat actors

New Report: Unveiling the Threat of Malicious Browser Extensions

06/12/2023 0 Comments 0 tags

Compromising the browser is a high-return target for adversaries. Browser extensions, which are small software modules that are added to the browser and can enhance browsing experiences, have become a

Sierra:21 – Flaws in Sierra Wireless Routers Expose Critical Sectors to Cyber Attacks

06/12/2023 0 Comments 0 tags

A collection of 21 security flaws have been discovered in Sierra Wireless AirLink cellular routers and open-source software components like TinyXML and OpenNDS. Collectively tracked as Sierra:21, the issues expose over 86,000 devices across

Scaling Security Operations with Automation

06/12/2023 0 Comments 0 tags

In an increasingly complex and fast-paced digital landscape, organizations strive to protect themselves from various security threats. However, limited resources often hinder security teams when combatting these threats, making it

Warning for iPhone Users: Experts Warn of Sneaky Fake Lockdown Mode Attack

05/12/2023 0 Comments 0 tags

A new “post-exploitation tampering technique” can be abused by malicious actors to visually deceive a target into believing that their Apple iPhone is running in Lockdown Mode when it’s actually

Russia’s AI-Powered Disinformation Operation Targeting Ukraine, U.S., and Germany

05/12/2023 0 Comments 0 tags

The Russia-linked influence operation called Doppelganger has targeted Ukrainian, U.S., and German audiences through a combination of inauthentic news sites and social media accounts. These campaigns are designed to amplify

Generative AI Security: Preventing Microsoft Copilot Data Exposure

05/12/2023 0 Comments 0 tags

Microsoft Copilot has been called one of the most powerful productivity tools on the planet. Copilot is an AI assistant that lives inside each of your Microsoft 365 apps —