GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries

05/10/2023 0 Comments 0 tags

A new Android banking trojan named GoldDigger has been found targeting several financial applications with an aim to siphon victims’ funds and backdoor infected devices. “The malware targets more than

CISA Warns of Active Exploitation of JetBrains and Windows Vulnerabilities

05/10/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, while removing five bugs from the list

Apple Rolls Out Security Patches for Actively Exploited iOS Zero-Day Flaw

05/10/2023 0 Comments 0 tags

Apple on Wednesday rolled out security patches to address a new zero-day flaw in iOS and iPadOS that it said has come under active exploitation in the wild. Tracked as CVE-2023-42824,

Atlassian Confluence Hit by New Actively Exploited Zero-Day – Patch Now

05/10/2023 0 Comments 0 tags

Atlassian has released fixes to contain an actively exploited critical zero-day flaw impacting publicly accessible Confluence Data Center and Server instances. The vulnerability, tracked as CVE-2023-22515, is remotely exploitable and allows

Researchers Link DragonEgg Android Spyware to LightSpy iOS Surveillanceware

05/10/2023 0 Comments 0 tags

New findings have identified connections between an Android spyware called DragonEgg and another sophisticated modular iOS surveillanceware tool named LightSpy. DragonEgg, alongside WyrmSpy (aka AndroidControl), was first disclosed by Lookout in July

Wing Disrupts the Market by Introducing Affordable SaaS Security

05/10/2023 0 Comments 0 tags

Today, mid-sized companies and their CISOs are struggling to handle the growing threat of SaaS security with limited manpower and tight budgets. Now, this may be changing. By focusing on

Rogue npm Package Deploys Open-Source Rootkit in New Supply Chain Attack

05/10/2023 0 Comments 0 tags

A new deceptive package hidden within the npm package registry has been uncovered deploying an open-source rootkit called r77, marking the first time a rogue package has delivered rootkit functionality.

Microsoft Warns of Cyber Attacks Attempting to Breach Cloud via SQL Server Instance

05/10/2023 0 Comments 0 tags

Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environment through an SQL Server instance. “The attackers initially exploited a SQL injection vulnerability

Qualcomm Releases Patch for 3 new Zero-Days Under Active Exploitation

03/10/2023 0 Comments 0 tags

Chipmaker Qualcomm has released security updates to address 17 vulnerabilities in various components, while warning that three other zero-days have come under active exploitation. Of the 17 flaws, three are

Warning: PyTorch Models Vulnerable to Remote Code Execution via ShellTorch

03/10/2023 0 Comments 0 tags

Cybersecurity researchers have disclosed multiple critical security flaws in the TorchServe tool for serving and scaling PyTorch models that could be chained to achieve remote code execution on affected systems. Israel-based runtime