Critical Cisco ISE Auth Bypass Flaw Impacts Cloud Deployments on AWS, Azure, and OCI

05/06/2025 0 Comments 0 tags

Cisco has released security patches to address a critical security flaw impacting the Identity Services Engine (ISE) that, if successfully exploited, could allow unauthenticated actors to carry out malicious actions

Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App

04/06/2025 0 Comments 0 tags

Google has disclosed details of a financially motivated threat cluster that it said “specialises” in voice phishing (aka vishing) campaigns designed to breach organizations’ Salesforce instances for large-scale data theft

Chaos RAT Malware Targets Windows and Linux via Fake Network Tool Downloads

04/06/2025 0 Comments 0 tags

Threat hunters are calling attention to a new variant of a remote access trojan (RAT) called Chaos RAT that has been used in recent attacks targeting Windows and Linux systems.

Your SaaS Data Isn’t Safe: Why Traditional DLP Solutions Fail in the Browser Era

04/06/2025 0 Comments 0 tags

Traditional data leakage prevention (DLP) tools aren’t keeping pace with the realities of how modern businesses use SaaS applications. Companies today rely heavily on SaaS platforms like Google Workspace, Salesforce,

Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks

04/06/2025 0 Comments 0 tags

Several malicious packages have been uncovered across the npm, Python, and Ruby package repositories that drain funds from cryptocurrency wallets, erase entire codebases after installation, and exfiltrate Telegram API tokens,

HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass

04/06/2025 0 Comments 0 tags

Hewlett Packard Enterprise (HPE) has released security updates to address as many as eight vulnerabilities in its StoreOnce data backup and deduplication solution that could result in an authentication bypass

Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack

03/06/2025 0 Comments 0 tags

Threat hunters are alerting to a new campaign that employs deceptive websites to trick unsuspecting users into executing malicious PowerShell scripts on their machines and infect them with the NetSupport

Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious Code

03/06/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a critical security flaw in the Roundcube webmail software that has gone unnoticed for a decade and could be exploited to take over susceptible

Scattered Spider: Understanding Help Desk Scams and How to Defend Your Organization

03/06/2025 0 Comments 0 tags

In the wake of high-profile attacks on UK retailers Marks & Spencer and Co-op, Scattered Spider has been all over the media, with coverage spilling over into the mainstream news

Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets

03/06/2025 0 Comments 0 tags

A growing number of malicious campaigns have leveraged a recently discovered Android banking trojan called Crocodilus to target users in Europe and South America. The malware, according to a new