New Python URL Parsing Flaw Could Enable Command Execution Attacks

12/08/2023 0 Comments 0 tags

A high-severity security flaw has been disclosed in the Python URL parsing function that could be exploited to bypass domain or protocol filtering methods implemented with a blocklist, ultimately resulting

Lolek Bulletproof Hosting Servers Seized, 5 Key Operators Arrested

12/08/2023 0 Comments 0 tags

European and U.S. law enforcement agencies have announced the dismantling of a bulletproof hosting service provider called Lolek Hosted, which cybercriminals have used to launch cyber-attacks across the globe. “Five of

Zoom ZTP & AudioCodes Phones Flaws Uncovered, Exposing Users to Eavesdropping

12/08/2023 0 Comments 0 tags

Multiple security vulnerabilities have been disclosed in AudioCodes desk phones and Zoom’s Zero Touch Provisioning (ZTP) that could be potentially exploited by a malicious attacker to conduct remote attacks. “An

New Attack Alert: Freeze[.]rs Injector Weaponized for XWorm Malware Attacks

12/08/2023 0 Comments 0 tags

Malicious actors are using a legitimate Rust-based injector called Freeze[.]rs to deploy a commodity malware called XWorm in victim environments. The novel attack chain, detected by Fortinet FortiGuard Labs on July 13,

CISA Adds Microsoft .NET Vulnerability to KEV Catalog Due to Active Exploitation

12/08/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched security flaw in Microsoft’s .NET and Visual Studio products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of

16 New CODESYS SDK Flaws Expose OT Environments to Remote Attacks

12/08/2023 0 Comments 0 tags

A set of 16 high-severity security flaws have been disclosed in the CODESYS V3 software development kit (SDK) that could result in remote code execution and denial-of-service under specific conditions, posing risks

New SystemBC Malware Variant Targets Southern African Power Company

12/08/2023 0 Comments 0 tags

An unknown threat actor has been linked to a cyber attack on a power generation company in southern Africa with a new variant of the SystemBC malware called DroxiDat as

Researchers Shed Light on APT31’s Advanced Backdoors and Data Exfiltration Tactics

12/08/2023 0 Comments 0 tags

The Chinese threat actor known as APT31 (aka Bronze Vinewood, Judgement Panda, or Violet Typhoon) has been linked to a set of advanced backdoors that are capable of exfiltrating harvested

Enhancing TLS Security: Google Adds Quantum-Resistant Encryption in Chrome 116

12/08/2023 0 Comments 0 tags

Google has announced plans to add support for quantum-resistant encryption algorithms in its Chrome browser, starting with version 116. “Chrome will begin supporting X25519Kyber768 for establishing symmetric secrets in TLS, starting in Chrome

Researchers Uncover Years-Long Cyber Espionage on Foreign Embassies in Belarus

12/08/2023 0 Comments 0 tags

A hitherto undocumented threat actor operating for nearly a decade and codenamed MoustachedBouncer has been attributed to cyber espionage attacks aimed at foreign embassies in Belarus. “Since 2020, MoustachedBouncer has most