Casbaneiro Banking Malware Goes Under the Radar with UAC Bypass Technique

25/07/2023 0 Comments 0 tags

The financially motivated threat actors behind the Casbaneiro banking malware family have been observed making use of a User Account Control (UAC) bypass technique to gain full administrative privileges on a machine,

North Korean Nation-State Actors Exposed in JumpCloud Hack After OPSEC Blunder

25/07/2023 0 Comments 0 tags

North Korean nation-state actors affiliated with the Reconnaissance General Bureau (RGB) have been attributed to the JumpCloud hack following an operational security (OPSEC) blunder that exposed their actual IP address. Google-owned threat

Apple Rolls Out Urgent Patches for Zero-Day Flaws Impacting iPhones, iPads and Macs

25/07/2023 0 Comments 0 tags

Apple has rolled out security updates to iOS, iPadOS, macOS, tvOS, watchOS, and Safari to address several security vulnerabilities, including one actively exploited zero-day bug in the wild. Tracked as CVE-2023-38606, the shortcoming

Ivanti Releases Urgent Patch for EPMM Zero-Day Vulnerability Under Active Exploitation

25/07/2023 0 Comments 0 tags

Ivanti is warning users to update their Endpoint Manager Mobile (EPMM) mobile device management software (formerly MobileIron Core) to the latest version that fixes an actively exploited zero-day vulnerability. Dubbed CVE-2023-35078,

Atlassian Releases Patches for Critical Flaws in Confluence and Bamboo

25/07/2023 0 Comments 0 tags

Atlassian has released updates to address three security flaws impacting its Confluence Server, Data Center, and Bamboo Data Center products that, if successfully exploited, could result in remote code execution on susceptible

Banking Sector Targeted in Open-Source Software Supply Chain Attacks

24/07/2023 0 Comments 0 tags

Cybersecurity researchers said they have discovered what they say is the first open-source software supply chain attacks specifically targeting the banking sector. “These attacks showcased advanced techniques, including targeting specific

New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection

24/07/2023 0 Comments 0 tags

Details have emerged about a now-patched flaw in OpenSSH that could be potentially exploited to run arbitrary commands remotely on compromised hosts under specific conditions. “This vulnerability allows a remote

How to Protect Patients and Their Privacy in Your SaaS Apps

24/07/2023 0 Comments 0 tags

The healthcare industry is under a constant barrage of cyberattacks. It has traditionally been one of the most frequently targeted industries, and things haven’t changed in 2023. The U.S. Government’s

Google Messages Getting Cross-Platform End-to-End Encryption with MLS Protocol

24/07/2023 0 Comments 0 tags

Google has announced that it intends to add support for Message Layer Security (MLS) to its Messages service for Android and open source implementation of the specification. “Most modern consumer

Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

24/07/2023 0 Comments 0 tags

Zero-day vulnerabilities in Windows Installers for the Atera remote monitoring and management software could act as a springboard to launch privilege escalation attacks. The flaws, discovered by Mandiant on February