Citrix Devices Under Attack: NetScaler Flaw Exploited to Capture User Credentials

11/10/2023 0 Comments 0 tags

A recently disclosed critical flaw in Citrix NetScaler ADC and Gateway devices is being exploited by threat actors to conduct a credential harvesting campaign. IBM X-Force, which uncovered the activity

libcue Library Flaw Opens GNOME Linux Systems Vulnerable to RCE Attacks

11/10/2023 0 Comments 0 tags

A new security flaw has been disclosed in the libcue library impacting GNOME Linux systems that could be exploited to achieve remote code execution (RCE) on affected hosts. Tracked as CVE-2023-43641 (CVSS

New Magecart Campaign Alters 404 Error Pages to Steal Shoppers’ Credit Cards

11/10/2023 0 Comments 0 tags

A sophisticated Magecart campaign has been observed manipulating websites’ default 404 error page to conceal malicious code in what’s been described as the latest evolution of the attacks. The activity, per Akamai,

Researchers Uncover Grayling APT’s Ongoing Attack Campaign Across Industries

11/10/2023 0 Comments 0 tags

A previously undocumented threat actor of unknown provenance has been linked to a number of attacks targeting organizations in the manufacturing, IT, and biomedical sectors in Taiwan. The Symantec Threat

New Report: Child Sexual Abuse Content and Online Risks to Children on the Rise

11/10/2023 0 Comments 0 tags

Certain online risks to children are on the rise, according to a recent report from Thorn, a technology nonprofit whose mission is to build technology to defend children from sexual

Google Adopts Passkeys as Default Sign-in Method for All Users

11/10/2023 0 Comments 0 tags

Google on Tuesday announced the ability for all users to set up passkeys by default, five months after it rolled out support for the FIDO Alliance-backed passwordless standard for Google Accounts on

HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

11/10/2023 0 Comments 0 tags

Amazon Web Services (AWS), Cloudflare, and Google on Tuesday said they took steps to mitigate record-breaking distributed denial-of-service (DDoS) attacks that relied on a novel technique called HTTP/2 Rapid Reset.

Gaza-Linked Cyber Threat Actor Targets Israeli Energy and Defense Sectors

09/10/2023 0 Comments 0 tags

A Gaza-based threat actor has been linked to a series of cyber attacks aimed at Israeli private-sector energy, defense, and telecommunications organizations. Microsoft, which revealed details of the activity in

North Korea’s Lazarus Group Launders $900 Million in Cryptocurrency

06/10/2023 0 Comments 0 tags

As much as $7 billion in cryptocurrency has been illicitly laundered through cross-chain crime, with the North Korea-linked Lazarus Group linked to the theft of roughly $900 million of those

Supermicro’s BMC Firmware Found Vulnerable to Multiple Critical Vulnerabilities

06/10/2023 0 Comments 0 tags

Multiple security vulnerabilities have been disclosed in the Intelligent Platform Management Interface (IPMI) firmware for Supermicro baseboard management controllers (BMCs) that could result in privilege escalation and execution of malicious