Apple Rolls Out Security Patches for Actively Exploited iOS Zero-Day Flaw

05/10/2023 0 Comments 0 tags

Apple on Wednesday rolled out security patches to address a new zero-day flaw in iOS and iPadOS that it said has come under active exploitation in the wild. Tracked as CVE-2023-42824,

CISA Warns of Active Exploitation of JetBrains and Windows Vulnerabilities

05/10/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, while removing five bugs from the list

GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries

05/10/2023 0 Comments 0 tags

A new Android banking trojan named GoldDigger has been found targeting several financial applications with an aim to siphon victims’ funds and backdoor infected devices. “The malware targets more than

Guyana Governmental Entity Hit by DinodasRAT in Cyber Espionage Attack

05/10/2023 0 Comments 0 tags

A governmental entity in Guyana has been targeted as part of a cyber espionage campaign dubbed Operation Jacana. The activity, which was detected by ESET in February 2023, entailed a spear-phishing attack

Analysis and Config Extraction of Lu0Bot, a Node.js Malware with Considerable Capabilities

05/10/2023 0 Comments 0 tags

Nowadays, more malware developers are using unconventional programming languages to bypass advanced detection systems. The Node.js malware Lu0Bot is a testament to this trend. By targeting a platform-agnostic runtime environment

Warning: PyTorch Models Vulnerable to Remote Code Execution via ShellTorch

03/10/2023 0 Comments 0 tags

Cybersecurity researchers have disclosed multiple critical security flaws in the TorchServe tool for serving and scaling PyTorch models that could be chained to achieve remote code execution on affected systems. Israel-based runtime

Qualcomm Releases Patch for 3 new Zero-Days Under Active Exploitation

03/10/2023 0 Comments 0 tags

Chipmaker Qualcomm has released security updates to address 17 vulnerabilities in various components, while warning that three other zero-days have come under active exploitation. Of the 17 flaws, three are

Over 3 Dozen Data-Stealing Malicious npm Packages Found Targeting Developers

03/10/2023 0 Comments 0 tags

Nearly three dozen counterfeit packages have been discovered in the npm package repository that are designed to exfiltrate sensitive data from developer systems, according to findings from Fortinet FortiGuard Labs.

Researcher Reveals New Techniques to Bypass Cloudflare’s Firewall and DDoS Protection

03/10/2023 0 Comments 0 tags

Firewall and distributed denial-of-service (DDoS) attack prevention mechanisms in Cloudflare can be circumvented by exploiting gaps in cross-tenant security controls, defeating the very purpose of these safeguards, it has emerged.

Protecting your IT infrastructure with Security Configuration Assessment (SCA)

03/10/2023 0 Comments 0 tags

Security Configuration Assessment (SCA) is critical to an organization’s cybersecurity strategy. SCA aims to discover vulnerabilities and misconfigurations that malicious actors exploit to gain unauthorized access to systems and data. Regular security