Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the Wild
Oct 09, 2024 | Ravie Lakshmanan
Covering critical security updates from Microsoft and other vendors, our platform ensures you’re informed on zero-days and exploits in the wild.
<Read More>
Microsoft Detects Growing Use of File Hosting Services in Business Email Compromise Attacks
Oct 09, 2024 | Ravie Lakshmanan
Microsoft alerts on cyberattacks using trusted file services like SharePoint and OneDrive to steal credentials and carry out financial fraud through phishing and Business Email Compromise (BEC) tactics
<Read More>
Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited
Oct 08, 2024 | Ravie Lakshmanan
Ivanti warns of active exploitation of three new security vulnerabilities in its Cloud Service Appliance (CSA), which, when combined with a previous flaw, can allow remote code execution and privilege bypass.
<Read More>
Gamers Tricked Into Downloading Lua-Based Malware via Fake Cheating Script Engines
Oct 08, 2024 | Ravie Lakshmanan
Users searching for game cheats are being tricked into downloading Lua-based malware that establishes persistence and delivers additional payloads, targeting gamers across multiple regions.
<Read More>
Cyberattack Group 'Awaken Likho' Targets Russian Government with Advanced Tools
Oct 08, 2024 | Ravie Lakshmanan
Russian government agencies and industrial entities are being targeted by the Awaken Likho group using spear-phishing attacks to deliver malware disguised as document files, enabling remote access via MeshCentral.
<Read More>
GoldenJackal Target Embassies and Air-Gapped Systems Using Malware Toolsets
Oct 08, 2024 | Ravie Lakshmanan
GoldenJackal is a cyber threat actor targeting embassies and government organizations, using malware to infiltrate air-gapped systems via infected USB drives. Their goal is to steal sensitive data, and they have developed two advanced toolsets for this purpose since 2019.
<Read More>