Cybersecurity

Google fixed another Chrome zero-day exploited at Pwn2Own

Google addressed another Chrome zero-day exploited at Pwn2Own in March Pierluigi Paganini April 03, 2024 Google fixed another Chrome zero-day vulnerability exploited during the Pwn2Own hacking competition in March. Google has addressed another zero-day vulnerability in the Chrome browser, tracked as CVE-2024-3159, that was exploited during the Pwn2Own hacking competition in March, 2024. The vulnerability […]

Cybersecurity

Highly sensitive files mysteriously disappeared from EUROPOL headquarters

Highly sensitive files mysteriously disappeared from EUROPOL headquarters Pierluigi Paganini April 03, 2024 A batch of highly sensitive files containing the personal information of top Europol executives mysteriously disappeared last summer The website Politico reported that the Europol has suffered a serious security breach, a batch of sensitive files of top law enforcement officials, including […]

Cybersecurity

Experts released PoC exploit for critical Progress Software OpenEdge bug

Experts released PoC exploit for critical Progress Software OpenEdge bug Pierluigi Paganini March 11, 2024 Researchers released technical specifics and a PoC exploit for a recently disclosed flaw in Progress Software OpenEdge Authentication Gateway and AdminServer. Researchers from Horizon3.ai have published technical details and a proof-of-concept (PoC) exploit for the critical security flaw CVE-2024-1403 in […]

Cybersecurity

BianLian group exploits JetBrains TeamCity bugs in ransomware attacks

BianLian group exploits JetBrains TeamCity bugs in ransomware attacks Pierluigi Paganini March 11, 2024 BianLian ransomware group was spotted exploiting vulnerabilities in JetBrains TeamCity software in recent attacks. Researchers from GuidePoint Security noticed, while investigating a recent attack linked to the BianLian ransomware group, that the threat actors gained initial access to the target by […]

Cybersecurity

Cisco addressed severe flaws in its Secure Client

Cisco addressed severe flaws in its Secure Client Pierluigi Paganini March 08, 2024 Cisco addressed two high-severity vulnerabilities in Secure Client that could lead to code execution and unauthorized remote access VPN sessions. Cisco released security patches to address two high-severity vulnerabilities in Secure Client respectively tracked as CVE-2024-20337 and CVE-2024-20338. Cisco Secure Client is […]

Cybersecurity

Snake, a new Info Stealer spreads through Facebook messages

Snake, a new Info Stealer spreads through Facebook messages Pierluigi Paganini March 07, 2024 Threat actors are using Facebook messages to spread a Python-based information stealer dubbed Snake, researchers warn. Cybereason researchers warn that threat actors are utilizing Facebook messages to spread the Snake malware, a Python-based information stealer. The researchers noticed that the threat […]

Cybersecurity

Snake, a new Info Stealer spreads through Facebook messages

Snake, a new Info Stealer spreads through Facebook messages Pierluigi Paganini March 07, 2024 Threat actors are using Facebook messages to spread a Python-based information stealer dubbed Snake, researchers warn. Cybereason researchers warn that threat actors are utilizing Facebook messages to spread the Snake malware, a Python-based information stealer. The researchers noticed that the threat […]

Cybersecurity

US Gov sanctioned Intellexa Consortium individuals and entities behind Predator spyware attacks – Security Affairs

US Gov sanctioned Intellexa Consortium individuals and entities behind Predator spyware attacks Pierluigi Paganini March 05, 2024 The U.S. government sanctioned two individuals and five entities linked to the development and distribution of the Predator spyware used to target Americans. Today, the Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced actions on […]

Cybersecurity

Apple emergency security updates fix two new iOS zero-days

Apple emergency security updates fix two new iOS zero-days Pierluigi Paganini March 05, 2024 Apple released emergency security updates to address two new iOS zero-day vulnerabilities actively exploited in the wild against iPhone users. Apple released emergency security updates to address two iOS zero-day vulnerabilities, respectively tracked as CVE-2024-23225 and CVE-2024-23296, that were exploited in […]