Cybersecurity

JetBrains vulnerability exploitation highlights debate over ‘silent patching’

Czech software giant JetBrains harshly criticized security company Rapid7 this week following a dispute over two recently-discovered vulnerabilities. In a blog post published Monday, JetBrains attributed the compromise of several customers’ servers to Rapid7’s decision to release detailed information on the vulnerabilities. “After the full disclosure was made, we started hearing from some customers who […]

Cybersecurity

CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign

The decrypted request content is as follows: 1000|87|283|Yes|6.1.7|||” Conclusion In this research, a follow-up to our Water Hydra APT Zero Day campaign analysis, we explored how the DarkGate operators were able to exploit CVE-2024-21412 as a zero-day attack to deploy the complex and evolving DarkGate malware. We also explored how security bypass vulnerabilities can be […]

DJing

March 2024 Eurorack round-up

This month’s best new releases include another Buchla reissue from Tiptop Audio, ALM’s compact utility module and a unique oscillator from EarthQuaker Devices. Buchla/Tiptop Audio Mixer/Preamplifier 207t Tiptop’s reissue of the Buchla 207 mixer sticks closely to the quirky format of the 1970s original. It’s a stereo design with six mono inputs, each of which […]

Cybersecurity

Cisco Secure Client Carriage Return Line Feed Injection Vulnerability

Cisco has released free software updates that address the vulnerability described in this advisory. Customers with service contracts that entitle them to regular software updates should obtain security fixes through their usual update channels. Customers may only install and expect support for software versions and feature sets for which they have purchased a license. By […]