Security News

Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS
2024-12-12 12:35

Details have emerged about a now-patched security vulnerability in Apple's iOS and macOS that, if successfully exploited, could sidestep the Transparency, Consent, and Control (TCC) framework and...

New Malware Technique Could Exploit Windows UI Framework to Evade EDR Tools
2024-12-11 15:13

A newly devised technique leverages a Windows accessibility framework called UI Automation (UIA) to perform a wide range of malicious activities without tipping off endpoint detection and response...

PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug to access sensitive files
2024-12-06 06:01

Still unpatched 100+ days later, watchTowr says A zero-day arbitrary file read vulnerability in Mitel MiCollab can be chained with a now-patched critical bug in the same platform to give attackers...

Mitel MiCollab zero-day and PoC exploit unveiled
2024-12-05 14:24

A zero-day vulnerability in the Mitel MiCollab enterprise collaboration suite can be exploited to read files containing sensitive data, watchTowr researcher Sonny Macdonald has disclosed, and...

Hackers Target Uyghurs and Tibetans with MOONSHINE Exploit and DarkNimbus Backdoor
2024-12-05 12:43

A previously undocumented threat activity cluster dubbed Earth Minotaur is leveraging the MOONSHINE exploit kit and an unreported Android-cum-Windows backdoor called DarkNimbus to facilitate...

Mitel MiCollab zero-day flaw gets proof-of-concept exploit
2024-12-05 11:00

Researchers have uncovered an arbitrary file read zero-day in the Mitel MiCollab collaboration platform, allowing attackers to access files on a server's filesystem. [...]

Russia-Linked Turla Exploits Pakistani Hackers' Servers to Target Afghan and Indian Entities
2024-12-04 17:23

The Russia-linked advanced persistent threat (APT) group known as Turla has been linked to a previously undocumented campaign that involved infiltrating the command-and-control (C2) servers of a...

PoC exploit for critical WhatsUp Gold RCE vulnerability released (CVE-2024-8785)
2024-12-04 11:16

Researchers have published a proof-of-concept (PoC) exploit for CVE-2024-8785, a critical remote code execution vulnerability affecting Progress WhatsUp Gold, a popular network monitoring solution...

Exploit released for critical WhatsUp Gold RCE flaw, patch now
2024-12-03 19:00

A proof-of-concept (PoC) exploit for a critical-severity remote code execution flaw in Progress WhatsUp Gold has been published, making it critical to install the latest security updates as soon...

NachoVPN Tool Exploits Flaws in Popular VPN Clients for System Compromise
2024-12-03 10:17

Cybersecurity researchers have disclosed a set of flaws impacting Palo Alto Networks and SonicWall virtual private network (VPN) clients that could be potentially exploited to gain remote code...