Security News

Mitel 0-day, 5-year-old Oracle RCE bug under active exploit
2025-01-08 20:30

3 CVEs added to CISA's catalog Cybercriminals are actively exploiting two vulnerabilities in Mitel MiCollab, including a zero-day flaw – and a critical remote code execution vulnerability in...

Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens
2025-01-08 18:55

Hackers are trying to exploit CVE-2024-52875, a critical CRLF injection vulnerability that leads to 1-click remote code execution (RCE) attacks in GFI KerioControl firewall product. [...]

Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks
2025-01-08 10:29

A Mirai botnet variant has been found exploiting a newly disclosed security flaw impacting Four-Faith industrial routers since early November 2024 with the goal of conducting distributed...

New Mirai botnet targets industrial routers with zero-day exploits
2025-01-07 20:44

A relatively new Mirai-based botnet has been growing in sophistication and is now leveraging zero-day exploits for security flaws in industrial routers and smart home devices. [...]

LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers
2025-01-03 08:16

A proof-of-concept (PoC) exploit has been released for a now-patched security flaw impacting Windows Lightweight Directory Access Protocol (LDAP) that could trigger a denial-of-service (DoS)...

New DoubleClickjacking attack exploits double-clicks to hijack accounts
2025-01-02 20:26

A new variation of clickjacking attacks called "DoubleClickjacking" lets attackers trick users into authorizing sensitive actions using double-clicks while bypassing existing protections against...

New "DoubleClickjacking" Exploit Bypasses Clickjacking Protections on Major Websites
2025-01-01 13:24

Threat hunters have disclosed a new "widespread timing-based vulnerability class" that leverages a double-click sequence to facilitate clickjacking attacks and account takeovers in almost all...

Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents
2024-12-31 05:42

The United States Treasury Department said it suffered a "major cybersecurity incident" that allowed suspected Chinese threat actors to remotely access some computers and unclassified documents. ...

Hackers exploit Four-Faith router flaw to open reverse shells
2024-12-30 18:03

Threat actors are exploiting a post-authentication remote command injection vulnerability in Four-Faith routers tracked as CVE-2024-12856 to open reverse shells back to the attackers. [...]

Malware botnets exploit outdated D-Link routers in recent attacks
2024-12-29 15:09

Two botnets tracked as 'Ficora' and 'Capsaicin' have recorded increased activity in targeting D-Link routers that have reached end of life or are running outdated firmware versions. [...]