Security News

Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access
2025-02-04 14:16

Cybersecurity researchers have called attention to a software supply chain attack targeting the Go ecosystem that involves a malicious package capable of granting the adversary remote access to...

Canadian charged with stealing $65 million using DeFI crypto exploits
2025-02-03 19:20

The U.S. Justice Department has charged a Canadian man with stealing roughly $65 million after exploiting two decentralized finance (DeFI) protocols. [...]

Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft
2025-01-31 05:49

Broadcom has released security updates to patch five security flaws impacting VMware Aria Operations and Aria Operations for Logs, warning customers that attackers could exploit them to gain...

Unpatched PHP Voyager Flaws Leave Servers Open to One-Click RCE Exploits
2025-01-30 07:21

Three security flaws have been disclosed in the open-source PHP package Voyager that could be exploited by an attacker to achieve one-click remote code execution on affected instances. "When an...

New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks
2025-01-30 06:41

A Mirai botnet variant dubbed Aquabot has been observed actively attempting to exploit a medium-severity security flaw impacting Mitel phones in order to ensnare them into a network capable of...

Hackers exploit critical unpatched flaw in Zyxel CPE devices
2025-01-29 14:42

Hackers are exploiting a critical command injection vulnerability in Zyxel CPE Series devices that is currently tracked as CVE-2024-40891 and remains unpatched since last July. [...]

New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits
2025-01-29 10:49

A team of security researchers from Georgia Institute of Technology and Ruhr University Bochum has demonstrated two new side-channel attacks targeting Apple silicon that could be exploited to leak...

Clone2Leak attacks exploit Git flaws to steal credentials
2025-01-27 16:36

A set of three distinct but related attacks, dubbed 'Clone2Leak,' can leak credentials by exploiting how Git and its credential helpers handle authentication requests. [...]

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits
2025-01-23 15:13

An exhaustive evaluation of three firewall models from Palo Alto Networks has uncovered a host of known security flaws impacting the devices' firmware as well as misconfigured security features....

Cisco warns of denial of service flaw with PoC exploit code
2025-01-22 18:47

Cisco has released security updates to patch a ClamAV denial-of-service (DoS) vulnerability, which has proof-of-concept (PoC) exploit code. [...]