Security News

15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials
2024-12-28 06:25

A high-severity flaw impacting select Four-Faith routers has come under active exploitation in the wild, according to new findings from VulnCheck. The vulnerability, tracked as CVE-2024-12856...

Hackers exploit DoS flaw to disable Palo Alto Networks firewalls
2024-12-27 16:33

Palo Alto Networks is warning that hackers are exploiting the CVE-2024-3393 denial of service vulnerability to disable firewall protections by forcing it to reboot. [...]

FICORA and Kaiten Botnets Exploit Old D-Link Vulnerabilities for Global Attacks
2024-12-27 07:11

Cybersecurity researchers are warning about a spike in malicious activity that involves roping vulnerable D-Link routers into two different botnets, a Mirai variant dubbed FICORA and a Kaiten (aka...

New botnet exploits vulnerabilities in NVRs, TP-Link routers
2024-12-24 20:04

A new Mirai-based malware campaign is actively exploiting unpatched vulnerabilities in Internet of Things (IoT) devices, including DigiEver DS-2105 Pro DVRs. [...]

Adobe warns of critical ColdFusion bug with PoC exploit code
2024-12-23 19:58

Adobe has released out-of-band security updates to address a critical ColdFusion vulnerability with proof-of-concept exploit code. [...]

Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits
2024-12-19 10:31

Fortinet has issued an advisory for a now-patched critical security flaw impacting Wireless LAN Manager (FortiWLM) that could lead to disclosure of sensitive information. The vulnerability,...

Critical security hole in Apache Struts under exploit
2024-12-17 21:57

You applied the patch that could stop possible RCE attacks last week, right? A critical security hole in Apache Struts 2, patched last week, is now being exploited using publicly available...

Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware
2024-12-17 16:35

A new social engineering campaign has leveraged Microsoft Teams as a way to facilitate the deployment of a known malware called DarkGate. "An attacker used social engineering via a Microsoft Teams...

Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection
2024-12-17 09:03

Bogus software update lures are being used by threat actors to deliver a new stealer malware called CoinLurker. "Written in Go, CoinLurker employs cutting-edge obfuscation and anti-analysis...

New Glutton Malware Exploits Popular PHP Frameworks Like Laravel and ThinkPHP
2024-12-16 09:09

Cybersecurity researchers have discovered a new PHP-based backdoor called Glutton that has been put to use in cyber attacks targeting China, the United States, Cambodia, Pakistan, and South...