Security News

NachoVPN Tool Exploits Flaws in Popular VPN Clients for System Compromise
2024-12-03 10:17

Cybersecurity researchers have disclosed a set of flaws impacting Palo Alto Networks and SonicWall virtual private network (VPN) clients that could be potentially exploited to gain remote code...

BootKitty UEFI malware exploits LogoFAIL to infect Linux systems
2024-12-02 18:07

The recently uncovered 'Bootkitty' UEFI bootkit, the first malware of its kind targeting Linux systems, exploits CVE-2023-40238, aka 'LogoFAIL,' to infect computers running on a vulnerable UEFI...

Cybercriminals Exploit Popular Game Engine Godot to Distribute Cross-Platform Malware
2024-11-28 09:29

A popular open-source game engine called Godot Engine is being misused as part of a new GodLoader malware campaign, infecting over 17,000 systems since at least June 2024. "Cybercriminals have...

Hackers exploit ProjectSend flaw to backdoor exposed servers
2024-11-27 21:00

Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers. [...]

APT-C-60 Hackers Exploit StatCounter and Bitbucket in SpyGlace Malware Campaign
2024-11-27 11:14

The threat actor known as APT-C-60 has been linked to a cyber attack targeting an unnamed organization in Japan that used a job application-themed lure to deliver the SpyGlace backdoor. That's...

Matrix Botnet Exploits IoT Devices in Widespread DDoS Botnet Campaign
2024-11-27 05:21

A threat actor named Matrix has been linked to a widespread distributed denial-of-service (DoD) campaign that leverages vulnerabilities and misconfigurations in Internet of Things (IoT) devices to...

Hackers exploit critical bug in Array Networks SSL VPN products
2024-11-26 13:26

America's Cyber Defense Agency has received evidence of hackers actively exploiting a remote code execution vulnerability in SSL VPN products Array Networks AG and vxAG ArrayOS. [...]

RomCom Exploits Zero-Day Firefox and Windows Flaws in Sophisticated Cyberattacks
2024-11-26 10:34

The Russia-aligned threat actor known as RomCom has been linked to the zero-day exploitation of two security flaws, one in Mozilla Firefox and the other in Microsoft Windows, as part of attacks...

1000s of Palo Alto Networks firewalls hijacked as miscreants exploit critical hole
2024-11-22 21:27

PAN-PAN! Intruders inject web shell backdoors, crypto-coin miners, more Thousands of Palo Alto Networks firewalls were compromised by attackers exploiting two recently patched security bugs. The...

China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer
2024-11-19 23:02

No word on when or if the issue will be fixed Chinese government-linked snoops are exploiting a zero-day bug in Fortinet's Windows VPN client to steal credentials and other information, according...