Security News

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices
2025-01-10 15:39

Cybersecurity researchers have detailed a now-patched security flaw impacting Monkey's Audio (APE) decoder on Samsung smartphones that could lead to code execution. The high-severity...

Zero-day exploits plague Ivanti Connect Secure appliances for second year running
2025-01-09 14:45

Factory resets and apply patches is the advice amid fortnight delay for other appliances The cybersecurity industry is urging those in charge of defending their orgs to take mitigation efforts...

Security pros baited with fake Windows LDAP exploit traps
2025-01-09 13:16

Tricky attackers trying yet again to deceive the good guys on home territory Security researchers are once again being lured into traps by attackers, this time with fake exploits of serious...

Mitel 0-day, 5-year-old Oracle RCE bug under active exploit
2025-01-08 20:30

3 CVEs added to CISA's catalog Cybercriminals are actively exploiting two vulnerabilities in Mitel MiCollab, including a zero-day flaw – and a critical remote code execution vulnerability in...

Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens
2025-01-08 18:55

Hackers are trying to exploit CVE-2024-52875, a critical CRLF injection vulnerability that leads to 1-click remote code execution (RCE) attacks in GFI KerioControl firewall product. [...]

Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks
2025-01-08 10:29

A Mirai botnet variant has been found exploiting a newly disclosed security flaw impacting Four-Faith industrial routers since early November 2024 with the goal of conducting distributed...

New Mirai botnet targets industrial routers with zero-day exploits
2025-01-07 20:44

A relatively new Mirai-based botnet has been growing in sophistication and is now leveraging zero-day exploits for security flaws in industrial routers and smart home devices. [...]

LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers
2025-01-03 08:16

A proof-of-concept (PoC) exploit has been released for a now-patched security flaw impacting Windows Lightweight Directory Access Protocol (LDAP) that could trigger a denial-of-service (DoS)...

New DoubleClickjacking attack exploits double-clicks to hijack accounts
2025-01-02 20:26

A new variation of clickjacking attacks called "DoubleClickjacking" lets attackers trick users into authorizing sensitive actions using double-clicks while bypassing existing protections against...

New "DoubleClickjacking" Exploit Bypasses Clickjacking Protections on Major Websites
2025-01-01 13:24

Threat hunters have disclosed a new "widespread timing-based vulnerability class" that leverages a double-click sequence to facilitate clickjacking attacks and account takeovers in almost all...