Security News

New botnet exploits vulnerabilities in NVRs, TP-Link routers
2024-12-24 20:04

A new Mirai-based malware campaign is actively exploiting unpatched vulnerabilities in Internet of Things (IoT) devices, including DigiEver DS-2105 Pro DVRs. [...]

Adobe warns of critical ColdFusion bug with PoC exploit code
2024-12-23 19:58

Adobe has released out-of-band security updates to address a critical ColdFusion vulnerability with proof-of-concept exploit code. [...]

Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits
2024-12-19 10:31

Fortinet has issued an advisory for a now-patched critical security flaw impacting Wireless LAN Manager (FortiWLM) that could lead to disclosure of sensitive information. The vulnerability,...

Critical security hole in Apache Struts under exploit
2024-12-17 21:57

You applied the patch that could stop possible RCE attacks last week, right? A critical security hole in Apache Struts 2, patched last week, is now being exploited using publicly available...

Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware
2024-12-17 16:35

A new social engineering campaign has leveraged Microsoft Teams as a way to facilitate the deployment of a known malware called DarkGate. "An attacker used social engineering via a Microsoft Teams...

Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection
2024-12-17 09:03

Bogus software update lures are being used by threat actors to deliver a new stealer malware called CoinLurker. "Written in Go, CoinLurker employs cutting-edge obfuscation and anti-analysis...

New Glutton Malware Exploits Popular PHP Frameworks Like Laravel and ThinkPHP
2024-12-16 09:09

Cybersecurity researchers have discovered a new PHP-based backdoor called Glutton that has been put to use in cyber attacks targeting China, the United States, Cambodia, Pakistan, and South...

390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits
2024-12-13 20:00

A now-removed GitHub repository that advertised a WordPress tool to publish posts to the online content management system (CMS) is estimated to have enabled the exfiltration of over 390,000...

Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS
2024-12-12 12:35

Details have emerged about a now-patched security vulnerability in Apple's iOS and macOS that, if successfully exploited, could sidestep the Transparency, Consent, and Control (TCC) framework and...

New Malware Technique Could Exploit Windows UI Framework to Evade EDR Tools
2024-12-11 15:13

A newly devised technique leverages a Windows accessibility framework called UI Automation (UIA) to perform a wide range of malicious activities without tipping off endpoint detection and response...