Security News

Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws
2023-11-14 19:00

Today is Microsoft's November 2023 Patch Tuesday, which includes security updates for a total of 58 flaws and five zero-day vulnerabilities. The total count of 58 flaws does not include 5 Mariner security updates and 20 Microsoft Edge security updates released earlier this month.

Zero-Day Alert: Lace Tempest Exploits SysAid IT Support Software Vulnerability
2023-11-09 16:54

The threat actor known as Lace Tempest has been linked to the exploitation of a zero-day flaw in SysAid IT support software in limited attacks, according to new findings from Microsoft. It has been patched by SysAid in version 23.3.36 of the software.

MOVEit hackers leverage new zero-day bug to breach organizations (CVE-2023-47246)
2023-11-09 14:50

A critical zero-day vulnerability in the SysAid IT support and management software solution is being exploited by Lace Tempest, a ransomware affiliate known for deploying Cl0p ransomware. The group has also similarly leveraged zero days in the Accellion file transfer appliance and Fortra's GoAnywhere file transfer solution.

Microsoft: SysAid zero-day flaw exploited in Clop ransomware attacks
2023-11-09 14:28

Threat actors are exploiting a zero-day vulnerability in the service management software SysAid to gain access to corporate servers for data theft and to deploy Clop ransomware. [...]

MOVEit cybercriminals unearth fresh zero-day to exploit on-prem SysAid hosts
2023-11-09 12:36

Second novel zero-day exploited by Lace Tempest this year offers notable demonstration of skill, especially for a ransomware affiliate The cybercriminals behind the rampant MOVEit exploits from...

New Microsoft Exchange zero-days allow RCE, data theft attacks
2023-11-03 15:14

Microsoft Exchange is impacted by four zero-day vulnerabilities that attackers can exploit remotely to execute arbitrary code or disclose sensitive information on affected installations. ZDI-23-1578 - A remote code execution flaw in the 'ChainedSerializationBinder' class, where user data isn't adequately validated, allowing attackers to deserialize untrusted data.

Hackers earn over $1 million for 58 zero-days at Pwn2Own Toronto
2023-10-27 19:00

The Pwn2Own Toronto 2023 hacking competition has ended with security researchers earning $1,038,500 for 58 zero-day exploits targeting consumer products between October 24 and October 27. During the Pwn2Own Toronto 2023 hacking event organized by Trend Micro's Zero Day Initiative, security researchers targeted mobile and IoT devices.

New Cyberattack From Winter Vivern Exploits a Zero-Day Vulnerability in Roundcube Webmail
2023-10-27 17:26

ESET researcher Matthieu Faou has exposed a new cyberattack from a cyberespionage threat actor known as Winter Vivern, whose interests align with Russia and Belarus. The attack focuses on exploiting a zero-day vulnerability in Roundcube webmail, with the result being the ability to list folders and emails in Roundcube accounts and exfiltrate full emails to an attacker-controlled server.

Pro-Russia group exploits Roundcube zero-day in attacks on European government emails
2023-10-25 16:45

The Winter Vivern cyber spy group is exploiting an XSS zero-day vulnerability in attacks on European governments. Researchers at ESET, who discovered the activity, didn't name the specific government entities it targeted but given Winter Vivern's nexus to Russia and Belarus, they are likely to be adversaries of those countries.

Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software
2023-10-25 13:20

The threat actor known as Winter Vivern has been observed exploiting a zero-day flaw in Roundcube webmail software on October 11, 2023, to harvest email messages from victims' accounts. "Winter...