US CISA added critical Apache RocketMQ flaw to its Known Exploited Vulnerabilities catalog

2 years ago

US CISA added critical vulnerability CVE-2023-33246 in Apache RocketMQ to its Known Exploited Vulnerabilities catalog. US Cybersecurity and Infrastructure Security Agency (CISA)…

Ragnar Locker gang leaks data stolen from the Israel’s Mayanei Hayeshua hospital

2 years ago

The Ragnar Locker ransomware gang added Israel's Mayanei Hayeshua hospital to the list of victims on its Tor leak site…

North Korea-linked threat actors target cybersecurity experts with a zero-day

2 years ago

North Korea-linked threat actors associated with North Korea exploited a zero-day flaw in attacks against cybersecurity experts. North Korea-linked threat…

Zero-day in Cisco ASA and FTD is actively exploited in ransomware attacks

2 years ago

A zero-day vulnerability (CVE-2023-20269) in Cisco ASA and FTD is actively exploited in ransomware attacks, the company warns. Cisco warns…

Nation-state actors exploit Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus, CISA warns

2 years ago

U.S. CISA warned that nation-state actors are exploiting flaws in Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus. The U.S.…

Zero-days fixed by Apple were used to deliver NSO Group’s Pegasus spyware

2 years ago

Citizen Lab reported that the actively exploited zero-days fixed by Apple are being used in Pegasus spyware attacks Researchers at…

Apple discloses 2 new actively exploited zero-day flaws in iPhones, Macs

2 years ago

Apple rolled out emergency security updates to address two new actively exploited zero-day vulnerabilities impacting iPhones and Macs. The two…

A malvertising campaign is delivering a new version of the macOS Atomic Stealer

2 years ago

Researchers spotted a new malvertising campaign targeting Mac users with a new version of the macOS stealer Atomic Stealer. Malwarebytes…

Two flaws in Apache SuperSet allow to remotely hack servers

2 years ago

A couple of security vulnerabilities in Apache SuperSet could be exploited by an attacker to gain remote code execution on vulnerable…

Chinese cyberspies obtained Microsoft signing key from Windows crash dump due to a mistake

2 years ago

Microsoft revealed that the Chinese group Storm-0558 stole a signing key used to breach government email accounts from a Windows…

This website uses cookies.