The Breach News

OpenRefine’s Zip Slip Vulnerability Poses Risk of Malicious Code Execution by Attackers

A critical security vulnerability has been uncovered in OpenRefine, an open-source tool for data cleaning and transformation, potentially enabling arbitrary code execution on affected systems. The flaw, designated as CVE-2023-37476, holds a CVSS score of 7.8 and is categorized as a Zip Slip vulnerability. It affects versions 3.7.3 and earlier,…

Read MoreOpenRefine’s Zip Slip Vulnerability Poses Risk of Malicious Code Execution by Attackers

Europol Takes Action Against Individuals Purchasing DDoS-for-Hire Services

Recent law enforcement efforts reveal that individuals who engaged with DDoS-for-hire services may now be facing serious repercussions. Following the takedown of the world-renowned DDoS-for-hire platform Webstresser.org in April 2018, authorities are now focusing on the clients who utilized this service to orchestrate millions of cyber attacks against a range…

Read MoreEuropol Takes Action Against Individuals Purchasing DDoS-for-Hire Services

Patch Released for Mali GPU Kernel Driver Vulnerability Addressing Ongoing Exploitation of Arm Issues

Arm has recently issued critical security patches to address a vulnerability in the Mali GPU Kernel Driver, which has been actively exploited in the field. This security flaw, designated as CVE-2023-4211, affects multiple driver versions, including the Midgard, Bifrost, and Valhall GPU Kernel Drivers across a range of versions. The…

Read MorePatch Released for Mali GPU Kernel Driver Vulnerability Addressing Ongoing Exploitation of Arm Issues

FBI Targets ‘Joanap Malware’ Victims to Disrupt North Korean Botnet

On Wednesday, the United States Department of Justice (DoJ) announced a significant initiative aimed at mapping and dismantling a sophisticated botnet known as Joanap, which has reportedly infiltrated Microsoft Windows systems worldwide over the last decade. Joanap is associated with an elite group of cyber adversaries known as Hidden Cobra,…

Read MoreFBI Targets ‘Joanap Malware’ Victims to Disrupt North Korean Botnet