Category vulnerabilities

Urgent: Serious Jenkins Vulnerability Poses RCE Risk – Update Now!

The maintainers of Jenkins, an open-source automation server widely used for continuous integration and delivery, have patched nine security vulnerabilities, including one critical issue that poses a serious risk of remote code execution (RCE). This vulnerability, identified as CVE-2024-23897, allows unauthorized users to read arbitrary files from the Jenkins controller’s…

Read MoreUrgent: Serious Jenkins Vulnerability Poses RCE Risk – Update Now!

Analysis of SystemBC Malware’s C2 Server Reveals Payload Delivery Techniques

Recent cybersecurity investigations have unveiled significant insights into the functioning of a notorious malware family known as SystemBC. This malware operates through a command-and-control (C2) server setup that has been analyzed by researchers at Kroll, revealing its availability for purchase on various underground marketplaces. Kroll’s analysis indicates that purchasers receive…

Read MoreAnalysis of SystemBC Malware’s C2 Server Reveals Payload Delivery Techniques

Critical Cisco Vulnerability Allows Remote Takeover of Unified Communication Systems

Cisco Addresses Critical Security Vulnerability in Unified Communications Products Cisco has recently issued important patches to mitigate a serious security vulnerability affecting multiple products within its Unified Communications and Contact Center Solutions range. This flaw, identified as CVE-2024-20253, is rated critically high with a CVSS score of 9.9. It poses…

Read MoreCritical Cisco Vulnerability Allows Remote Takeover of Unified Communication Systems

AllaKore RAT Malware Exploiting Mexican Companies with Financial Fraud Tactics

Mexican financial institutions are currently being targeted by a sophisticated spear-phishing campaign that deploys a modified variant of the open-source remote access trojan known as AllaKore RAT. This attack has been attributed to an unidentified financially motivated actor based in Latin America, with the campaign having been operational since at…

Read MoreAllaKore RAT Malware Exploiting Mexican Companies with Financial Fraud Tactics

Emergence of New Ransomware Gangs: Albabat, Kasseika, and Kuiper Leverage Rust and Go

Cybersecurity researchers have discovered a new variant of the Phobos ransomware family named Faust. This iteration was documented by Fortinet FortiGuard Labs, which detailed its dissemination method involving a Microsoft Excel document (.XLAM) that contains a VBA script capable of executing malicious actions. The attack initiates when the victim opens…

Read MoreEmergence of New Ransomware Gangs: Albabat, Kasseika, and Kuiper Leverage Rust and Go

Researchers Discover Outlook Vulnerability That May Expose Your NTLM Passwords

A recently addressed security vulnerability in Microsoft Outlook exposes users to potential exploitation by malicious actors aiming to access NT LAN Manager (NTLM) v2 hashed passwords through specially crafted files. The flaw, identified as CVE-2023-35636, has been rated with a CVSS score of 6.5 and was patched during Microsoft’s December…

Read MoreResearchers Discover Outlook Vulnerability That May Expose Your NTLM Passwords

Juniper Networks Issues Critical Junos OS Updates for Severe Vulnerabilities

Juniper Networks Addresses High-Security Vulnerabilities Juniper Networks has announced critical out-of-band updates to its SRX Series and EX Series products to counter high-severity vulnerabilities that could potentially allow adversaries to take control of affected systems. This announcement underscores the growing risks in cybersecurity, particularly for organizations relying on Juniper’s networking…

Read MoreJuniper Networks Issues Critical Junos OS Updates for Severe Vulnerabilities

URGENT: GitLab Update Required – Critical Flaw in Workspace Creation Enables File Overwrite

GitLab has once again addressed a significant security vulnerability in both its Community Edition (CE) and Enterprise Edition (EE). This flaw, designated as CVE-2024-0402, poses a serious risk, allowing authenticated users to write files to arbitrary locations on the server while creating a workspace. The vulnerability, which received a critical…

Read MoreURGENT: GitLab Update Required – Critical Flaw in Workspace Creation Enables File Overwrite

New Glibc Vulnerability Provides Attackers with Root Access on Major Linux Distributions

A critical vulnerability affecting the widely used GNU C Library (glibc) has come to light, enabling local malicious actors to gain full root access on Linux systems. This flaw is tracked as CVE-2023-6246, with a CVSS rating of 7.8, indicating a high level of severity. The vulnerability is located in…

Read MoreNew Glibc Vulnerability Provides Attackers with Root Access on Major Linux Distributions