Uncategorized

New “ToolShell” Exploit Chain Attacking SharePoint Servers to Gain Complete Control

Organizations about an active campaign targeting Microsoft SharePoint servers using a sophisticated exploit chain dubbed "ToolShell." The attacks combine previously…

9 months ago

LG Innotek Camera Vulnerability Expose Devices to Admin Hijacking

A critical security vulnerability has been discovered in LG Innotek's LNV5110R camera model that could allow remote attackers to gain…

9 months ago

Arizona Woman Sentenced for Helping North Korean Hackers

Christina Marie Chapman, a 50-year-old Arizona woman, received a 102-month prison sentence for orchestrating a sophisticated fraud scheme that helped…

9 months ago

Salesforce Vulnerabilities Expose Systems to RCE Attacks — Apply Patches Now

Salesforce has disclosed multiple critical security vulnerabilities affecting Tableau Server installations worldwide, with the most severe vulnerabilities enabling remote code…

9 months ago

UNC3944 Cyberattack – Targeting VMware vSphere to Deploy Ransomware and Steal Data

Threat-hunting teams are warning that the financially motivated group UNC4, also tracked as 0ktapus, Octo Tempest, and Scattered Spider, has transitioned from credential-harvesting campaigns to a…

9 months ago

US Offers Up to $15 Million for Information on Three North Korean Officials Linked to IT Schemes

The United States government launched coordinated enforcement actions Friday targeting North Korean revenue generation schemes, offering substantial rewards for information…

9 months ago

Multiple Vulnerabilities in Tridium Niagara Framework Allow Attackers to Exfiltrate Sensitive Network Data

Critical vulnerabilities in Tridium's Niagara Framework®, a widely-used software platform that connects and manages diverse devices in building automation, industrial…

9 months ago

Critical Vulnerabilities in VMware Tools VGAuth Component Allow Attackers to Gain Full System Access

A critical vulnerabilities in VMware Tools that could allow attackers with basic user access to escalate privileges to full system…

9 months ago

Bloomberg Comdb2 Vulnerabilities Allows Attackers to Initiate DoS Attack via Malicious Packet

Five critical security vulnerabilities in Bloomberg's open-source Comdb2 database that could allow attackers to launch denial-of-service attacks through specially crafted…

9 months ago

New VOIP Botnet Targets Routers Using Default Passwords

A sophisticated global botnet campaign targeting Voice over Internet Protocol (VOIP) devices with default credentials, beginning with an unusual concentration…

9 months ago