A new claim has surfaced on the internet regarding a zero-day exploit that targets the Windows operating system. This exploit, which enables local privilege escalation (LPE), could allow attackers to …
WordPress Plugin SQl Injection Exposes 1,000,000 Sites to Cyber Attack
Over a million WordPress websites have been at risk due to a critical SQL Injection vulnerability discovered in the popular LayerSlider plugin. The flaw, CVE-2024-2879, could allow unauthenticated attackers to …
Feds Stepping to Patch Years-old SS7 Vulnerability in Phone Networks
The FCC (Federal Communications Commission) seeks public input regarding measures by communications providers to address vulnerabilities in SS7 and Diameter protocols that enable tracking consumers’ mobile device locations without consent. …
Aembit Selected as Finalist for RSA Conference 2024 Innovation Sandbox Contest
The Leading Company for Securing Access Between Workloads Recognized for the Aembit Workload IAM Platform Aembit, the Workload Identity and Access Management (IAM) Company, has been named one of the …
WP-Members Plugin Expose WordPress Sites To Injection Attacks
A security researcher reported a critical vulnerability in the WP-Members Membership Plugin that allows attackers to inject malicious scripts and potentially take over websites. Administrators could take advantage of the …
StrelaStealer Attacking Users to Steal Logins from Outlook & Thunderbird
A sophisticated variant of StrelaStealer malware has been identified, targeting Spanish-speaking users with the primary aim of pilfering email account credentials from popular email clients Outlook and Thunderbird. This updated …
New Chrome Feature Blocks Hackers From Stealing Your Cookie
Google has unveiled a new web feature called “Device Bound Session Credentials (DBSC)” that will help protect users from cookie theft. Malware that steals cookies from users and allows attackers …
What is Malware Packers? How To Analyse With ANY.RUN Sandbox – SOC/DIFR Guide
Antiviruses can quickly detect malicious executable files, but attackers can bypass this by using packers to compress and obfuscate the code, making it difficult for antivirus software to analyze. Packers …
Chinese Hackers Hijack Swedish Routers to Launch Cyber Attacks
The Security Police (Säpo) has disclosed that a Chinese hacker group, APT31, has commandeered Swedish routers to perpetrate cyber attacks against multiple countries. This sophisticated cyber espionage campaign, believed to …
New Pikabot Campaign Weaponizes HTML, Javascript & Excel Files
A new player has emerged with a sophisticated approach to infiltrating systems worldwide. Dubbed Pikabot, this malicious backdoor has been active since early 2023, but recent activities have showcased its …



