A cluster of malicious Python projects has been identified in PyPI, the official Python PyPI package repository, which targets both Windows and Linux systems and often deploys a custom backdoor. In certain …
Multiple Flaws in Dell PowerProtect Products Let Attackers Execute OS Commands
Multiple vulnerabilities have been discovered in Dell’s PowerProtect, which were associated with SQL injection, cross-site scripting (XSS), privilege escalation, command injection, and path tracing. The severity for these vulnerabilities ranges …
New Hacker Group Uses SQL Injection to Hack Companies in APAC Region
A new threat actor has been discovered to be using SQL injection attacks to gain unauthorized access to organizations in the APAC region. This threat actor has been named “GambleForce” …
Engineering-assisted Dynamic Malware Analysis using GPT-4 With 100% Recall Rate
A new prompt engineering-assisted Dynamic Malware Analysis model has been introduced, which can overcome the drawbacks faced in the quality API call sequences deployed for dynamic malware analysis. This new …
Zoom Mobile and Desktop App Flaws Let Attackers Escalate Privileges
The popular video conferencing software Zoom has security issues with its desktop and mobile apps that could allow for privilege escalation. An attacker may be able to obtain elevated privileges …
New Dark Web Market OLVX Advertising Variety of Hacking Tools
Threat actors exploit underground markets by purchasing or selling stolen data, malware, and hacking tools to facilitate cybercrime. These underground markets provide the following key facilities among threat actors that …
Microsoft Seized Storm-1152 Websites Used to Sell Microsoft Products & Accounts
Hackers sell fake Microsoft products and accounts because it allows them to profit from illicit activities, taking advantage of unsuspecting users. Microsoft’s security team, partnered with Arkose Labs, is cracking …
Beware of Malicious 7ZIP on the Microsoft App Store that Delivers Malware
Hackers target 7ZIP due to its widespread use and popularity, making it a lucrative vector for spreading malware. Exploiting vulnerabilities in 7ZIP allows them to compromise a large number of …
Hackers Abuse OAuth Applications to Launch Automated Financial Attacks
OAuth (Open Authorization) is an industry-standard protocol that allows third-party applications to access a user’s data without exposing login credentials. This standard protocol facilitates secure authorization and authentication, commonly used …
Recruiters Beware! Hackers Deliver Malware Posing as Job Applicant
Threat actors have been targeting recruiters disguised as job applicants to deliver their malware. Though this method is not unique, the technique and attack vectors have been noted to have …
