In the open-source ecosystem, shadows shift as collaboration succeeds, attracting both novices and skilled threat actors. A rising threat has been evolving and sharpening its tools in recent months. Checkmarx …
Apple Emergency Update for New Zero-Day Used to Hack iPhones
Apple Emergency Update for New Zero-Day Used to Hack iPhones By Eswar – October 5, 2023 Apple has discovered a Zero-day vulnerability affecting iOS and iPadOS versions earlier than 17.0.3, …
Wireshark 4.0.10 Released: What’s New!
Wireshark has been the most widely used open-source Network protocol analyzing tool for several purposes, including troubleshooting, analysis, development, and education. On their previous release of 4.0.9, CVE-2023-5371, associated with …
Top 10 SaaS Security Risks and How to Mitigate Them
SaaS, an acronym for Software as a Service, is a software distribution model that enables organizations to access and utilize ready-made software solutions. Rather than developing and customizing software in-house, …
Sony Breached Via MOVEit Zero-Day Vulnerability
Sony Interactive Entertainment (SIE) discloses a cybersecurity breach caused by the exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer platform. Nearly 6791 current and former workers or members of …
Malicious npm Package from a Twin Developers Deliver r77 Rootkit
A malicious supply chain attack affecting the popular npm platform, often used for Node.js projects, has been identified. This attack employs a tactic known as typosquatting, where malicious actors create …
EvilProxy Attacking Microsoft 365 Users Abusing Open Redirection With Indeed.com
EvilProxy Attacking Microsoft 365 Users Abusing Open Redirection With Indeed.com By Guru – October 5, 2023 A recent phishing campaign, identified by Menlo Labs, has been actively targeting executives in …
Qualcomm Sys Hackers Actively Exploit 3 new Zero-Days – Patch Now
Three new zero days have been reported to Qualcomm, which were CVE-2023-33106, CVE-2023-33107, and CVE-2023-33063. These vulnerabilities were discovered as part of Google Project Zero and were disclosed to Qualcomm …
Microsoft Teams & Edge Zero-Day Vulnerabilities Leads to Code Execution
Microsoft has addressed two zero-day vulnerabilities in two Open-Source Software security vulnerabilities, which include Microsoft Edge, Microsoft Teams for Desktop, Skype for Desktop, and Webp images extension. These vulnerabilities were …
Exim SMTP Service Zero-day Flaw Let Attackers Execute Remote Code
Six new zero-day vulnerabilities in Exim Message Transfer Agent have been reported as part of the Zero-Day initiative. These vulnerabilities were discovered in June 2022 but were not disclosed until …


