Researchers at Qualys discovered a new Remote Code Execution flaw in the OpenSSH. This flaw exists in OpenSSH’s forward ssh-agent. This flaw allows an attacker to execute arbitrary commands on …
Chinese APT41 Group Attack Android Devices With WyrmSpy and DragonEgg Malware
A Chinese-based state-sponsored espionage group, APT41 targets Android devices through spyware wyrmspy and Dragon egg which masquerades as legit applications. This group has been active since 2012 and targets both …
Chrome 115 Update for Windows, MacOS, and Linux – 20 Vulnerabilities Patched
Google released Chrome 115 to the stable channel for Windows, MacOS, and Linux on Tuesday, patching 20 vulnerabilities, including 11 that were discovered by external researchers. Four security issues were assessed …
VirusTotal Data Leak Exposes User’s Sensitive Details
The latest news revealed a popular Google platform to scan malicious documents from Virustotal exposed to data breaches of its registered customers. At the end of June, a file comprising …
New Jailbreak Attacks are revealed in LLM Chatbots like ChatGPT
LLMs have reshaped content generation, making understanding jailbreak attacks and prevention techniques challenging. Surprisingly, there’s a scarcity of public disclosures on countermeasures employed in chatbot services that are commercial LLM-based. …
HCL BigFix WebUI Flaw Redirects User to External Site
HCL BigFix is an endpoint management platform that has the capability to automate discovery, management, and remediation. It can find and fix vulnerabilities on endpoints, whether it be on-premises, cloud, …
Hackers Could Deactivate Your WhatsApp Account With A Simple Email
It has been reported that any individual could potentially deactivate a WhatsApp account by sending an email, and currently, there is no known method to prevent this from happening. This …
CISA Urge Gov Agencies to Apply Patch for Windows and Office zero-days Immediately
CISA urged government agencies to apply the patch immediately for Microsoft Office and Windows HTML remote code execution vulnerabilities exploited in the wild. As a result, these vulnerabilities have frequently …
JumpCloud Hacked – Hackers Breached The Systems Via Spear-Phishing Attack
A sophisticated nation-state adversary with advanced capabilities attacked Jumpcloud with a spear phishing attack. JumpCloud is a US-based zero-trust directory platform that customers use to authenticate, authorize, and manage users, …
IT Security Analyst Jailed for Impersonating as a Hacker in Own Company
A 28 years old Former IT security analyst of an Oxford-based company has been sentenced to three years for deceiving the company to extort money. On 27 February 2018, the …

