GitLab released security patches 16.11.1, 16.10.4, and 16.9.6 for both Community and Enterprise Editions, and upgrading to these versions is strongly recommended to address vulnerabilities. Scheduled patch releases occur twice …
New Qiulong Ransomware Well-Equiped To Make Waves
The Qiulong ransomware gang, a new cyber threat actor, has emerged targeting Brazilian victims as the group announced their arrival by compromising Dr. Lincoln Graca Neto and Rosalvo Automoveis, two …
ArcaneDoor Exploiting Cisco Zero-Days To Attack Government Networks
Hackers target Cisco zero-days as they can abuse the widely used networking equipment that contains vulnerabilities which means they can affect many systems and networks in one shot. Attackers use …
KnowBe4 to Acquire Egress for Aids in Email Awareness Training
KnowBe4, the leader in security awareness training and simulated phishing platforms, has announced its definitive agreement to acquire Egress, a pioneer in adaptive and integrated cloud email security. This acquisition …
Social Engineering Paves the Way for the XZ Cyber Incident
The XZ cyber incident is a textbook example of how sophisticated social engineering tactics can lead to significant security breaches. Over the course of two years, a carefully planned attack …
Google Meet Now Allows Non-Google Account Users to Join Encrypted Calls
Google has announced that external participants without Google accounts can join client-side encrypted Google Meet calls. This move marks a substantial step in balancing user accessibility with robust security measures. …
Volkswagen Hacked – Hackers Stolen 19,000 Documents From VW Server
Volkswagen, one of the world’s leading automotive manufacturers, has fallen victim to a sophisticated hacking operation in a significant cybersecurity breach. Investigations suggest that the cyberattack originated in China, raising …
Beware Of Fake MetaMask Android Apps That Steal Login Details
Threat actors exploit fake Android apps primarily for illicit reasons, such as stealing sensitive and personal information from unsuspecting users. Besides this, these fake apps often mimic legitimate ones to …
CrushFTP Zero-Day Could Allow Attackers To Gain Complete Server Access
CrushFTP disclosed a zero-day vulnerability (CVE-2024-4040) affecting versions below 10.7.1 and 11.1.0. The vulnerability allows remote attackers with low privileges to bypass the VFS sandbox and read arbitrary files on …
IBM QRadar XSS Flaw Let Attackers Arbitrary JavaScript Code
A significant vulnerability was detected in IBM QRadar Suite Software and Cloud Pak for Security, allowing attackers to execute arbitrary JavaScript code. An attacker can insert harmful executable scripts into …
