Hackers target 7ZIP due to its widespread use and popularity, making it a lucrative vector for spreading malware. Exploiting vulnerabilities in 7ZIP allows them to compromise a large number of …
Hackers Abuse OAuth Applications to Launch Automated Financial Attacks
OAuth (Open Authorization) is an industry-standard protocol that allows third-party applications to access a user’s data without exposing login credentials. This standard protocol facilitates secure authorization and authentication, commonly used …
Recruiters Beware! Hackers Deliver Malware Posing as Job Applicant
Threat actors have been targeting recruiters disguised as job applicants to deliver their malware. Though this method is not unique, the technique and attack vectors have been noted to have …
Lazarus Group’s Operation Blacksmith Attacking Organizations Worldwide
The Lazarus Group is a notorious North Korean state-sponsored hacking organization known for:- Cyber espionage Financial Theft Destructive attacks They have been implicated in high-profile incidents, including the 2014 Sony …
Microsoft Patch Tuesday, December 2023 Edition
The final Patch Tuesday of 2023 is upon us, with Microsoft Corp. today releasing fixes for a relatively small number of security holes in its Windows operating systems and other …
Hackers Planting Credit Card Skimmers Inside Google Tag Manager Scripts
Recently, it has been reported that Magecart Veteran ATMZOW has found 40 new domains of Google Tag Manager. As a result, thousands of websites have been affected by this security …
New Editbot Stealer in Action; Stealing Browser Passwords & Cookies
A new malicious campaign, Editbot Stealer, was discovered in which threat actors use WinRAR archive files with minimal detection to perform a multi-stage attack. Threat actors have been utilizing the …
Apple Urgently Patches Zero-day Flaw Exploited in the Wild
Apple has released an emergency security update for patching two actively exploited zero-day vulnerabilities on iOS. The vulnerabilities were discovered earlier this month and are tracked as CVE-2023-42916, and CVE-2023-42917 …
Apache ActiveMQ Vulnerability Exploited by Kinsing to Attack Linux Servers
Threat actors actively targeted the Apache ActiveMQ vulnerability to get unauthorized access to messaging systems, leading to potential data breaches and system compromise. Meanwhile, the Apache ActiveMQ vulnerability, which was …
Researchers Bypassed Android Lock Screen using Driving mode Assistant
Recent reports indicate that researchers have discovered a new method to bypass the Android Lock Screen and extract sensitive information like photos, contacts, browsing history, shared location, and much more. …

