Mac users were targeted by a fake browser update chain called ‘ClearFake’, which was delivered by Atomic Stealer to compromise their systems. Malwarebytes has reported that one of the most …
Hackers using Weaponized Office Document to Exploit Windows Search RCE
A new attack chain campaign has been discovered, which involves the exploitation of CVE-2023-36884 and CVE-2023-36584. CVE-2023-36884 was a remote code execution vulnerability, and CVE-2023-36584 was a security bypass vulnerability …
Firefox 120 Released With Security Updates: What’s New!
With the release of Mozilla Firefox 120, 10 vulnerabilities are patched, including six ‘High Severity’ issues and two moderate and low severity issues. The key changes in Firefox 120 include: …
North Korean Hackers Targeting CyberLink Users in Supply-chain Attack
In the ever-evolving realm of cybersecurity, Microsoft Threat Intelligence has uncovered a sophisticated supply chain attack orchestrated by the North Korean Hackers Diamond Sleet (ZINC). This ingenious attack involved tampering …
WailingCrab Malware Abuse Messaging Protocol for C2 Communications
Researchers noticed developments in the sophisticated, multi-component malware dubbed WailingCrab, especially those pertaining to its C2 communication techniques, which included abusing the MQTT Internet-of-Things (IoT) messaging protocol. The WailingCrab malware, commonly …
Hackers Exploiting Windows SmartScreen Zero-day Vulnerability to Deploy Remcos RAT
Microsoft released multiple security patches as part of their Patch Tuesday, in which three zero-day vulnerabilities were also patched. One of the zero-day vulnerabilities was CVE-2023-36025, which affected the Windows …
Bug Hunter GPT – AI Assistant that Replies for Hacking Questions
ChatGPT, like InstructGPT, follows prompts for detailed responses. It answers questions and composes content similar to customer service chatbots. LLMs (Large Language Models) are revolutionizing cybersecurity rapidly with the help …
Citrix Warns Admin to Kill Active or Persistent Sessions to Thwart Hackers
As previously reported, CVE-2023-4966 was discovered and published by Citrix. This vulnerability affected Citrix NetScaler Gateway and ADC devices. Following this, AssetNote published a proof-of-concept for this vulnerability named “CitrixBleed.” …
Hackers Exploiting 0-day RCE Flaws in the Wild to Deploy Mirai Malware
The Mirai botnet is a malicious network of infected computers, routers, and IoT devices harnessed by cybercriminals to launch large-scale DDoS attacks. The destructiveness of Mirai lies in its ability …
Microsoft Defender Bounty Program: Rewards up to $20,000 USD
Microsoft has launched the Defender Bounty Program, which aims to improve the security of its customers’ experience by incentivizing researchers with rewards of up to USD 20,000. Through this program, …
