A hacktivist entity known as USDoD has claimed to have leaked CrowdStrike’s “entire threat actor list” and alleged possession of the company’s “entire IOC [indicators of compromise] list”, which contains …
Google Chrome Enhances Security to Block Malicious Downloads
Google has recently unveiled significant updates to Chrome’s download protection features, aiming to provide users with enhanced security against potentially harmful files. These changes come as part of Google’s ongoing …
6600+ Vulnerable GeoServer instances Exposed to the Internet
Security analysts have identified 6,635 GeoServer instances exposed to the Internet, which makes them vulnerable to critical remote code execution (RCE) attacks. A recent tweet from the Shadowserver Foundation stated …
Microsoft’s Windows Hello for Business Flaw Let Attackers Bypass Authentication
A recently discovered vulnerability in Microsoft’s Windows Hello for Business (WHfB) authentication system allowed attackers to bypass the supposedly phishing-resistant login method, raising concerns about the security of this widely …
DDoS Attack Lasted for 6 Days, Record created for the duration of the Cyberattack
A financial institution in the Middle East endured a record-breaking Distributed Denial of Service (DDoS) attack for six days. The attack, orchestrated by the hacktivist group SN_BLACKMETA, set a new …
Progress Telerik Report Server Flaw Let Attackers Execute Remote Code
A critical security vulnerability has been discovered in the Progress® Telerik® Report Server, potentially allowing attackers to execute remote code on affected systems. The flaw, identified as CVE-2024-6327, has been …
GitLab Patch XSS Vulnerability that Lets Attackers to Execute Arbitrary Code
GitLab has released new Community Edition (CE) and Enterprise Edition (EE) versions to address multiple vulnerabilities. Among these, a high-severity cross-site scripting (XSS) vulnerability has garnered particular attention due to …
BIND DNS Vulnerability Lets Attackers Flood Server With DNS Messages
The Internet Systems Consortium (ISC) has released critical security advisories addressing multiple vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 software, a cornerstone of the Domain Name System (DNS) …
Darkgate Autoit Converter Bypasses Windows Defender & Most Antiviruses
A new tool known as the Darkgate Autoit Converter Crypter has emerged on the dark web. This sophisticated malware is designed to bypass Windows Defender and most other antivirus programs, …
Beware of New Krampus Loader That Getting Popular in Dark Web
A new malware loader named “Krampus” has surfaced on the dark web, gaining rapid popularity among threat actors. The loader was announced on a dark web forum by a threat …










