FrostyGoop represents a significant advancement in industrial control systems (ICS) malware, being the ninth ICS-specific threat and the first to leverage Modbus TCP communications for directly impacting Operational Technology (OT). …
Tag-100 Hacker Group Exploiting Citrix NetScaler & F5 BIG-IP Vulnerabilities
A new threat actor, TAG-100, has emerged and is actively targeting government and private sector organizations worldwide and initiates its attacks by exploiting vulnerabilities in internet-facing devices, such as Citrix …
Critical Docker Vulnerability Lets Hacker Bypass Authentication
A critical security vulnerability in Docker Engine has been discovered, potentially allowing attackers to bypass authentication and gain unauthorized access to systems. The vulnerability, identified as CVE-2024-41110, affects multiple versions …
ERP Provider Exposes 769 Million Records, Including API Keys And Email Addresses
A massive data breach involving ClickBalance, one of Mexico’s largest Enterprise Resource Planning (ERP) technology providers, has been uncovered by cybersecurity researcher Jeremiah Fowler. The breach exposed a staggering 769,333,246 …
Stargazers Ghost: Network of GitHub Accounts Used to Deliver Malware
Cybersecurity researchers at Check Point have uncovered a sophisticated network of GitHub accounts, dubbed the Stargazers Ghost Network, that has been distributing malware and phishing links since at least June …
Google Chrome 127 Released With Fix for Vulnerabilities that Lead to Browser Crash
Google has announced the release of Chrome 127, which is now available on the Stable channel for Windows, Mac, and Linux. The new version, 127.0.6533.72/73 for Windows and Mac and …
New Windows False File Immutability Vulnerability Let Attackers Execute Arbitrary Code
A new unnamed vulnerability class has been detected in the Windows 11 Kernel that could allow a threat actor to execute arbitrary code with Kernel privileges. This vulnerability, named “File …
CrowdStrike Details Incident Affected Millions of Windows Systems Worldwide
In a recent preliminary Post-Incident Review (PIR), cybersecurity firm CrowdStrike provided a detailed account of the events that led to a massive global IT outage on July 19, 2024. The …
LiteSpeed Cache Plugin Flaw Let Attackers Inject Malicious Code, 5M+ Sites Impacted
The popular LiteSpeed Cache plugin for WordPress has been found vulnerable to a Cross-Site Request Forgery (CSRF) attack, which could potentially impact over 5 million websites. The flaw, identified as …
KnowBe4 Hired Fake North Korean IT Worker, Catches While Installing Malware
Security awareness and training provider KnowBe4 recently disclosed that it inadvertently hired a fake North Korean IT worker who attempted to install malware on a company-issued computer. The incident highlights …










