Hackers abuse CHM files because they can embed malicious scripts or code within them. Windows systems often trust and execute these files without many security checks. When the CHM …
Hackers Using k4spreader Tool To Install DDoS Botnet And Miners
A new ELF malware tool named k4spreader, written in Cgo by the Chinese “8220” (Water Sigbin) mining gang, was discovered in June 2024. Packed with a modified UPX packer, k4spreader …
Polyfill JS Library Injected Malware Into 100K+ Websites
Polyfill.js is a JavaScript library that gives modern functionality on older browsers without native support for some web features. Polyfills ensure compatibility across a wide range of browsers, enabling developers …
Researchers Released PoC For Windows Bluetooth Service RCE Vulnerability
Microsoft addressed a Remote code execution vulnerability on their Bluetooth service on March 2023 Patch Tuesday. This vulnerability could allow an unauthorized threat actor to run a certain function on …
FireTail Unveils Free Access for All to Cutting-Edge API Security Platform
FireTail announces a free version of its enterprise-level API security tools, making them accessible to developers and organizations of all sizes. FireTail’s unique combination of open-source code libraries, inline API …
HC3 Unveils Qilin Ransomware Attacking Global Healthcare Organizations
The Health Sector Cybersecurity Coordination Center (HC3) has issued a critical alert regarding a new ransomware strain, Qilin, which is targeting healthcare organizations worldwide. This revelation underscores the escalating cyber …
VMware ESXi Vulnerability Allows Attackers to Bypass Authentication
VMware has disclosed three critical vulnerabilities in its ESXi hypervisor that allow attackers to bypass authentication mechanisms. These vulnerabilities, identified as CVE-2024-37085, CVE-2024-37086, and CVE-2024-37087, pose significant risks to organizations …
Neiman Marcus Hacked: 64,000 customers Data Exposed
A Luxury retailer, Neiman Marcus, has disclosed a data breach affecting approximately 64,000 customers. The incident, which came to light after an investigation, exposed sensitive customer information, including names, contact …
P2Pinfect Malware Deploy Ransomware and Cryptominer in Windows Via SSH
Cybersecurity researchers have discovered a significant evolution in the previously dormant P2Pinfect malware strain. The updated version can now deploy ransomware and a cryptominer, posing a serious threat to organizations …
New MOVEit Auth Bypass Vulnerability Under Attack Now, Patch Immediately
Progress Software’s popular MOVEit Transfer and MOVEit Cloud-managed, file transfer solutions, have been found to contain a critical authentication bypass vulnerability (CVE-2024-5806). The vulnerability, which exists in the products’ SFTP …


