Pwn2Own 2024 Automotive is a unique event aimed at identifying and fixing flaws in connected automotive technologies. Tokyo, Japan, hosts the Pwn2Own 2024 Automotive from January 24–26, 2024. Tesla is …
Mass Exploitation of Ivanti VPN Exposes Corporate Networks to Hack Attacks
It was previously reported that Ivanti Connect Secure was vulnerable to an authentication bypass (CVE-2023-46805) and a command injection vulnerability (CVE-2024-21887) actively exploited by threat actors in the wild. Moreover, …
Exploit Released for Critical GoAnywhere MFT Auth Bypass : Patch Now
Fortra-owned GoAnywhere MFT (Managed File Transfer) has been discovered with a new vulnerability that could allow an unauthorized threat actor to create an admin user via the administration panel. This …
Transfer Learning in Computer Vision: Adapting Pre-trained Models for New Tasks
To simplify and speed up data-backed software solutions, specially trained machine models are used. However, it is challenging and time-consuming to train these models from the very beginning. That’s why …
LockBit Ransomware Gang Claims Cyber Attack on Subway
An infamous cybercriminal group known as LockBit Ransomware recently targeted Subway’s food chain, unleashing a vicious attack that could potentially lead to the exposure of sensitive data. The extent of …
Re-vamped Zloader Attacking Windows Users With New RSA Encryption
Zloader, also known as Terdot, DELoader, or Silent Night, is a modular trojan that reappeared after nearly two years of absence but with significant enhancements to the loader module. Zloader has …
ThreeAM Ransomware Attacking Small & Medium Companies
For financial gain, hackers exploit ransomware through which they encrypt victims’ data and then demand a ransom payment in exchange for its release. It shows the urgency and importance of …
Apple Critical Zero-day Flaw Exposes iPhones & Macs
Apple has released its first zero-day vulnerability patch of 2024, which affected several Apple products, including tvOS, iOS, iPadOS, macOS, and Safari. The zero-day is tracked under the CVE ID …
Atlassian Confluence Servers Attacked From 600+ IP Addresses
Atlassian disclosed a critical vulnerability last week related to Remote Code Execution (CVE-2023-22527). This particular vulnerability was reported to be affecting Confluence Data Center and Server versions released earlier than …
What is Infrastructure as Code Security (IaC) – Best Practices Guide in 2024
Infrastructure as Code (IaC) is a popular DevOps practice that manages and provides IT infrastructure through code rather than manual processes. This shift streamlines operations and ensures consistency and speed …
