FIRST, the Forum of Incident Response and Security Teams has recently unveiled the latest version of their Common Vulnerability Scoring System (CVSS). The new CVSS 4.0 is the replacement of …
Boeing Admits Cyberattack; Lockbit Claims Zero-Day Exploit Was Used to Gain Access
Boeing, the aerospace industry leader, has recently reported a cyberattack on its systems. The attack primarily targeted the company’s parts and distribution business. While this breach has not affected flight …
VMware Workspace Flaw Let Attacker Redirect User to Malicious Source
An open redirect vulnerability in the VMware Workspace ONE UEM console has been identified as CVE-2023-20886, which has a CVSS score of 8.8 and is classified as ‘Important’ in severity. By …
Iranian APT Group Utilize IIS-based Backdoors to Compromise Windows servers
A new threat actor who is found to be associated with Iran’s Ministry of Intelligence and Security (MOIS) IIS has been discovered to be conducting cyberespionage campaigns. Their targets are …
Kubernetes Security Flaw Let Attackers Escalate to Admin Privileges
A new privilege escalation vulnerability has been discovered in Kubernetes, which allows threat actors to gain administrative privileges on affected pods. The CVE for this vulnerability has been assigned as …
Knight Ransomware Attacking Windows Computer to Exfiltrate Sensitive Data
Knight ransomware, a relatively new ransomware gang that first appeared in August 2023, targets Windows computers to steal sensitive data. Several industrial sectors have been attacked by the Knight ransomware …
Strategic App Management: Simplifying, Securing, and Optimizing Device Workflows
In today’s tech-driven world, our reliance on mobile devices is second nature. With apps powering our daily tasks, smooth app management across enterprise devices is more pressing than ever. But …
Palo Alto Networks to Acquire Cloud Security Start-up Dig
One of the top companies in the cybersecurity industry, Palo Alto Networks, has recently finalized the acquisition of Dig Security, an up-and-coming startup that specializes in providing advanced security solutions …
Within 5 Minutes, Hackers Were Able to Get AWS Credentials From GitHub
Recent reports indicate that a new campaign under the name EleKtra-Leak has been identified to target AWS IAM (Identity and Access Management) credentials within minutes of their public exposure on …
Exploit Released for Cisco IOS XE Zero-day Vulnerability
Cisco was reported with a critical vulnerability last week, which has been actively exploited by threat actors in the wild. The vulnerability was assigned with the CVE-2023-20198 and was given …










