Threat actors have employed a new technique to distribute malicious code named “EtherHiding,” which abuses Binance’s Smart Chain (BSC) contracts to host parts of a malicious code chain to hide …
IBM QRadar SIEM XSS Flaw Let Attackers Execute JavaScript code
Two medium-severity vulnerabilities have been discovered in the widely used IBM QRadar SIEM, associated with Cross-Site Scripting (XSS) and Information disclosure. The vulnerabilities have been assigned with CVE-2023-40367 and CVE-2023-30994. …
CISA to Flag Vulnerabilities & Misconfigurations Exploited in Ransomware Attacks
Ransomware attacks have grown to be a serious concern for businesses of all sizes, with the potential to seriously harm the operations, finances, and reputation of the targeted enterprises. Many ransomware …
Hackers Abusing Skype and Teams to Deliver the DarkGate Malware
Hackers utilized the Teams and Skype messaging platforms to spread the DarkGate malware to the targeted businesses. When DarkGate malware is installed, a Visual Basic for Applications (VBA) loader script …
Telegram, AWS, and Alibaba Cloud Users Targeted in Latest Supply Chain Attack
A new supply-chain attack, which was active throughout September 2023, has been discovered in which threat actors used Typosquatting and Startjacking techniques to lure developers using Alibaba cloud services, AWS, …
OWASP ZAP 2.14.0 Released – What’s New!
OWASP ZAP is a free and open-source web application security scanner. It is designed to be utilized by expert penetration testers as well as individuals who are new to application …
Microsoft Announced AI Bug Bounty Program that Rewards Up to $15,000
Microsoft created a new AI Bug Bounty program, which rewards people who help improve the AI Power Bing experience. The rewards range from $2,000 to $15,000. The initial release of …
Critical Google Chrome User-After-Free Site Isolation Flaw
As part of a security update for Chrome, Google has upgraded the Stable channels to 118.0.5993.70 for Mac and Linux and 118.0.5993.70/.71 for Windows. The Extended Stable channel has been …
New WordPress Malware as Cache Plugin Creates Rogue Admin Account
A novel kind of malware that acts as a sophisticated backdoor that can carry out several operations while impersonating a legitimate plugin has been identified. The malware has several features, …
Large-scale Akira Ransomware Attacking Unsecured Computers
In order to disrupt human-operated ransomware attacks and prevent attackers from advancing their objectives through lateral movement, it is crucial to swiftly contain any compromised user accounts. Taking this step …

