Google, a well-known tech giant, has introduced a new feature called “passwordless by default”. This feature aims to simplify the login process for users by eliminating the need for traditional …
Heap-based Buffer Overflow Flaw in cURL Library Using SOCKS5 Proxy
Previously, the maintainers of the popular curl command line tool posted a pre-announcement regarding two vulnerabilities that affected both the curl tool and the libcurl library. However, the details of …
How LLM-like Models like ChatGPT patch the Security Gaps in SoC Functions
The emergence of Large Language Models (LLMs) is transforming NLP, enhancing performance across NLG, NLU, and information retrieval tasks. They are primarily excellent in text-related tasks like generation, summarization, translation, …
Nation-state Hackers Exploiting Confluence Zero-day Vulnerability
Microsoft has detected the nation-state threat actor Storm-0062, also known as DarkShadow or Oro0lxy, exploiting CVE-2023-22515 in the wild since September 14, 2023. The vulnerability was publicly disclosed on October …
Top 10 Best SaaS Security Tools
Security management across multiple Software-as-a-Service (SaaS) clouds can present challenges, primarily stemming from the heightened prevalence of malware and ransomware attacks. In the present landscape, organizations encounter many challenges with …
SAP Patches for XSS, Log Injection & Other Vulnerabilities
SAP has released the security patches for the Patch Day of October 2023, in which they release new Security Notes and 2 updates to the previously released Security Notes. There …
HTTP/2 Rapid Reset Zero-day Flaw Exploited to Launch Massive DDoS Attack
Cloudflare was unexpectedly hit by an enormous HTTP attack that peaked at over 201 million requests per second. Starting on August 25, 2023, this onslaught posed a significant challenge, especially …
Patch Tuesday, October 2023 Edition
Microsoft today issued security updates for more than 100 newly-discovered vulnerabilities in its Windows operating system and related software, including four flaws that are already being exploited. In addition, Apple …
New APT Group Using Custom Malware to Attack Manufacturing & IT Industries
An unidentified APT group deployed custom malware and public tools to target organizations in Taiwan’s following sectors:- Manufacturing IT Biomedical This campaign also targeted a government agency in the Pacific …
Hackers Exploiting Citrix NetScaler Vulnerability to Steal User Credentials
Threat actors were attacking unpatched NetScaler Gateways using the vulnerability classified as CVE-2023-3519 to inject malicious script into the HTML of the authentication web page and steal user credentials. With a …


