A Stored Cross-Site Scripting (Stored XSS) vulnerability was recently discovered in Cacti that allows an authenticated user to poison the data stored in Cacti’s database. Moreover, administrative accounts can view this …
Pandora Malware Attacks Android TVs via Firmware Updates and Pirated Video
A new threat to Android devices named android[.]pandora has been identified that compromises the devices when pirated video content is installed or during firmware updates. This malware belongs to the …
Hackers Using ChatGPT to Generate Malware & Social Engineering Threats
Large language models (LLMs) and generative AI are rapidly advancing globally, offering great utility but also raising misuse concerns. The rapid modernization of generative AI and its AI counterparts will …
Top 20 Most Exploited Vulnerabilities: Microsoft Products Draw Hackers
Finding and patching the open vulnerabilities in today’s threat landscape is one of the utmost priorities for security researchers and analysts. Identifying weaponized high-risk CVEs actively targeted by Threat Actors …
Samsung Issued Patches for Multiple Critical Security Flaws
Samsung Mobile has issued fixes to address several security flaws discovered in Galaxy phones and tablets. In the September 2023 security patch, 62 bugs were fixed; Google provided 27 of …
Dastardly From BurpSuite: Lightweight Web App Security Scanner
Dastardly is a powerful web vulnerability DAST (Dynamic Application Security Testing) scanner developed to assist organizations in effectively safeguarding their web applications. It is a free, lightweight web application security scanner …
AtlasVPN Zero-day Vulnerability Leaks the users IP Address
A Critical 0-day vulnerability was discovered in AtlasVPN for Linux, which can disconnect the AtlasVPN and leak the user’s IP address. The AtlasVPN, running a daemon on Linux, also runs …
Windows’s File History Service Flaw Let Attackers Escalate Privileges
A Privilege Escalation was recently discovered, which affects Windows’s File History service and can be used by threat actors to gain escalated privileges on a Windows System. This issue was …
Hackers Weaponizing MinIO Storage System Flaws to Execute Remote Code
Recent reports indicate two vulnerabilities relating to information disclosure and remote code execution in MinIO, and their proof of concept was publicly disclosed. Threat actors relied on a non-native solution …
Holiday Season Cyber Alert: Reflectiz Declares War on Magecart
Reflectiz, a cybersecurity company specializing in continuous web threat management, offers an exclusive, fully remote solution to battle Magecart web-skimming attacks, a popular cyberattack involving injecting malicious code into the …
