You’ve probably never heard of “16Shop,” but there’s a good chance someone using it has tried to phish you. A 16Shop phishing page spoofing Apple and targeting Japanese users. Image: …
Cisco Duo Device Health App Flaw Allows Directory Traversal Attacks
The CryptoService function in the Cisco Duo Device Health Application for Windows has a vulnerability tracked as (CVE-2023-20229). This might allow a low-privileged attacker to carry out directory traversal attacks …
Ivanti Avalanche Flaw Let Attackers Execute Remote Code
Ivanti Avalanche has been reported with several vulnerabilities ranging between Medium to High severity. Vulnerabilities include Arbitrary file upload remote code execution, Authentication bypass, Buffer Overflow, and Directory Traversal remote …
Discord.io Hack Was Due to a Flaw in the Website’s Code
Discord.io experienced a significant data breach on the 14th of August 2023 that risks the privacy of about 760K consumers’ data. The platform revealed the massive data breach on August 15th, claiming …
IBM Security Guardium Flaw Let Attacker to execute arbitrary commands
A Command Injection vulnerability was recently discovered on IBM Security Guardium which allows threat actors to execute arbitrary commands on the affected system remotely. This vulnerability was due to improper …
New Phishing Attack Exploits Cloudflare R2 Hosting Service to Steal Cloud Passwords
The Cloudflare R2 hosting service like the following platforms, which provides a cost-effective large-scale data storage platform to developers with no exit bandwidth charges:- Amazon S3 Google GCS Azure Blob …
New Citrix ADC Zero-Day Scanner Tool Released With IOCs
Citrix was previously discovered with a Zero-Day vulnerability on their Citrix NetScaler Application Delivery Controller (ADC) that allowed threat actors to perform remote code execution. The Zero-Day was found to …
2000+ Citrix NetScalers Hacked to Deploy Webshell
It has been discovered that an attacker installed web shells on susceptible Citrix NetScalers, exploiting the CVE-2023-3519 flaw to acquire persistent access. This critical zero-day vulnerability poses a significant risk …
Cyber Criminals Turned Mac Systems into Proxy Exit Nodes
Besides Windows OS, now threat actors are also actively targeting Mac systems to accomplish their illicit goals. Cybersecurity analysts at AT&T Alien Labs recently observed that threat actors are actively …
Threat Actors Using ChatGPT Lure to Target iPhone and Android Users
The “CryptoRom” scam uses ChatGPT to trick victims into downloading fake crypto-trading mobile applications. Android and iPhone users have reported increased instances of similar fraud utilizing apps from official app stores. …



