Category: Uncategorized
-
Hitron DVR Zero-Day Vulnerabilities Exploited by InfectedSlurs Botnet Ionut Arghire
Akamai flags six zero-day vulnerabilities in Hitron DVRs exploited to ensnare devices in the InfectedSlurs botnet. The post Hitron DVR Zero-Day Vulnerabilities Exploited by InfectedSlurs Botnet appeared first on SecurityWeek. Read More
-

Chinese Hackers Exploiting VPN Flaws to Deploy KrustyLoader Malware [email protected] (The Hacker News)
A pair of recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been exploited to deliver a Rust-based payload called KrustyLoader that’s used to drop the open-source Sliver adversary simulation tool. The security vulnerabilities, tracked as CVE-2023-46805 (CVSS score: 8.2) and CVE-2024-21887 (CVSS score: 9.1), could be abusedRead More
-

New Glibc Flaw Grants Attackers Root Access on Major Linux Distros [email protected] (The Hacker News)
Malicious local attackers can obtain full root access on Linux machines by taking advantage of a newly disclosed security flaw in the GNU C library (aka glibc). Tracked as CVE-2023-6246, the heap-based buffer overflow vulnerability is rooted in glibc’s __vsyslog_internal() function, which is used by syslog() and vsyslog() for system logging purposes. It’s said to have been…
-

Brazilian Feds Dismantle Grandoreiro Banking Trojan, Arresting Top Operatives [email protected] (The Hacker News)
A Brazilian law enforcement operation has led to the arrest of several Brazilian operators in charge of the Grandoreiro malware. The Federal Police of Brazil said it served five temporary arrest warrants and 13 search and seizure warrants in the states of São Paulo, Santa Catarina, Pará, Goiás, and Mato Grosso. Slovak cybersecurity firm ESET, which provided additionalRead More
-

URGENT: Upgrade GitLab – Critical Workspace Creation Flaw Allows File Overwrite [email protected] (The Hacker News)
GitLab once again released fixes to address a critical security flaw in its Community Edition (CE) and Enterprise Edition (EE) that could be exploited to write arbitrary files while creating a workspace. Tracked as CVE-2024-0402, the vulnerability has a CVSS score of 9.9 out of a maximum of 10. “An issue has been discovered in GitLab CE/EE…
-
data loss
Post ContentRead More
-
ChatGPT Violated European Privacy Laws, Italy Tells Chatbot Maker OpenAI Associated Press
Italian regulators told OpenAI that its ChatGPT artificial intelligence chatbot has violated GDPR. The post ChatGPT Violated European Privacy Laws, Italy Tells Chatbot Maker OpenAI appeared first on SecurityWeek. Read More
-
The Ransomware Threat in 2024 is Growing: Report Kevin Townsend
Anyone who believes ransomware will go away doesn’t understand the nature of criminality. Extortion has and always will be a primary criminal business plan. The post The Ransomware Threat in 2024 is Growing: Report appeared first on SecurityWeek. Read More
-
Data of 750 Million Indian Mobile Subscribers Sold on Hacker Forums Ionut Arghire
A massive database containing the information of 85% of the Indian population has emerged on the dark web. The post Data of 750 Million Indian Mobile Subscribers Sold on Hacker Forums appeared first on SecurityWeek. Read More
-
Secure your machine learning models with these MLSecOps tips
Post ContentRead More
