Category: Uncategorized
-
Oracle WebLogic Authentication Bypass Attack (CVE-2020-14883, CVE-2020-14882)
What is the Attack? An attack campaign led by the 8220 gang has been seen leveraging a 3-year old Oracle WebLogic Server vulnerabilities (CVE-2020-14883 which is commonly chained with CVE-2020-14882) to distribute malware. The attackers are able to download maliciously crafted XML files, allowing remote code execution, and finally deploying stealer and cryptominer malware such…
-
10 of the biggest ransomware attacks in 2023
Post ContentRead More
-

Experts Detail Multi-Million Dollar Licensing Model of Predator Spyware [email protected] (The Hacker News)
A new analysis of the sophisticated commercial spyware called Predator has revealed that its ability to persist between reboots is offered as an “add-on feature” and that it depends on the licensing options opted by a customer. “In 2021, Predator spyware couldn’t survive a reboot on the infected Android system (it had it on iOS),”…
-

Chameleon Android Banking Trojan Variant Bypasses Biometric Authentication [email protected] (The Hacker News)
Cybersecurity researchers have discovered an updated version of an Android banking malware called Chameleon that has expanded its targeting to include users in the U.K. and Italy. “Representing a restructured and enhanced iteration of its predecessor, this evolved Chameleon variant excels in executing Device Takeover (DTO) using the accessibility service, all while expanding its targeted…
-
Web fuzzing: Everything you need to know
Post ContentRead More
-
Celebrities Found in Unprotected Real Estate Database Exposing 1.5 Billion Records Ionut Arghire
Real Estate Wealth Network database containing real estate ownership data, including for celebrities and politicians, was found unprotected. The post Celebrities Found in Unprotected Real Estate Database Exposing 1.5 Billion Records appeared first on SecurityWeek. Read More
-

New JavaScript Malware Targeted 50,000+ Users at Dozens of Banks Worldwide [email protected] (The Hacker News)
A new piece of JavaScript malware has been observed attempting to steal users’ online banking account credentials as part of a campaign that has targeted more than 40 financial institutions across the world. The activity cluster, which employs JavaScript web injections, is estimated to have led to at least 50,000 infected user sessions spanning North…
-
ESET Patches High-Severity Vulnerability in Secure Traffic Scanning Feature Eduard Kovacs
ESET has patched CVE-2023-5594, a high-severity vulnerability that can cause a browser to trust websites that should not be trusted. The post ESET Patches High-Severity Vulnerability in Secure Traffic Scanning Feature appeared first on SecurityWeek. Read More
-
ESO Solutions Data Breach Impacts 2.7 Million Individuals Ionut Arghire
ESO Solutions is informing 2.7 million individuals of a data breach impacting their personal and health information. The post ESO Solutions Data Breach Impacts 2.7 Million Individuals appeared first on SecurityWeek. Read More
-
Ivanti Patches Dozen Critical Vulnerabilities in Avalanche MDM Product Eduard Kovacs
Ivanti has patched 20 vulnerabilities in its Avalanche MDM product, including a dozen remote code execution flaws rated critical. The post Ivanti Patches Dozen Critical Vulnerabilities in Avalanche MDM Product appeared first on SecurityWeek. Read More
