Category: Uncategorized
-
WinRAR ZIP Arbitrary Code Execution Vulnerability (CVE-2023-38831)
What is WinRAR? WinRAR is a popular utility tool for file compression/decompression and archive management. What is the Attack? CVE-2023-38831 is an arbitrary code execution vulnerability that affects WinRAR before version 6.23. The vulnerability allows threat actors to create a zip file that contains a folder and a file with the same filename. Opening (some…
-
Adobe ColdFusion Deserialization of Untrusted Data Vulnerabilities (CVE-2023-26359, CVE-2023-26360)
What is Adobe ColdFusion? Adobe ColdFusion is a commercial rapid web-application and mobile applications development platform. What is the Attack? CVE-2023-26359 and CVE-2023-26360 are deserialization of untrusted data vulnerabilities that affect Adobe ColdFusion. Successful exploitation of the vulnerabilities could allow unauthenticated attackers to achieve arbitrary code execution. CVE-2023-26359 has a CVSS score of 9.8 and…
-
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability (CVE-2023-24489)
What is Citrix Content Collaboration? Citrix Content Collaboration is a security-focused collaboration, content sharing and synchronization service from Citrix for the enterprise. What is the Attack? CVE-2023-24489 is a directory traversal vulnerability that affects Citrix Systems ShareFile StorageZones Controller prior to 5.11.24. The vulnerability is due to improper validation of user input in the ProcessRawPostedFile…
-
University of Minnesota Confirms Data Breach, Says Ransomware Not Involved Ionut Arghire
University of Minnesota confirms data was stolen from its systems, says no malware infection or file encryption has been identified. The post University of Minnesota Confirms Data Breach, Says Ransomware Not Involved appeared first on SecurityWeek. Read More
-

Lazarus Group Exploits Critical Zoho ManageEngine Flaw to Deploy Stealthy QuiteRAT Malware [email protected] (The Hacker News)
The North Korea-linked threat actor known as Lazarus Group has been observed exploiting a now-patched critical security flaw impacting Zoho ManageEngine ServiceDesk Plus to distribute a remote access trojan called such as QuiteRAT. Targets include internet backbone infrastructure and healthcare entities in Europe and the U.S., cybersecurity company Cisco Talos said in a two-part analysis Read More
-
Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks Ionut Arghire
Cisco has released patches for three high-severity vulnerabilities in NX-OS and FXOS software that could lead to denial-of-service (DoS) conditions. The post Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks appeared first on SecurityWeek. Read More
-
Mysterious Malware Uses Wi-Fi Scanning to Get Location of Infected Device Eduard Kovacs
Mysterious Whiffy Recon malware scans for nearby Wi-Fi access points to obtain the location of the infected device. The post Mysterious Malware Uses Wi-Fi Scanning to Get Location of Infected Device appeared first on SecurityWeek. Read More
-
FBI: Suspected Chinese actors continue Barracuda ESG attacks
Post ContentRead More
-
FBI: Patches for Recent Barracuda ESG Zero-Day Ineffective Ionut Arghire
The FBI says that the patches Barracuda released in May for an exploited ESG zero-day vulnerability (CVE-2023-2868) were not effective. The post FBI: Patches for Recent Barracuda ESG Zero-Day Ineffective appeared first on SecurityWeek. Read More
-

New Telegram Bot “Telekopye” Powering Large-scale Phishing Scams from Russia [email protected] (The Hacker News)
A new financially motivated operation is leveraging a malicious Telegram bot to help threat actors scam their victims. Dubbed Telekopye, a portmanteau of Telegram and kopye (meaning “spear” in Russian), the toolkit functions as an automated means to create a phishing web page from a premade template and send the URL to potential victims, codenamed Mammoths by the…
