Category: Uncategorized
-

New Variant of XLoader macOS Malware Disguised as ‘OfficeNote’ Productivity App [email protected] (The Hacker News)
A new variant of an Apple macOS malware called XLoader has surfaced in the wild, masquerading its malicious features under the guise of an office productivity app called “OfficeNote.” “The new version of XLoader is bundled inside a standard Apple disk image with the name OfficeNote.dmg,” SentinelOne security researchers Dinesh Devadoss and Phil Stokes said in a Monday analysis. “The applicationRead…
-

Ivanti Warns of Critical Zero-Day Flaw Being Actively Exploited in Sentry Software [email protected] (The Hacker News)
Software services provider Ivanti is warning of a new critical zero-day flaw impacting Ivanti Sentry (formerly MobileIron Sentry) that it said is being actively exploited in the wild, marking an escalation of its security woes. Tracked as CVE-2023-38035 (CVSS score: 9.8), the issue has been described as a case of authentication bypass impacting versions 9.18 and prior due to…
-

Critical Adobe ColdFusion Flaw Added to CISA’s Exploited Vulnerability Catalog [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability, cataloged as CVE-2023-26359 (CVSS score: 9.8), relates to a deserialization flaw present in Adobe ColdFusion 2018 (Update 15 and earlier) and ColdFusion 2021 (Read More
-
Adobe ColdFusion Deserialization of Untrusted Data Vulnerabilities
FortiGuard Labs continue to see cyber attacks targeting to exploit the coldfusion vulnerability CVE-2023-26360. Blocking over multiple hundreds of attacks over the last weeks.Read More
-
Ivanti Ships Urgent Patch for API Authentication Bypass Vulnerability Ryan Naraine
A critical-severity vulnerability in the Ivanti Sentry (formerly MobileIron Sentry) product exposes sensitive API data and configurations. The post Ivanti Ships Urgent Patch for API Authentication Bypass Vulnerability appeared first on SecurityWeek. Read More
-
Vendors criticize Microsoft for repeated security failings
Post ContentRead More
-
Researchers Uncover Real Identity of CypherRAT and CraxsRAT Malware Developer Ionut Arghire
Cyfirma security researchers uncover the real identity of the CypherRAT and CraxsRAT malware developer and MaaS operator. The post Researchers Uncover Real Identity of CypherRAT and CraxsRAT Malware Developer appeared first on SecurityWeek. Read More
-

New WinRAR Vulnerability Could Allow Hackers to Take Control of Your PC [email protected] (The Hacker News)
A high-severity security flaw has been disclosed in the WinRAR utility that could be potentially exploited by a threat actor to achieve remote code execution on Windows systems. Tracked as CVE-2023-40477 (CVSS score: 7.8), the vulnerability has been described as a case of improper validation while processing recovery volumes. “The issue results from the lack of proper…
-
Australian Lender Latitude Financial Reports AU$76 Million Cyberattack Costs Eduard Kovacs
Australian lender Latitude Financial said the recent ransomware attack has cost it AU$76 million (roughly US$50 million). The post Australian Lender Latitude Financial Reports AU$76 Million Cyberattack Costs appeared first on SecurityWeek. Read More
-
US Gov Warns of Foreign Intelligence Cyberattacks Against US Space Industry Ionut Arghire
The FBI, NCSC, and AFOSI warn US space industry organizations of foreign intelligence targeting and exploitation, including cyberattacks. The post US Gov Warns of Foreign Intelligence Cyberattacks Against US Space Industry appeared first on SecurityWeek. Read More
