The company has assessed four of the five disclosed vulnerabilities as being of high to critical severity.
Автор: Jai Vijayan, Contributing Writer
China’s Volt Typhoon Exploits 0-day in Versa’s SD-WAN Director Servers
So far, the threat actor has compromised at least five organizations using CVE-2024-39717; CISA has added bug to its Known Exploited Vulnerability database.
Constantly Evolving MoonPeak RAT Linked to North Korean Spying
The malware is a customized variant of the powerful open source XenoRAT information stealing malware often deployed by Kimsuky and other DPRK APTs.
NFC Traffic Stealer Targets Android Users & Their Banking Info
The malware builds on a near-field communication tool in combination with phishing and social engineering to steal cash.
‘Styx Stealer’ Blows Its Own Cover With Sloppy OpSec Mistake
An individual in Turkey is behind a new information stealer that researchers have recently observed in multiple attacks.
Azure Kubernetes Bug Lays Open Cluster Secrets
Vulnerability gave attackers with access to a pod a way to obtain credentials and other secrets.
Multiple Microsoft Apps for macOS Vulnerable to Library Injection Attacks
Outlook, Teams, PowerPoint, OneNote, Excel, and Word undermine macOS’s strict user permission-based privacy and security protections.
National Public Data Confirms Massive Breach
Cyber incidents like this highlight the need for tougher action on companies that fail to adequately protect consumer data.
Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
The attack affects organizations that have synced multiple on-premises Active Directory domains to a single Azure tenant.
‘EastWind’ Cyber-Spy Campaign Combines Various Chinese APT Tools
The likely China-linked campaign is deploying CloudSorcerer and other proprietary binaries belonging to known state-sponsored groups, showing how advanced persistent threat groups often collaborate with each other.