Information Security News Blog
Microsoft has patched a zero-day vulnerability that was actively exploited to propagate the QakBot botnet on Windows systems. The heap-based buffer overflow vulnerability, CVE-2024-30051 (CVSS score 7.8), affects the Desktop Window Manager (DWM) library....
According to a recent report by ESET, the Ebury botnet has infected nearly 400,000 Linux servers since 2009. As of the end of 2023, approximately 100,000 servers remain at risk. ESET researchers have been...
Four critical vulnerabilities have been identified in VMware Workstation and Fusion products, potentially allowing attackers to access confidential information, conduct DoS attacks, and execute arbitrary code. These issues affect Workstation 17.x and Fusion 13.x...
Experts from SSD Secure Disclosure have discovered vulnerabilities in the D-Link EXO AX4800 (DIR-X4860) router, which allow an attacker to gain complete control over the device. The flaws were found in DIR-X4860 routers with...
According to Wccftech, Google recently held the I/O 2024 conference, where it unveiled its latest sixth-generation cloud TPU, “Trilium,” which has already been integrated into Google’s AI supercomputer. Additionally, Google announced the inclusion of...
Google has urgently released patches for a newly discovered zero-day flaw in Chrome, following reports of active exploitation by unknown attackers. The vulnerability, catalogued as CVE-2024-4947, affects the V8 JavaScript engine integral to Google’s...
Researchers have identified an actively evolving social engineering campaign aimed at gaining initial access to corporate IT systems for further exploitation. The perpetrators bombard enterprises with spam emails to capture the attention of employees....
The developers of Cacti, an open-source system for network monitoring and management, have addressed 12 vulnerabilities, including two critical ones leading to arbitrary code execution. Here are the most severe vulnerabilities that have been...
A highly alarming situation is emerging in the world of cybersecurity. A hacker known by the pseudonym “Cvsp” has announced on a cybercrime forum the sale of an RCE exploit for a zero-day vulnerability...
Recently, hackers have increasingly employed DNS tunneling to monitor when victims open phishing emails and click on malicious links, as well as to scan networks for vulnerabilities. DNS tunneling involves encoding data or commands...
Since April of this year, millions of phishing emails have been sent through the Phorpiex botnet as part of a large-scale campaign employing LockBit Black ransomware. This warning comes from the New Jersey Cybersecurity...
On May 14, 2024, Google held its annual Google I/O conference as scheduled. During the event, Google highlighted its latest and most advanced AI technologies and showcased their various applications. Interestingly, Google also introduced...