Juniper Networks has released the first security recommendations in 2023, which cover more than 230 vulnerabilities fixed in the network giant's line of solutions.
Deep Instinct recercers discovered a new company using remote access Trojans (RAT) Strat and Ratty, whose operators use MSI/JAR and CAB/JAR files to avoid detection.
The top-end dual-band gaming router Asus RT-AX82U is subject to three critical vulnerabilities that can be used to bypass authentication, leak information or cause a denial of service (DoS) state.
Critical CVE-2022-44877 with a severity rating of 9.8 out of 10, recently fixed in the Control Web Panel (formerly known as CentOS Web Panel), allowing an attacker to remotely execute code without authentication, is actively exploited in the wild.
In their latest report, Crowdstrike report how Scattered Spider tried to implement BYOVD using an old Intel driver to bypass Microsoft Defender for Endpoint, Palo Alto Networks Cortex XDR and SentinelOne.
Google has announced the release of Chrome 109 in a stable channel with fixes for 17 vulnerabilities, including 14 bugs reported by external researchers.
Group-IB uncovered Dark Pink APT, involved in attacks on government agencies and military facilities in the Asia-Pacific region using special malware to steal information.
At least 29 security vulnerabilities have been fixed by Adobe developers in their corporate product line, releasing the first batch of security fixes for 2023.
ESET announces a new StrongPity campaign, in which APT distributes a fake Shagle application, which is a Trojan version of Telegram for Android with the addition of a backdoor.
The first January ICS fixes came up with a dozen security recommendations from Siemens and Schneider Electric, eliminating a total of 27 vulnerabilities.