As we warned, Horizon3 researchers have uncovered a PoC exploit and presented a technical analysis for the critical RCE vulnerability CVE-2022-47966 in Zoho ManageEngine products.
Cisco has announced fixes for a serious SQL vulnerability in Unified Communications Manager (CM) and Unified Communications Manager Session Management Edition (CM SME).
Mandiant researchers have determined that a recent Fortinet vulnerability was exploited as a 0-day for malware delivery in October 2022, almost two months before the patch release.
The new Hook Banking Trojan for just $5,000 a month opens up the possibility for attackers to steal accounts from more than 450 Internet banking applications and crypto wallets.
The OpenText Enterprise Content Management (ECM) system is subject to a variety of vulnerabilities, including critical RCE without authentication. OpenText Extended ECM is an enterprise CMS platform that implements management and integration with leading enterprise applications such as SAP, Microsoft 365, Salesforce and SAP SuccessFactors.
The Canadian distributor of alcoholic beverages Liquor Control Board of Ontario (LCBO) was attacked by Magecart, which led to the compromise of personal data of users. LCBO is one of the largest sellers of alcoholic beverages in Canada and sells alcoholic beverages throughout the province of Ontario, operating more than 670 stores with a total staff of almost 8000 people.
Apple has released fixes to address numerous serious security vulnerabilities for the flagship iOS and macOS platforms. The most serious of the documented vulnerabilities affect WebKit and can expose iOS and macOS devices to code execution attacks through malicious web content.
Secret documents of the Taiwan National Security Bureau (NSB) can be purchased on breached for $150,000. Taiwan's main intelligence agency is investigating a possible leak, but so far has not confirmed the authenticity of the documents appearing on the darknet.
Tacito Security researchers have released a PoC exploit for a vulnerability called iTLB multihit. The error affects a fairly wide range of Intel processors and is associated with the associative translation buffer (TLB), a specialized CPU cache used to accelerate the translation of virtual memory addresses to physical memory addresses.
In recent years, the use of Cobalt Strike and Metasploit as tools for attacks on various types of systems has become very popular among attackers. However, using these tools, security tools have learned to detect and stop attacks based on the information collected. In order to avoid detection of EDR and various antivirus solutions, hackers had to try other options.
Hackers from TurkHackTeam claimed responsibility for a cyber attack on the website of the Swedish parliament in protest against the burning of the Koran, demanding an apology. Judging by the tweets, hackers are attacking everything in a row: telecom, banks, online medical journal sites and the subway.