The bugs could be exploited to bypass security controls, access restricted services, and crash firewalls.
Hi, what are you looking for?
The bugs could be exploited to bypass security controls, access restricted services, and crash firewalls.
The Mini Shai-Hulud attack introduced a preinstall hook to fetch and execute a Bun binary and bypass security monitoring.
The authentication bypass flaw allows attackers to gain administrative access to vulnerable servers.
Affecting the kernel’s authencesn cryptographic template, the vulnerability was introduced in 2017 and impacts all distributions.
The vulnerability allows attackers to read data from a LiteLLM proxy’s database and potentially modify it.
The hackers exfiltrated the data from Checkmarx’s GitHub environment on March 30, a week after publishing malicious code.
US service members received WhatsApp messages claiming they would be targeted with drones and missiles.
The browser refreshes resolve critical and high-severity vulnerabilities that could lead to arbitrary code execution.
A member of Silk Typhoon, Xu Zewei is accused of launching cyberattacks against universities in the US.
Over 70 cloned Open VSX extensions are likely sleeper extensions designed to distribute malware.
A fake RPC server can be used to listen for RPC requests and impersonate the target service to elevate privileges to System.
The threat detection startup will invest in accelerating its engineering and go-to-market efforts.
The initial vulnerability was exploited by Russia-linked APT28 in attacks against Ukraine and EU countries.
A code reuse issue enabled comma characters in certificate principals to be interpreted as list separators.
The threat actor infected victims with the Snow malware family – Snowbelt, Snowglaze, and Snowbasin – for persistent access.
A race condition in PackageKit allows unprivileged users to escalate privileges when installing packages.
Dubbed GopherWhisper, the group relies on multiple Go-based backdoors alongside custom loaders and injectors.
It targeted high-precision calculation software to tamper with results and packed a self-propagation mechanism.
The malware provides remote access and control of infected devices and maintains post-patching persistence.
Tied to a fresh Checkmarx supply chain attack claimed by TeamPCP, the incident references the Shai-Hulud worm.