Vulnerabilities Critical Apache ActiveMQ Vulnerability Exploited to Deliver Ransomware A recently patched Apache ActiveMQ vulnerability tracked as CVE-2023-46604 is being exploited to deliver ransomware. Eduard KovacsNovember 2, 2023
Malware & Threats Mass Exploitation of ‘Citrix Bleed’ Vulnerability Underway Multiple threat actors are exploiting CVE-2023-4966, aka Citrix Bleed, a critical vulnerability in NetScaler ADC and Gateway. Ionut ArghireNovember 1, 2023
Malware & Threats Russian Hackers Caught Exploiting Roundcube Webmail Zero-Day Russian APT Winter Vivern exploits a zero-day in the Roundcube webmail server in attacks targeting European governments. Ionut ArghireOctober 25, 2023
Malware & Threats Number of Cisco Devices Hacked via Unpatched Vulnerability Increases to 40,000 The number of Cisco devices hacked via the CVE-2023-20198 zero-day has reached 40,000, including many in the US. Eduard KovacsOctober 19, 2023
Vulnerabilities Recent NetScaler Vulnerability Exploited as Zero-Day Since August Mandiant says the recently patched Citrix NetScaler vulnerability CVE-2023-4966 had been exploited as zero-day since August. Ionut ArghireOctober 18, 2023
Vulnerabilities US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability CISA, FBI, and MS-ISAC warn of potential widespread exploitation of CVE-2023-22515, a critical vulnerability in Atlassian Confluence. Ionut ArghireOctober 17, 2023
Vulnerabilities Cisco Devices Hacked via IOS XE Zero-Day Vulnerability Cisco is warning customers that a new IOS XE zero-day vulnerability tracked as CVE-2023-20198 is being exploited to hack devices. Eduard KovacsOctober 17, 2023
Mobile & Wireless Apple Releases iOS 16 Update to Patch Exploited Vulnerability Apple has released iOS 16.7.1 and iPadOS 16.7.1 to patch CVE-2023-42824, a kernel vulnerability that has been exploited in attacks. Eduard KovacsOctober 12, 2023
Vulnerabilities CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability CISA has added five bugs to its Known Exploited Vulnerabilities catalog, including the recent WordPad, Skype, and HTTP/2 zero-days. Ionut ArghireOctober 11, 2023
Mobile & Wireless Android’s October 2023 Security Updates Patch Two Exploited Vulnerabilities The October 2023 security update for Android patches two vulnerabilities exploited in attacks, both likely linked to spyware vendors. Ionut ArghireOctober 3, 2023
Vulnerabilities Companies Address Impact of Exploited Libwebp Vulnerability Companies have addressed the impact of the exploited Libwebp vulnerability CVE-2023-4863 on their products. Eduard KovacsOctober 3, 2023
Vulnerabilities Recently Patched TeamCity Vulnerability Exploited to Hack Servers In-the-wild exploitation of a critical vulnerability in the TeamCity CI/CD server started shortly after a patch was released by developers. Eduard KovacsOctober 2, 2023
Vulnerabilities Cisco Warns of IOS Software Zero-Day Exploitation Attempts Cisco has released patches for vulnerability in the GET VPN feature of IOS and IOS XE software that has been exploited in attacks. Ionut ArghireSeptember 28, 2023
Vulnerabilities Google Rushes to Patch New Zero-Day Exploited by Spyware Vendor Google has rushed to patch a new Chrome zero-day vulnerability, tracked as CVE-2023-5217 and exploited by a spyware vendor. Eduard KovacsSeptember 28, 2023
Mobile & Wireless Apple Patches 3 Zero-Days Likely Exploited by Spyware Vendor to Hack iPhones Apple has patched 3 zero-day vulnerabilities that have likely been exploited by a spyware vendor to hack iPhones. Eduard KovacsSeptember 22, 2023
Vulnerabilities Thousands of Juniper Appliances Vulnerable to New Exploit VulnCheck details a new fileless exploit targeting a recent Junos OS vulnerability that thousands of devices have not been patched against. Ionut ArghireSeptember 19, 2023
Endpoint Security Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products Trend Micro has patched CVE-2023-41179, an Apex One zero-day code execution vulnerability that has been exploited in attacks. Eduard KovacsSeptember 19, 2023
Malware & Threats After Apple and Google, Mozilla Also Patches Zero-Day Exploited for Spyware Delivery After Apple and Google, Mozilla has also patched an image processing-related zero-day vulnerability exploited by spyware. Eduard KovacsSeptember 13, 2023
Vulnerabilities Google Patches Chrome Zero-Day Reported by Apple, Spyware Hunters Google has released a Chrome 116 security update to patch CVE-2023-4863, the fourth Chrome zero-day vulnerability documented in 2023. Ionut ArghireSeptember 12, 2023
Vulnerabilities Recent Juniper Flaws Chained in Attacks Following PoC Exploit Publication Four recent vulnerabilities in the J-Web component of Junos OS have started being chained in malicious attacks after PoC exploit code was published. Ionut ArghireAugust 30, 2023