Vulnerabilities Hunk Companion, WP Query Console Vulnerabilities Chained to Hack WordPress Sites Two vulnerabilities in the Hunk Companion and WP Query Console WordPress plugins allow attackers to backdoor websites. Ionut ArghireDecember 12, 2024
Cybercrime Cleo Vulnerability Exploitation Linked to Termite Ransomware Group Exploitation of a vulnerability affecting Cleo file transfer tools has been linked to the new Termite ransomware group. Eduard KovacsDecember 11, 2024
Vulnerabilities Cleo File Transfer Tool Vulnerability Exploited in Wild Against Enterprises CVE-2024-50623, an improperly patched vulnerability affecting Cleo file transfer tools, has been exploited in the wild. Eduard KovacsDecember 10, 2024
Vulnerabilities CISA Warns of Zyxel Firewall Vulnerability Exploited in Attacks A second vulnerability in Zyxel firewalls has been exploited in Helldown ransomware attacks over the past weeks. Ionut ArghireDecember 4, 2024
Vulnerabilities Microsoft Patches Exploited Vulnerability in Partner Network Website Microsoft informed customers that vulnerabilities affecting cloud, AI and other services have been patched, including an exploited flaw. Eduard KovacsNovember 28, 2024
Vulnerabilities ProjectSend Vulnerability Exploited in the Wild VulnCheck warns of widespread exploitation of a year-and-a-half-old ProjectSend vulnerability for which multiple public exploits exist. Ionut ArghireNovember 27, 2024
Nation-State Russian APT Chained Firefox and Windows Zero-Days Against US and European Targets The Russia-linked RomCom APT has been observed chaining two zero-days in Firefox and Windows for backdoor delivery. Ionut ArghireNovember 27, 2024
Vulnerabilities Chinese Hackers Exploiting Critical Vulnerability in Array Networks Gateways CISA warns about attacks exploiting CVE-2023-28461, a critical vulnerability in Array Networks AG and vxAG secure access gateways. Ionut ArghireNovember 26, 2024
Ransomware Recent Zyxel Firewall Vulnerability Exploited in Ransomware Attacks A ransomware group has been observed exploiting a recently patched command injection vulnerability in Zyxel firewalls for initial access. Ionut ArghireNovember 25, 2024
Vulnerabilities 400,000 Systems Potentially Exposed to 2023’s Most Exploited Flaws VulnCheck finds hundreds of thousands of internet-accessible hosts potentially vulnerable to 2023’s top frequently exploited flaws. Ionut ArghireNovember 22, 2024
Malware & Threats 2,000 Palo Alto Firewalls Compromised via New Vulnerabilities The number of internet-exposed Palo Alto firewalls is dropping, but 2,000 have been compromised, according to Shadowserver Foundation. Eduard KovacsNovember 21, 2024
Vulnerabilities Exploitation Attempts Target Citrix Session Recording Vulnerabilities Exploitation attempts seen for two recently patched Citrix Session Recording vulnerabilities tracked as CVE-2024-8068 and CVE-2024-8069. Eduard KovacsNovember 21, 2024
Vulnerabilities CISA Warns of Progress Kemp LoadMaster Vulnerability Exploitation CISA is warning organizations that CVE-2024-1212, a Progress Kemp LoadMaster OS command injection vulnerability, is being exploited in attacks. Eduard KovacsNovember 20, 2024
Vulnerabilities Oracle Patches Exploited Agile PLM Zero-Day Oracle has patched a high-severity information disclosure zero-day in Agile PLM that has been exploited in the wild. Ionut ArghireNovember 20, 2024
Malware & Threats Palo Alto Patches Firewall Zero-Day Exploited in Operation Lunar Peek Palo Alto Networks has released patches and CVEs for the firewall zero-days exploited in what the company calls Operation Lunar Peek. Eduard KovacsNovember 19, 2024
Malware & Threats Discontinued GeoVision Products Targeted in Botnet Attacks via Zero-Day A zero-day vulnerability affecting five discontinued GeoVision product models has been exploited by a botnet. Ionut ArghireNovember 18, 2024
Vulnerabilities Palo Alto Networks Releases IoCs for New Firewall Zero-Day Palo Alto Networks has released IoCs for the attacks exploiting a newly uncovered firewall zero-day vulnerability. Eduard KovacsNovember 18, 2024
Vulnerabilities CISA Warns of Two More Palo Alto Expedition Flaws Exploited in Attacks CISA has added two more Palo Alto Networks Expedition flaws, CVE-2024-9463 and CVE-2024-9465, to its KEV catalog. Eduard KovacsNovember 15, 2024
Vulnerabilities Palo Alto Networks Confirms New Firewall Zero-Day Exploitation Palo Alto Networks has confirmed that a zero-day is being exploited in attacks after investigating claims of a firewall remote code execution flaw. Eduard KovacsNovember 15, 2024
Vulnerabilities Windows Zero-Day Exploited by Russia Triggered With File Drag-and-Drop, Delete Actions The exploit for a new zero-day vulnerability in Windows is executed by deleting files, drag-and-dropping them, or right clicking on them. Ionut ArghireNovember 14, 2024