2025

Juniper enterprise routers backdoored via “magic packet” malware

Juniper enterprise routers backdoored via “magic packet” malware 2025-01-23 at 20:05 By Zeljka Zorz A stealthy attack campaign turned Juniper enterprise-grade routers into entry points to corporate networks via the “J-magic” backdoor, which is loaded into the devices’ memory and spawns a reverse shell when instructed to do so. “Our telemetry indicates the J-magic campaign […]

Juniper enterprise routers backdoored via “magic packet” malware Read More »

SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix

SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix 2025-01-23 at 18:49 By Connor Jones Big organizations and governments are main users of these gateways SonicWall is warning customers of a critical vulnerability that was potentially already exploited as a zero-day.… This article is an excerpt from The Register View Original Source

SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix Read More »

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits 2025-01-23 at 17:33 By An exhaustive evaluation of three firewall models from Palo Alto Networks has uncovered a host of known security flaws impacting the devices’ firmware as well as misconfigured security features. “These weren’t obscure, corner-case vulnerabilities,” security vendor Eclypsium said in

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits Read More »

Beware: Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks

Beware: Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks 2025-01-23 at 17:33 By Cybersecurity researchers are calling attention to a new malware campaign that leverages fake CAPTCHA verification checks to deliver the infamous Lumma information stealer. “The campaign is global, with Netskope Threat Labs tracking victims targeted in Argentina, Colombia, the United States, the

Beware: Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks Read More »

Instagram luring TikTok influencers with $50K cash bonuses — to help them ‘get off the ground’: report

Instagram luring TikTok influencers with $50K cash bonuses — to help them ‘get off the ground’: report 2025-01-23 at 16:49 By Brooke Steinberg Instagram is attempting to reel in TikTok’s creators. This article is an excerpt from Latest Technology News and Product Reviews | New York Post View Original Source

Instagram luring TikTok influencers with $50K cash bonuses — to help them ‘get off the ground’: report Read More »

FortiGate config leaks: Victims’ email addresses published online

FortiGate config leaks: Victims’ email addresses published online 2025-01-23 at 16:49 By Connor Jones Experts warn not to take leaks lightly as years-long compromises could remain undetected Thousands of email addresses included in the Belsen Group’s dump of FortiGate configs last week are now available online, revealing which organizations may have been impacted by the

FortiGate config leaks: Victims’ email addresses published online Read More »

VMware users gripe over 3-year commitment to renew licenses

VMware users gripe over 3-year commitment to renew licenses 2025-01-23 at 16:19 By Dan Robinson Chips and software giant Broadcom says it’s ‘flexible and open’ on licensing terms, but customers disagree VMware users continue to be unhappy with licensing changes since the virtualization giant was acquired by Broadcom, and are now complaining that they are

VMware users gripe over 3-year commitment to renew licenses Read More »

Trustwave SpiderLabs: The Ransomware Trends Confronting the Energy and Utilities Sector

Trustwave SpiderLabs: The Ransomware Trends Confronting the Energy and Utilities Sector 2025-01-23 at 16:18 By Increasing frequency, new threat groups emerging, the rise of ransomware-as-a-service (RaaS) attack model, and third-party attacks are just a few of the dangerous trends Trustwave SpiderLabs details in Energy and Utilities Sector Deep Dive: Ransomware Trends. This article is an excerpt

Trustwave SpiderLabs: The Ransomware Trends Confronting the Energy and Utilities Sector Read More »

Experts Find Shared Codebase Linking Morpheus and HellCat Ransomware Payloads

Experts Find Shared Codebase Linking Morpheus and HellCat Ransomware Payloads 2025-01-23 at 16:18 By An analysis of HellCat and Morpheus ransomware operations has revealed that affiliates associated with the respective cybercrime entities are using identical code for their ransomware payloads. The findings come from SentinelOne, which analyzed artifacts uploaded to the VirusTotal malware scanning platform

Experts Find Shared Codebase Linking Morpheus and HellCat Ransomware Payloads Read More »

SK hynix wobbles on market uncertainty, despite record 2024 earnings

SK hynix wobbles on market uncertainty, despite record 2024 earnings 2025-01-23 at 15:33 By Dan Robinson Shares slide at ‘most profitable’ company in Korea as world worries over geopolitics Market uncertainty and fears around trade protectionism are overshadowing SK hynix’s latest earnings, with its shares sliding despite revenue doubling for the financial year just completed.…

SK hynix wobbles on market uncertainty, despite record 2024 earnings Read More »

CERT-UA Warns of Malicious AnyDesk Requests Under the Pretext of Phony “Security Audits”  

CERT-UA Warns of Malicious AnyDesk Requests Under the Pretext of Phony “Security Audits”   2025-01-23 at 15:33 By Cyble Overview  Government entities and organizations in Ukraine are on high alert after the Computer Emergency Response Team of Ukraine (CERT-UA) uncovered a social engineering campaign targeting unsuspecting users with malicious AnyDesk requests.     The attackers are impersonating

CERT-UA Warns of Malicious AnyDesk Requests Under the Pretext of Phony “Security Audits”   Read More »

Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw

Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw 2025-01-23 at 15:03 By Zeljka Zorz Cisco has released patches for a critical privilege escalation vulnerability in Meeting Management (CVE-2025-20156) and a heap-based buffer overflow flaw (CVE-2025-20128) that, when triggered, could terminate the ClamAV scanning process on endpoints running a Cisco Secure Endpoint

Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw Read More »

Aircraft Collision Avoidance Systems Hit by High-Severity ICS Vulnerability 

Aircraft Collision Avoidance Systems Hit by High-Severity ICS Vulnerability  2025-01-23 at 14:48 By Paul Shread Overview  A pair of vulnerabilities in the Traffic Alert and Collision Avoidance System (TCAS) II for avoiding midair collisions were among 20 vulnerabilities reported by Cyble in its weekly Industrial Control System (ICS) Vulnerability Intelligence Report.  The midair collision system

Aircraft Collision Avoidance Systems Hit by High-Severity ICS Vulnerability  Read More »

Brit competition watchdog takes aim at Google, Apple’s mobile ecosystems

Brit competition watchdog takes aim at Google, Apple’s mobile ecosystems 2025-01-23 at 14:18 By Richard Speed CMA flexes its new Strategic Market Status muscles The UK’s Competition and Markets Authority (CMA) is launching Strategic Market Status (SMS) investigations into both Apple and Google, probing the duo’s control of their respective mobile ecosystems.… This article is

Brit competition watchdog takes aim at Google, Apple’s mobile ecosystems Read More »

Scroll to Top