Alerts
Vulnerability disclosures, active campaigns and security notices worth your attention.
- Pixnapping: When Your Screen Spies on YouYou didn’t click a malicious link. You didn’t download a shady app. You didn’t even give away your password. And yet your crypto wallet seed phrase, your…
- Critical WordPress Anti-Spam Plugin Flaws Expose 200,000+ Sites to Remote AttacksTwo critical security flaws impacting the Spam protection, Anti-Spam, and FireWall plugin WordPress could allow an unauthenticated attacker to install and…
- New Qilin ransomware encryptor features stronger encryption, evasionA new Rust-based version of the Qilin (Agenda) ransomware strain, dubbed ‘Qilin.B,’ has been spotted in attacks, featuring stronger encryption, better…
- Free Sniper Dz Phishing Tools Fuel 140,000+ Cyber Attacks Targeting User CredentialsMore than 140,000 phishing websites have been found linked to a phishing-as-a-service (PhaaS) platform named Sniper Dz over the past year, indicating that…
- Hackers deploy AI-written malware in targeted attacksSuspected cases AI-created malware have been spotted in real attacks. Earlier this year, cybersecurity companyProofpoint discovereda malicious PowerShell…
- Patch Issued for Critical VMware vCenter Flaw Allowing Remote Code ExecutionThe vulnerability, tracked as CVE-2024-38812 (CVSS score: 9.8), has been described as a heap-overflow vulnerability in theDCE/RPC protocol.
- SonicWall SSLVPN access control flaw is now exploited in attacksCVE-2024-40766 is a critical (CVSS v3 score: 9.3) access control flaw impacting SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices.
- Cisco Fixes Two Critical Flaws in Smart Licensing Utility to Prevent Remote AttacksThe flaws, which were discovered during internal security testing, also do not affect Smart Software Manager On-Prem and Smart Software Manager Satellite…
- Malware exploits 5-year-old zero-day to infect end-of-life IP camerasThe flaw, discovered by Akamai’s Aline Eliovich, is tracked as CVE-2024-7029 and is a high-severity (CVSS v4 score: 8.7) issue in the “brightness” function…
- Critical Flaw in WordPress LiteSpeed Cache Plugin Allows Hackers Admin AccessCybersecurity researchers have disclosed a critical security flaw in theLiteSpeed Cacheplugin for WordPress that could permit unauthenticated users to gain…
- Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch nowMicrosoft warned customers this Tuesday to patch a critical TCP/IP remote code execution (RCE) vulnerability with an increased likelihood of exploitation…
- FreeBSD Releases Urgent Patch for High-Severity OpenSSH VulnerabilityThe vulnerability, tracked asCVE-2024-7589, carries a CVSS score of 7.4 out of a maximum of 10.0, indicating high severity.
- Google fixes Android kernel zero-day exploited in targeted attacksThe zero-day, tracked asCVE-2024-36971, is a use after free (UAF) weakness in the Linux kernel’s network route management. It requires System execution…
- WhatsApp for Windows lets Python, PHP scripts execute with no warningA security issue in the latest version of WhatsApp for Windows allows sending Python and PHP attachments that are executed without any warning when the…
- Stargazer Goblin’ Creates 3,000 Fake GitHub Accounts for Malware SpreadA threat actor known as Stargazer Goblin has set up a network of inauthentic GitHub accounts to fuel a Distribution-as-a-Service (DaaS) that propagates a…
Stay ahead
Know whether an alert affects you.
We can assess your exposure to a disclosed vulnerability and tell you what actually needs patching first.