Blog
Multiple Flaws Found in Ninja Forms Plugin Leave 800,000 Sites Vulnerable
Multiple security vulnerabilities have been disclosed in the Ninja Forms plugin for WordPress that could be exploited by threat actors to escalate privileges and steal sensitive data. The flaws, tracked as CVE-2023-37979, CVE-2023-38386, and CVE-2023-38393, impact...
Hackers Deploy “SUBMARINE” Backdoor in Barracuda Email Security Gateway Attacks
"SUBMARINE comprises multiple artifacts — including a SQL trigger, shell scripts, and a loaded library for a Linux daemon — that together enable execution with root privileges, persistence, command and control, and cleanup," the agency said.
Hackers Deploy “SUBMARINE” Backdoor in Barracuda Email Security Gateway Attacks
"SUBMARINE comprises multiple artifacts — including a SQL trigger, shell scripts, and a loaded library for a Linux daemon — that together enable execution with root privileges, persistence, command and control, and cleanup," the agency said.
What Google’s Web Environment Integrity Proposal Means for Future of Open Web
A recent Google proposal of an unexpected web standard – DRM – has raised the eyebrows of the user community. Termed the “Google Web Environment Integrity API,” this proposal has sparked heated debates within the online community. Authored by four Google team members,...
Forged Certificates Using Whisker Leveraged to Gain Unauthorized Access
By exploiting anomalies in certificate-based TGT (Ticket Granting Ticket) requests, cyber attackers are able to gain unauthorized access and potentially elevate their privileges within the targeted system. Forged certificates for unauthorized access Forged...
Surging Threat: Education Sector Ransomware Attacks Skyrocket in 2023
Ransomware attacks have become a persistent threat, with their numbers steadily rising over the years. Among the sectors significantly affected by these attacks in 2023, the education industry stands out as a prominent target. A sectoral study by Sophos unearthed...
Is backdoor access oppressive? – Week in security with Tony Anscombe
Bills granting access to end-to-end encrypted systems, opportunity for cybercriminals, abuse by authority, human rights, and tech companies leaving the UK?
New Android Malware CherryBlos Utilizing OCR to Steal Sensitive Data
A new Android malware strain called CherryBlos has been observed making use of optical character recognition (OCR) techniques to gather sensitive data stored in pictures. CherryBlos, per Trend Micro, is distributed via bogus posts on social media platforms and comes...
Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins
The vulnerability, tracked as CVE-2023-24489 (CVSS score of 9.1), was the result of errors leading to unauthenticated file upload, which could then be exploited to obtain RCE, says security firm Assetnote, which identified and reported the bug.
Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins
The vulnerability, tracked as CVE-2023-24489 (CVSS score of 9.1), was the result of errors leading to unauthenticated file upload, which could then be exploited to obtain RCE, says security firm Assetnote, which identified and reported the bug.
FREE GUIDE