Blog
WordPress Ninja Forms Plugin Flaw Lets Hackers Steal Submitted Data
Researchers at Patchstack discovered and disclosed the three vulnerabilities to the plugin's developer, Saturday Drive, on June 22nd, 2023, warning that it affects NinjaForms versions 3.6.25 and older.
Zimbra Faces Critical XSS Vulnerability
A new vulnerability has been found in Zimbra Collaboration. The discovery of the Zimbra XSS vulnerability AKA Cross-Site Scripting (XSS) vulnerability in ZCS version 8.8.15, poses a threat to the confidentiality and integrity of sensitive data. This vulnerability...
After TD Ameritrade, Cl0p Ransomware Group Delists Maximus
Following Maximus’ confirmation of utilizing MOVEit for internal and external file sharing, concerns arose as personal information may have been compromised by a third party. Subsequently, another disclosure came to light when the ransomware group responsible for...
Indirect Instruction Injection in Multi-Modal LLMs
Interesting research: “(Ab)using Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs“: Abstract: We demonstrate how images and sounds can be used for indirect prompt and instruction injection in multi-modal LLMs. An attacker generates an...
Hawaii Community College admits paying ransom to extortionists
After a ransomware attack which saw the personal information of 28,000 individuals stolen by hackers, Hawaii Community College has confirmed that it has paid a ransom.
CISA to Establish Network of Regional Election Advisers for 2024
Announced by Director Jen Easterly on Tuesday, the 10 advisers will support election officials working in their respective areas in an effort to “build even stronger connective tissue between state and local election officials and … CISA.”
CISA to Establish Network of Regional Election Advisers for 2024
Announced by Director Jen Easterly on Tuesday, the 10 advisers will support election officials working in their respective areas in an effort to “build even stronger connective tissue between state and local election officials and … CISA.”
Education Sector has Highest Ransomware Victim Count
A new report by Sophos revealed that 79% of higher and 80% of “lower” education institutions were compromised by ransomware over the past year – up from 64% and 56% in 2021, respectively.
CISA Issues Joint Cybersecurity Alert on Insecure Direct Object Reference Vulnerabilities
One of the most commonly exploited forms of vulnerability in web applications was highlighted in a joint advisory by international cyber defence agencies. The advisory warning was about web application access control abuse witnessed via Insecure Direct Object...
BlueBravo Deploys GraphicalProton Backdoor Against European Diplomatic Entities
The Russian nation-state actor known as BlueBravo has been observed targeting diplomatic entities throughout Eastern Europe with the goal of delivering a new backdoor called GraphicalProton, exemplifying the continuous evolution of the threat. The phishing campaign is...
FREE GUIDE