Author: Cybernoz

Attackers chained Craft CMS zero-days attacks in the wild
28
Apr
2025

Attackers chained Craft CMS zero-days attacks in the wild

Attackers chained Craft CMS zero-days attacks in the wild Pierluigi Paganini April 28, 2025 Orange Cyberdefense’s CSIRT reported that threat…

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code
28
Apr
2025

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code

A severe zero-day vulnerability has been uncovered in multiple Viasat satellite modem models, including the RM4100, RM4200, EM4100, RM5110, RM5111,…

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution
28
Apr
2025

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution

A severe vulnerability (CVE-2025-23016) in the FastCGI library-a core component of lightweight web server communication been disclosed, threatening countless embedded…

WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors
28
Apr
2025

WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors

Apr 28, 2025Ravie LakshmananWebsite Security / Malware Cybersecurity researchers are warning about a large-scale phishing campaign targeting WooCommerce users with…

A Key Weapon in the Ongoing War Between Hackers and Defenders
28
Apr
2025

A Key Weapon in the Ongoing War Between Hackers and Defenders

Obfuscation stands as a powerful weapon for attackers seeking to shield their malicious code from defenders. This technique, which deliberately…

week in security
28
Apr
2025

A week in security (April 21 – April 27)

Last week on Malwarebytes Labs: Last week on ThreatDown: Stay safe! Our business solutions remove all remnants of ransomware and…

Hackers Exploit Critical Craft CMS Flaws
28
Apr
2025

Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised

Apr 28, 2025Ravie LakshmananWeb Application Security / Vulnerability Threat actors have been observed exploiting two newly disclosed critical security flaws…

FTC
28
Apr
2025

FTC Announces New, Stricter Children’s Privacy Rule

After years of consideration and public comment, the Federal Trade Commission (FTC) has officially updated its Children’s Online Privacy Protection…

React Router Vulnerabilities Allow Attackers to Spoof Content and Alter Values
28
Apr
2025

React Router Vulnerabilities Allow Attackers to Spoof Content and Alter Values

Why Application Security is Non-Negotiable The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application…

Iluka Resources picks control system for rare earths refinery
28
Apr
2025

Iluka Resources picks control system for rare earths refinery

Iluka Resources will implement a Honeywell-made distributed control system at its Eneabba rare earths refinery, which is scheduled for commissioning in…

Securing Agentic AI and Beyond — API Security
28
Apr
2025

Securing Agentic AI and Beyond — API Security

We recently released The Rise of Agentic AI, our API ThreatStats report for Q1 2025, finding that evolving API threats are…

New iOS Critical Vulnerability That Could Brick iPhones With a Single Line of Code
28
Apr
2025

New iOS Critical Vulnerability That Could Brick iPhones With a Single Line of Code

A critical vulnerability in iOS could allow malicious applications to disable iPhones with just a single line of code permanently….