Author: Cybernoz

Experts discovered PostgreSQL flaw chained with BeyondTrust zeroday in targeted attacks
14
Feb
2025

Experts discovered PostgreSQL flaw chained with BeyondTrust zeroday in targeted attacks

Experts discovered PostgreSQL flaw chained with BeyondTrust zeroday in targeted attacks Pierluigi Paganini February 14, 2025 Threat actors are exploiting…

New Device Code Phishing Attack Exploit Device Code Authentication To Capture Authentication Tokens
14
Feb
2025

New Device Code Phishing Attack Exploit Device Code Authentication To Capture Authentication Tokens

A sophisticated phishing campaign, identified by Microsoft Threat Intelligence, has been exploiting a technique known as “device code phishing” to…

CISA Publishes 20 Advisories on ICS Security Flaws and Exploits
14
Feb
2025

CISA Publishes 20 Advisories on ICS Security Flaws and Exploits

 The Cybersecurity and Infrastructure Security Agency (CISA) has issued 20 security advisories on February 13, 2025, warning about critical vulnerabilities…

PostgreSQL Terminal Tool Injection Vulnerability Allows Remote Code Execution
14
Feb
2025

PostgreSQL Terminal Tool Injection Vulnerability Allows Remote Code Execution

Researchers have uncovered a high-severity SQL injection vulnerability, CVE-2025-1094, affecting PostgreSQL’s interactive terminal tool, psql.  This flaw was identified during…

Astaroth 2FA Phishing Kit Targets Gmail, Yahoo, Office 365, and Third-Party Logins
14
Feb
2025

Astaroth 2FA Phishing Kit Targets Gmail, Yahoo, Office 365, and Third-Party Logins

A new phishing kit named Astaroth has emerged as a significant threat in the cybersecurity landscape by bypassing two-factor authentication…

Grip Security unveils SSPM solution to strengthen SaaS security posture
14
Feb
2025

Grip Security unveils SSPM solution to strengthen SaaS security posture

Grip Security has unveiled its SaaS Security Posture Management (SSPM) solution, which proactively identifies misconfigurations, enforces best practices and strengthens…

Salt Typhoon Hackers Exploited 1000+ Cisco Devices to Gain Admin Access 
14
Feb
2025

Salt Typhoon Hackers Exploited 1000+ Cisco Devices to Gain Admin Access 

Researchers observed a sophisticated cyber-espionage campaign led by the Chinese state-sponsored group known as “Salt Typhoon,” also referred to as…

AMD Ryzen Flaw Enables Code Execution Through DLL Hijacking
14
Feb
2025

AMD Ryzen Flaw Enables Code Execution Through DLL Hijacking

A security vulnerability has been identified in the AMD Ryzen™ Master Utility, a performance-tuning tool for AMD Ryzen™ processors. This flaw, discovered by a security researcher,…

Valve removed the game PirateFi from the Steam video game platform because contained a malware
14
Feb
2025

Valve removed the game PirateFi from the Steam video game platform because contained a malware

Valve removed the game PirateFi from the Steam video game platform because contained a malware Pierluigi Paganini February 14, 2025…

AMD Ryzen DLL Hijacking Vulnerability Let Attackers Execute Arbitrary Code
14
Feb
2025

AMD Ryzen DLL Hijacking Vulnerability Let Attackers Execute Arbitrary Code

A high-severity security vulnerability, identified as CVE-2024-21966, has been discovered in the AMD Ryzen™ Master Utility, a software tool designed…

Dutch Authorities Dismantle Network of 127 Command-and-Control Servers
14
Feb
2025

Dutch Authorities Dismantle Network of 127 Command-and-Control Servers

Dutch police and the Public Prosecution Service have taken down a network of 127 command-and-control servers. This network was operated…

Apache Fineract SQL Injection Vulnerability Allows Malicious Data Injection
14
Feb
2025

Apache Fineract SQL Injection Vulnerability Allows Malicious Data Injection

The Apache Software Foundation has disclosed a critical SQL injection vulnerability in its widely utilized financial platform, Apache Fineract. The…