Author: Cybernoz

Marvin Attack: 25-year-old RSA Decryption Vulnerability Disclosed
02
Oct
2023

25 Year Old RSA Decryption Vulnerability Disclosed

A new type of vulnerability in the software implementation of PKCS#1 v1.5 padding scheme for RSA key exchange, which was…

APT34 Employs Weaponized Word Documents to Deploy Malware
02
Oct
2023

APT34 Employs Weaponized Word Documents to Deploy Malware

APT34 is a secretive cyberespionage group specializing in Middle East targets, known for gathering sensitive intelligence via spear phishing and…

Patch Tuesday: Critical Flaws in Adobe Commerce Software
02
Oct
2023

Unpatched Exim Vulnerabilities Expose Many Mail Servers to Attacks 

The existence of several unpatched vulnerabilities impacting Exim mail transfer agent (MTA) installations was disclosed last week, more than one…

Malicious HDMI Cables Steals Photos, Videos, and Location Data
02
Oct
2023

Malicious HDMI Cables Steals Photos, Videos, and Location Data

John Bumstead, who works for a company called 404Media that fixes and sells used electronics, found an iPhone-to-HDMI adapter that…

Patch Tuesday: Critical Flaws in Adobe Commerce Software
02
Oct
2023

CISA Kicks Off Cybersecurity Awareness Month With New Program

To celebrate the 20th Cybersecurity Awareness Month, CISA has launched a new program, meant to promote four critical actions that…

OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code
02
Oct
2023

OpenRefine’s Zip Slip Vulnerability Could Let Attackers Execute Malicious Code

Oct 02, 2023THNVulnerability / Cyber Attack A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and…

Snatch Ransomware Group Claims The FDVA Cyber Attack
02
Oct
2023

Cybersecurity Solutions: Need Of The Hour

In today’s hyper-connected digital landscape, the phrase “better safe than sorry” couldn’t be more fitting. Cybersecurity isn’t just a buzzword;…

Recently Patched TeamCity Vulnerability Exploited to Hack Servers
02
Oct
2023

Recently Patched TeamCity Vulnerability Exploited to Hack Servers

In-the-wild exploitation of a critical vulnerability in JetBrains’ TeamCity continuous integration and continuous deployment (CI/CD) server started just days after…

Malicious npm & PyPi Packages Exfiltrate SSH Keys From Server
02
Oct
2023

Malicious npm & PyPi Packages Exfiltrate SSH Keys From Server

JavaScript and Python both have their own package repositories called npm (Node Package Manager) and PyPi (Python Package Index), respectively….

Threat Hunting with MITRE ATT&CK
02
Oct
2023

Threat Hunting with MITRE ATT&CK

Cybercriminal tactics continue to grow in number and advance in ability; in response, many organisations have seen the need to…

02
Oct
2023

Lazarus impersonated Meta recruiter to breach Spanish aerospace firm

Operators of the North Korea-linked Lazarus APT obtained initial access to the network of an aerospace company in Spain last…

Patch Tuesday: Critical Flaws in Adobe Commerce Software
02
Oct
2023

Silverfort Open Sources Lateral Movement Detection Tool

Identity protection provider Silverfort has announced the open source release of a lateral movement detection tool. Called LATMA (Lateral Movement…