week in security
13
Jan
2025

A week in security (January 6 – January 12)

Last week on Malwarebytes Labs: Last week on ThreatDown: Stay safe! Our business solutions remove all remnants of ransomware and…

Critical Ivanti Vulnerabilities Addressed With Latest Patch
13
Jan
2025

Critical Ivanti Vulnerabilities Addressed With Latest Patch

Ivanti has released patches to address two significant vulnerabilities in its Ivanti Connect Secure, Policy Secure, and ZTA Gateways products….

How Harold Teasdale Automates the Fight Against Insider Threats and Access Control Nightmares
13
Jan
2025

How Harold Teasdale Automates the Fight Against Insider Threats and Access Control Nightmares

Cybersecurity is no longer just about protecting systems from external attackers. In an increasingly digitized world, the greatest risks often…

PoC Exploit Released for Critical macOS Sandbox Vulnerability (CVE-2024-54498)
13
Jan
2025

PoC Exploit Released for Critical macOS Sandbox Vulnerability (CVE-2024-54498)

A proof-of-concept (PoC) exploit has been publicly disclosed for a critical vulnerability impacting macOS systems, identified as CVE-2024-54498. This vulnerability poses…

Microsoft took legal action against crooks who developed a tool to abuse its AI-based services
13
Jan
2025

Microsoft took legal action against crooks who developed a tool to abuse its AI-based services

Microsoft took legal action against crooks who developed a tool to abuse its AI-based services Pierluigi Paganini January 13, 2025…

Hackers Exploiting YouTube to Deliver Malware Bypassing Antivirus Detections
13
Jan
2025

Hackers Exploiting YouTube to Deliver Malware Bypassing Antivirus Detections

Cybercriminals are increasingly leveraging YouTube’s vast platform to distribute malware, bypassing traditional antivirus detections and exploiting users’ trust in the…

IBM Robotic Process Autmation Vulnerability Let Attackers Obtain Sensitive Data
13
Jan
2025

IBM Robotic Process Autmation Vulnerability Let Attackers Obtain Sensitive Data

A newly disclosed security vulnerability in IBM Robotic Process Automation (RPA) has raised concerns about potential data breaches. The vulnerability, tracked as CVE-2024-51456,…

Expired Domains
13
Jan
2025

Expired Domains Allowed Control Over 4,000 Backdoors on Compromised Systems

Jan 13, 2025Ravie LakshmananMalware / Domain Security No less than 4,000 unique web backdoors previously deployed by various threat actors…

Critical macOS Sandbox Vulnerability PoC Exploit Released Online
13
Jan
2025

Critical macOS Sandbox Vulnerability PoC Exploit Released Online

A proof-of-concept exploit was released for a critical vulnerability impacting macOS systems, identified as CVE-2024-54498. Security researcher @wh1te4ever recently revealed…

Hackers Abusing Youtube To Deliver Malware That Steals Browser Data
13
Jan
2025

Hackers Abusing Youtube To Deliver Malware That Steals Browser Data

Malware actors leverage popular platforms like YouTube and social media to distribute fake installers. Reputable file hosting services are abused…

Naveen Goud
13
Jan
2025

Better be aware of this ongoing PayPal Phishing Scam that seems genuine

PayPal, the widely used online payment platform, is currently facing scrutiny after being linked to a “No Phish Phishing” scam…

WordPress Skimmers
13
Jan
2025

WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables

Cybersecurity researchers are warning of a new stealthy credit card skimmer campaign that targets WordPress e-commerce checkout pages by inserting…