Hackers Using AV/EDR Tool "EDRSandBlast" To Bypass Endpoints
04
Nov
2024

Hackers Using AV/EDR Tool “EDRSandBlast” To Bypass Endpoints

AV, anti-malware, and EDR are tools that are primarily used to detect and prevent cyber-attacks. While the AV/EDR bypass tools…

Sophisticated Phishing Attack Targeting Ukraine Military Sectors
04
Nov
2024

Sophisticated Phishing Attack Targeting Ukraine Military Sectors

The Ukrainian Cyber Emergency Response Team discovered a targeted phishing campaign launched by UAC-0215 against critical Ukrainian infrastructure, including government…

Ollama AI Framework
04
Nov
2024

Critical Flaws in Ollama AI Framework Could Enable DoS, Model Theft, and Poisoning

Nov 04, 2024Ravie LakshmananVulnerability / Cyber Threat Cybersecurity researchers have disclosed six security flaws in the Ollama artificial intelligence (AI)…

Critical QNAP Zero-day Flaw in QuRouter Patched, Update Now!
04
Nov
2024

Critical QNAP Zero-day Flaw in QuRouter Patched, Update Now!

QNAP Systems, Inc., a leading provider of network-attached storage (NAS) and networking solutions, has released a critical security update for…

Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files
04
Nov
2024

Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files

Researchers warn of ongoing spear-phishing attacks by Russian threat actor Midnight Blizzard targeting individuals in various sectors. The attacks involve…

Scammers Use DocuSign API to Evade Spam Filters with Phishing Invoices
04
Nov
2024

Scammers Use DocuSign API to Evade Spam Filters with Phishing Invoices

Scammers are exploiting DocuSign’s APIs to send realistic fake invoices, primarily targeting security software like Norton. This phishing technique bypasses…

A Call For Cybersecurity Awareness Month All Year Round
04
Nov
2024

A Call For Cybersecurity Awareness Month All Year Round

On the last day of Cybersecurity Awareness Month (CAM), Oct. 31, Cybersecurity Ventures released “Hackerpocalypse: The Human Risk”, on its Cybercrime Magazine…

Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443)
04
Nov
2024

Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443)

Synology has released fixes for an unauthenticated “zero-click” remote code execution flaw (CVE-2024-10443, aka RISK:STATION) affecting its popular DiskStation and…

TechUK calls for government support to help UK datacentre market reach growth potential
04
Nov
2024

TechUK calls for government support to help UK datacentre market reach growth potential

The datacentre sector could become one of the fastest-growing industries in the UK, but doing so will require greater collaboration…

MediaTek Smartphone Chipsets Vulnerabilities Let Attackers Escalate Privileges
04
Nov
2024

MediaTek Smartphone Chipsets Vulnerabilities Let Attackers Escalate Privileges

Recent security bulletins have disclosed high-severity vulnerabilities in MediaTek smartphone chipsets, which could enable attackers to escalate privileges and gain…

Evasive Panda Attacking Cloud Services To Steal Data Using New Toolkit
04
Nov
2024

Evasive Panda Attacking Cloud Services To Steal Data Using New Toolkit

The Evasive Panda group deployed a new C# framework named CloudScout to target a Taiwanese government entity in early 2023,…

Monitoring Distributed Microservices
04
Nov
2024

Monitoring Distributed Microservices

As data and usage grow, apps adopt distributed microservices with load balancers for scalability. Monitoring error rates, resource use, and…