Automation tools are popular among users on messaging services like Telegram and Discord. Users that engage in cybercrime are among them. Message-sending programmes have…
API
IT Systems Were Compromised, According To Policybazaar, But No Critical Consumer Data Was Disclosed
The company stated in a notification to exchanges that the detected vulnerabilities in Policybazaar’s IT systems have been resolved and a thorough examination of…
Business Networks Were Vulnerable To Misuse Because Of Zyxel Firewall Flaws
The severity of the code execution bug was reduced by the prior patch’s “high uptake.” Following the identification of two security flaws that exposed…
Spreading Of A New QakBot Variant Through HTML Files Attached to Phishing Emails
A phishing email was intercepted by Fortinet’s FortiGuard Labs as part of a phishing campaign that propagated a new QakBot variant. Since 2007, security…
Remote Code Execution is Caused via Prototype Pollution in Blitz.js.
A critical prototype pollution vulnerability in Blitz.js, a JavaScript online application framework, has been patched to prevent remote code execution (RCE) on Node.js servers.…
Android Security: How This New Malware Has Emerged As A Major Threat To SmartPhones
Only appearing a month ago, MaliBot has already established itself as one of the most common malware strains that targets Android users. One of…
Use-After-Free Vulnerability in Google Chrome WebGPU
A recent use-after-free vulnerability in Google Chrome’s WebGPU standard was found by Cisco Talos. Cross-platform web browser Google Chrome is built on the open-source…
The first victim is listed on the extortion website for the new Lilith ransomware
The ‘Lilith’ ransomware campaign has only begun, and it has already placed its first victim on a data leak website designed to facilitate double-extortion…
Using OAuth, A Researcher Reveals How Cyberattacks Might Result in Account Takeovers
A security researcher has discovered that by manipulating the OAuth protocol flow, single-click account hijacking is achievable. A system for managing identities and securing…
Automate the binary vulnerability disclosure with Ghidra and Semgrep
The following tools can be used to automate processes involving vulnerability finding using static analysis methods: A straight forward Ghidra script named Rhabdomancer finds…