Cyber Security News

SonicWall Releases Urgent Update to Remove Rootkit Malware ‘OVERSTEP’ from SMA Devices

SonicWall has issued an urgent firmware update, version 10.2.2.2-92sv, for its Secure Mobile Access (SMA) 100 series appliances to detect…

17 hours ago

Threat Actors with Fake Job Lures Attacking Job Seekers to Deploy Advanced Malware

In recent months, a sophisticated campaign has emerged in which state-linked threat actors are leveraging fake job offers to ensnare…

17 hours ago

U.S. Secret Service Dismantles 300 SIM Servers and 100,000 SIM Cards Disabling Cell Phone Towers

The U.S. Secret Service has dismantled a massive, sophisticated network of electronic devices in the New York tristate area, thwarting…

17 hours ago

SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE

SolarWinds has released an urgent security advisory for a critical vulnerability in its Web Help Desk software that could allow…

18 hours ago

Hackers Exploits IMDS Service to Gain Initial Access to a Cloud Environment

Threat actors were manipulating the Instance Metadata Service (IMDS), a core component designed to securely furnish compute instances with temporary…

19 hours ago

GitHub Enhances NPM’s Security with Strict Authentication, Granular Tokens, and  Trusted Publishing

Recent High-profile supply‐chain attacks have exposed critical weaknesses in package registry security, prompting GitHub to roll out a suite of…

20 hours ago

EV Charging Provider Confirm Data Breach – Customers Personal Data Exposed

Digital Charging Solutions GmbH (DCS), a leading provider of white-label charging services for automotive OEMs and fleet operators, has confirmed…

20 hours ago

Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content

A sophisticated cyber campaign, dubbed "Operation Rewrite," is actively hijacking Microsoft Internet Information Services (IIS) web servers to serve malicious…

20 hours ago

Hackers Abusing GitHub Notifications to Deliver Phishing Emails

In recent weeks, security researchers have uncovered an elaborate phishing campaign that leverages legitimate GitHub notification mechanisms to deliver malicious…

21 hours ago

Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands

A critical security flaw in Libraesva ESG email security gateways has been identified and patched, allowing threat actors to execute…

23 hours ago