A new privilege escalation vulnerability has been discovered in Zscaler Client Connector, combining three different vulnerabilities.
The three vulnerabilities were associated with Reverting password check (CVE-2023-41972), arbitrary code execution (CVE-2023-41973), and Arbitrary File Deletion (CVE-2023-41969).
Though these vulnerabilities are low-level and...
Researchers discovered REF4578, an intrusion set that uses vulnerable drivers to disable established security solutions (EDRs) for crypto mining and deploys a malicious payload known as GHOSTENGINE.
GHOSTENGINE is in charge of locating and running the machine's modules. To download...
Multiple vulnerabilities involving SQL injection have been identified in Ivanti Endpoint Manager.
These vulnerabilities could potentially enable malicious actors to carry out various unauthorized actions, including initiating Denial of Service attacks and executing arbitrary code on affected systems.
One of...
Recent email campaigns distribute DanaBot malware through two document types: those using equation editor exploits and those containing external links, where attackers send emails disguised as job applications with a malicious Word document attached.
The document itself doesn't contain malware...
In the rapidly evolving, complex threat landscape, EDR companies are constantly racing against new vectors.
Recently, Helvio Benedito Dias de Carvalho Junior (aka M4v3r1ck) from Sec4US has developed an innovation called "HookChain." It is an IAT hooking-based technique that utilizes...
Bitdefender GravityZone Update Server (versions 6.36.1, Endpoint Security for Linux 7.0.5.200089, and Endpoint Security for Windows 7.9.9.380) is vulnerable to server-side request forgery (SSRF) due to an incorrect regular expression.
The weakness allows an attacker to send crafted requests to...
COM (Component Object Model) hijacking is a technique in which threat actors exploit the core architecture of Windows by adding a new value on a specific registry key related to the COM object.
This allows the threat actors to...
Endpoint management and security is not one of the top areas of discussion regarding IT security, and this doesn't come as a surprise.
For the better part of the last decade, most enterprise endpoints were safely barricaded within the enterprise...
The zero-trust model to business security is actually proposed by the well-known Market research company, Forrester Research, almost ten years ago, and the fact is that it is one of the most challenging approaches to implement.
Yes, it clearly means...
Microsoft issued a warning about ongoing Dopplepaymer Ransomware attack from unknown threat actors targeting enterprise network-based Windows users.
Microsoft internal investigation found that the ransomware attack initiated by remote operators who are abusing existing Domain Admin credentials to exploit the...