Friday, August 28, 2026
Follow on LinkedIn

Endpoint Security

Zscaler Client Connector Zero-interaction Privilege Escalation Vulnerability

A new privilege escalation vulnerability has been discovered in Zscaler Client Connector, combining three different vulnerabilities. The three vulnerabilities were associated with Reverting password check (CVE-2023-41972), arbitrary code execution (CVE-2023-41973), and Arbitrary File Deletion (CVE-2023-41969). Though these vulnerabilities are low-level and...

GHOSTENGINE Malware Exploits Vulnerable drivers To Terminate EDR Agents

Researchers discovered REF4578, an intrusion set that uses vulnerable drivers to disable established security solutions (EDRs) for crypto mining and deploys a malicious payload known as GHOSTENGINE. GHOSTENGINE is in charge of locating and running the machine's modules. To download...

Ivanti Endpoint Manager SQL Injection Flaw Let Attackers Execute Arbitrary Code

Multiple vulnerabilities involving SQL injection have been identified in Ivanti Endpoint Manager. These vulnerabilities could potentially enable malicious actors to carry out various unauthorized actions, including initiating Denial of Service attacks and executing arbitrary code on affected systems. One of...

Hackers Weaponize Word Files To Deliver DanaBot Malware

Recent email campaigns distribute DanaBot malware through two document types: those using equation editor exploits and those containing external links, where attackers send emails disguised as job applications with a malicious Word document attached.  The document itself doesn't contain malware...

HookChain – A New Sophisticated Technique Evades EDR Detection

In the rapidly evolving, complex threat landscape, EDR companies are constantly racing against new vectors. Recently, Helvio Benedito Dias de Carvalho Junior (aka M4v3r1ck) from Sec4US has developed an innovation called "HookChain." It is an IAT hooking-based technique that utilizes...

Critical Bitdefender Vulnerabilities Let Attackers Gain Control Over System

Bitdefender GravityZone Update Server (versions 6.36.1, Endpoint Security for Linux 7.0.5.200089, and Endpoint Security for Windows 7.9.9.380) is vulnerable to server-side request forgery (SSRF) due to an incorrect regular expression.  The weakness allows an attacker to send crafted requests to...

Malware Families Adapting To COM Hijacking Technique For Persistence

COM (Component Object Model) hijacking is a technique in which threat actors exploit the core architecture of Windows by adding a new value on a specific registry key related to the COM object. This allows the threat actors to...

Endpoint Management And Security : Key To Handling And Securing Future IT Operations

Endpoint management and security is not one of the top areas of discussion regarding IT security, and this doesn't come as a surprise. For the better part of the last decade, most enterprise endpoints were safely barricaded within the enterprise...

Zero Trust – The Best Model For Strengthening Security in The Enterprise Networks – A 5-Step Guide

The zero-trust model to business security is actually proposed by the well-known Market research company, Forrester Research, almost ten years ago, and the fact is that it is one of the most challenging approaches to implement. Yes, it clearly means...

Beware!! Microsoft Warns Dopplepaymer Ransomware Attack On Windows Users in Enterprise Network

Microsoft issued a warning about ongoing Dopplepaymer Ransomware attack from unknown threat actors targeting enterprise network-based Windows users. Microsoft internal investigation found that the ransomware attack initiated by remote operators who are abusing existing Domain Admin credentials to exploit the...

Latest News

Latest News