How to Safeguard Your Data: Preventing Credential Theft in Large-Scale Phishing Attacks

Clever Phishing Technique Exploits HTTP Headers to Trick Users In the vast ocean of cyber threats, phishing remains a dominant form of attack, with cybercriminals devising new and sophisticated techniques to trick unsuspecting users. Recently, cybersecurity researchers uncovered a crafty phishing campaign that leverages a lesser-known vulnerability in HTTP headers to deceive individuals into divulging…

Read More

Newly Patched Cloud Appliance Vulnerability Under Active Exploitation: Ivanti Alert

Ivanti’s Cloud Service Appliance Vulnerability Exploited in the Wild Ivanti recently disclosed that their Cloud Service Appliance (CSA) has fallen prey to active exploitation due to a newly patched security flaw. This high-severity vulnerability, identified as CVE-2024-8190 with a CVSS score of 7.2, permits remote code execution under specific circumstances. The Vulnerability The vulnerability lies…

Read More

Apple Vision Pro Vulnerability Exposes Virtual Keyboard Inputs to Attackers

The GAZEploit Vulnerability: A Threat to Apple’s Vision Pro Headset Recently, a security loophole known as GAZEploit has surfaced, posing a risk to Apple’s Vision Pro mixed reality headset. This vulnerability, now under the CVE identifier CVE-2024-40865, once exploited, could provide cyber attackers with the means to extract data entered via the headset’s virtual keyboard….

Read More

Breaking: WhatsUp Gold Vulnerability – Critical Exploit Reported Hours After PoC Release

Malicious Actors Exploit Progress Software WhatsUp Gold Security Flaws Recently, there has been a surge in opportunistic cyber attacks leveraging publicly available proof-of-concept (PoC) exploits targeting newly disclosed security vulnerabilities in Progress Software WhatsUp Gold. This activity, which began on August 30, 2024, just five hours after a PoC was made public for CVE-2024-6670 (scoring…

Read More

Urgent Update: GitLab Addresses Critical Vulnerability Allowing Unauthorized Pipeline Job Execution

GitLab Releases Security Updates to Address Critical Vulnerability GitLab, a popular DevOps platform, recently rolled out security updates to tackle 17 vulnerabilities, one of which has been classified as critical. This critical flaw, identified as CVE-2024-6678, has been assigned a CVSS score of 9.9 out of a possible 10.0. The vulnerability allows an attacker to…

Read More

Beware of ‘Ajina.Banker’ – The Latest Android Malware that Skips 2FA Using Telegram

Bank Customers in Central Asia targeted by Emerging Android Malware Bank customers in the Central Asia region have fallen prey to a new strain of Android malware known as Ajina.Banker. This malicious software, discovered by the Singapore-based cybersecurity firm Group-IB in November 2024, aims to steal financial information and intercept two-factor authentication (2FA) messages, posing…

Read More