JSON Web Token Vulnerability

JSON Web Token Vulnerability

A security flaw with risk severity of high has been found in the popular JsonWebToken open-source JavaScript package. The attacker could perform RCE on a server verifying a maliciously crafted…
Pokeman NFT Games Malvertised

Pokeman NFT Games Malvertised

Threat actors are seen using rogue websites for Pokemon NFT card games to distribute the NetSupport remote access tool to gain control over the devices of unsuspecting victims. The popularity…
BlueBottle Threat Actor Campaign

BlueBottle Threat Actor Campaign

Researchers have discovered a new threat group, actively targeting the financial sector in the African continent. The group called Bluebottle makes extensive use of Living off the Land, dual-use tools,…
Air France KLM discloses a Data Breach

Air France KLM discloses a Data Breach

Air France informed some of its customers that personal information belongs to them was exposed following a breach of their accounts. Clients of Air France, KLM, Transavia, Aircalin, Kenya Airways, and TAROM…
IceID Malware Malvertised Zoom Installer

IceID Malware Malvertised Zoom Installer

Researchers discovered a phishing campaign targeting Zoom users to deliver the IcedID malware. IcedID is a banking trojan that has capabilities like other financial threats like Gozi, Zeus, and Dridex.…