Aruba Clear pass RCE bypassed

A critical vulnerability has been patched in Aruba ClearPass Policy Manager that exposes host systems to remote exploitation. The flaw is classed as an unauthenticated remote code execution (RCE) vulnerability…

Hijacking Firefox

The SSDP engine of the victims' Firefox browsers can be tricked into triggering an Android intent by simply replacing location of the XML file in the response packets with a…

Maze infects via VM 🐾

The gang responsible for the Maze ransomware family conducted an attack in which they distributed their malware payload inside of a virtual machine (VM). The attackers packaged the ransomware payload…

Ngrok Abused

Cybercriminals have been using ngrok—a cross-platform application to expose local development servers to the internet, for malicious purposes for years now. An organization was targeted by a keylogger, where malicious…

BLESA .. Bluetooth Disguised

The improper BLE reconnection procedure has made billions of Android and iOS devices vulnerable to the new attack dubbed Bluetooth Low Energy Spoofing Attack (BLESA). Two critical security flaws in…

Crowdstrike joins hand with ServiceNow for IR

CrowdStrike has today announced it has joined the ServiceNow® Service Graph Connector Program, a new designation within the Technology Partner Program. Users can now integrate device data from the CrowdStrike…

Zoom 2FA goes for all

Zoom has announced that it has added two-factor authentication (2FA) support to all user accounts to make it simpler to secure them against security breaches and identity theft. With 2FA, Zoom users…