⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

A string of recent security incidents has highlighted a disturbing trend in cyberattacks, where attackers exploit identity exposure to unlock active attack paths and wreak havoc on unsuspecting organizations. The alarming rate at which this is happening underscores the need for businesses and individuals alike to take immediate action to shore up their defenses. One … Read more

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

**Phantom IT Calls Pose Serious Threat to Executives in Microsoft 365 Data Theft and Extortion Attacks** In a disturbing trend, cyberattackers have started targeting high-ranking executives with fake IT support calls, compromising their sensitive data and extorting them for ransom. This insidious tactic has been observed in attacks on Microsoft 365 users, where attackers exploit … Read more

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

**Critical Vulnerability in Telerik UI Components Exposes Millions to Remote Code Execution** A devastating security flaw has been discovered in the widely-used Telerik UI components, leaving millions of websites and applications vulnerable to remote code execution (RCE). The bug, known as a “padding oracle” vulnerability, allows attackers to chain it with other vulnerabilities to gain … Read more

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

A sophisticated malware campaign is making headlines, as a four-stage VBScript chain has been discovered spreading through ScreenConnect clients. The malicious code exploits vulnerabilities in previously unknown areas of the software, leaving many organizations vulnerable to potential breaches. At its core, the attack relies on the use of ScreenConnect, a popular remote desktop management tool … Read more

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

A new wave of sophisticated cyber attacks is exploiting a critical vulnerability in the way online identities are managed, leaving millions of users vulnerable to active attack paths. The threat, which has been dubbed “Identity Exposure,” leverages cross-domain privilege escalation to bypass traditional security measures and gain access to sensitive systems. At its core, Identity … Read more

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

A New Wave of Sophisticated Attacks Targets Executives in Microsoft 365 Data Theft and Extortion Schemes, Exposing a Chilling Reality of Personal and Corporate Compromise. Microsoft 365 users, particularly high-ranking executives, are being targeted by sophisticated attackers who make fake IT calls to gain access to sensitive data. These cunning scammers pose as IT support … Read more

Mathspace discloses data breach affecting over 1 million people

Over a million people’s personal information exposed in Mathspace data breach A devastating data breach has been disclosed by online maths learning platform Mathspace, affecting over 1 million students, staff, and parents across Australia, New Zealand, the United States, and the UK. The attackers exploited a vulnerability in Metabase, an internal reporting system used by … Read more

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

Cybersecurity firm N-able has issued its fourth hotfix in just five weeks for a critical vulnerability in its popular remote monitoring and management (RMM) platform, N-central. The flaw, which allows attackers to gain unauthenticated access to sensitive data and execute arbitrary code on affected systems, is particularly concerning given the widespread adoption of RMM tools … Read more

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A devastating combination of a padding oracle bug and an unauthenticated remote code execution vulnerability in Telerik UI components has been discovered, leaving numerous organizations vulnerable to serious attacks. The severity of this issue is compounded by the fact that it affects not only authenticated users but also those who are not logged in, making … Read more