Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

A Critical Flaw in NetScaler Exposes Gateway and AAA Servers to Authentication Bypass Attacks A recently discovered vulnerability in Citrix’s NetScaler platform is exposing gateway and authentication, authorization, and accounting (AAA) servers to a critical risk of authentication bypass attacks. The flaw, which affects certain versions of NetScaler, can allow attackers to gain unauthorized access … Read more

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

A Critical Vulnerability in Isolated Vms Puts Sandboxed JavaScript on the Loose, Threatening Hosts with Potential RCE Attacks A newly discovered flaw in isolated virtual machines (ivms) is giving attackers a way to bypass security controls and execute arbitrary code on the host system. The vulnerability, known as “isolated-vm”, allows sandboxed JavaScript to escape its … Read more

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

A newly discovered vulnerability, dubbed “Cryptographic Context Injection,” has been found to pose a significant threat to users of the popular chat platform Grok. The attack allows malicious web pages to steal sensitive information from unsuspecting victims, including those who use Grok’s secure messaging features. The vulnerability works by exploiting a flaw in the way … Read more

Why “Shady AI” is Security’s Next Big Governance Problem

Security experts are sounding the alarm about a growing threat that could compromise even the most robust cybersecurity defenses: “Shady AI” – artificially intelligent systems designed to evade detection and exploit vulnerabilities in organizations’ digital infrastructure. A recent analysis of 11 real-world cases has revealed a disturbing trend: identity exposure can unlock active attack paths, … Read more

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

A new type of attack, dubbed a “Zombie Card” exploit, has been discovered that can breathe life back into expired contactless payment cards. This clever technique allows hackers to revive and reuse compromised card data for malicious purposes, putting millions of users at risk. The Zombie Card attack works by exploiting vulnerabilities in the payment … Read more

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

A Critical Zimbra SNMP Flaw Allows Unauthenticated Remote Code Execution, Leaving Thousands of Organizations Exposed Thousands of organizations worldwide are facing a significant security threat after it was discovered that attackers can exploit a critical flaw in the Simple Network Management Protocol (SNMP) component of the popular email server software Zimbra. The vulnerability, which allows … Read more

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

A Critical Flaw in NetScaler Puts Companies with Gateway and AAA Servers at Risk of Authentication Bypass Attacks Cybersecurity experts are sounding the alarm over a critical vulnerability discovered in Citrix’s NetScaler, a popular network delivery controller used by many organizations worldwide. The flaw, which affects certain versions of the product, allows attackers to bypass … Read more

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

A Critical Flaw in Sandboxed JavaScript Allows Escalation of Privileges, Potentially Leading to Remote Code Execution A newly discovered vulnerability in isolated virtual machines (isolated-vm) has left security experts scrambling. The flaw allows sandboxed JavaScript code to escape its confines and gain access to the underlying host system, potentially enabling attackers to execute malicious code … Read more

New Manic Android malware can exfiltrate data through nearby devices

New Android Malware Exfiltrates Data Through Nearby Devices, Targeting European Users A sophisticated Android malware named Manic has been discovered by researchers at ThreatFabric, targeting users in multiple European countries with a novel data exfiltration mechanism that allows it to siphon sensitive information from compromised devices even when they are offline. The malware combines spyware, … Read more

CISA warns of hackers exploiting critical MLflow vulnerability

Cybersecurity experts are sounding the alarm as hackers begin exploiting a critical vulnerability in MLflow, an open-source platform used by thousands of organizations to build and manage artificial intelligence (AI) applications. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that unpatched instances of MLflow are vulnerable to attacks that can allow threat … Read more