Cisco warns of critical flaws allowing Nexus switch takeover

Critical Flaws in Cisco Nexus Switches Leave Devices Vulnerable to Takeover Cisco has issued a warning about five critical vulnerabilities in its NX-OS data center network operating system that could allow an attacker to take control of Nexus switches. The issues, discovered during internal security testing, affect the NX-API, Next Generation OAM (NGOAM), and MPLS … Read more

FakeGit malware campaign returns with 17,610 malicious GitHub repos

A massive malware campaign has resurfaced on GitHub, with over 17,610 fake repositories spreading the SmartLoader malware. This is a significant threat that highlights the ongoing challenges in securing online development platforms and the importance of vigilance for developers. The FakeGit campaign, which first came to light in July when researchers at Island published a … Read more

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

A sophisticated cyberattack has compromised several South Korean financial institutions, using a custom-built AI-powered pentesting tool called ARTEX. The attackers leveraged identity exposure to bypass security measures and gain access to sensitive data, highlighting the importance of robust identity management practices in preventing such breaches. The attacks are believed to have begun with the exploitation … Read more

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

A sophisticated malware campaign targeting Ukrainian government personnel has been uncovered, with attackers using a previously unknown vulnerability in Microsoft’s User Account Control (UAC) system. The malicious code, dubbed UAC-0099, employs the ASHVEIN remote access Trojan (RAT) to steal sensitive information and issue commands from compromised systems. The attack is noteworthy not only for its … Read more

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Japan’s cybersecurity landscape has taken a concerning turn, with a significant spike in web data leaks reported across the country. A closer examination of these incidents reveals that mobile API abuse and Metabase attacks are major contributing factors. The alarming trend is not only affecting Japanese businesses but also has far-reaching implications for global online … Read more

Uranium crypto exchange hacker convicted for stealing $53 million

A brazen cyberheist on a decentralized crypto exchange, Uranium Finance, has come to an end with the conviction of 36-year-old Jonathan Spalletta. The Maryland man was found guilty of stealing over $53 million in cryptocurrency after hacking the exchange not once, but twice in April 2021. Spalletta’s modus operandi involved exploiting vulnerabilities in Uranium’s smart … Read more

OAuth grants pile up faster than you can review them. Here’s how to keep up.

OAuth Grants Pile Up Faster Than You Can Review Them. Here’s Why It Matters. Imagine a scenario where thousands of employees, each making quick decisions to connect their work accounts with various apps, create standing trust relationships that can last indefinitely. This is what happens every day in countless organizations, thanks to the OAuth protocol, … Read more

Cisco warns of critical flaws allowing Nexus switch takeover

A Critical Flaw in Nexus Switches Puts Data Centers at Risk Cybersecurity experts are sounding the alarm after Cisco released five critical vulnerability advisories for its NX-OS data center network operating system. The flaws, which allow attackers to run arbitrary code with root privileges on Nexus switches, could have far-reaching consequences if left unpatched. The … Read more

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

South Korean financial firms are reeling after a sophisticated cyberattack used a cutting-edge AI-powered pentesting tool, ARTEX, to steal sensitive data. The attack highlights the evolving threat landscape and the need for organizations to stay ahead of emerging security risks. The attackers exploited vulnerabilities in identity management systems, allowing them to gain privileged access to … Read more

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

Ukrainian Government Personnel Hit by Sophisticated Malware Campaign A recent cybersecurity campaign has targeted Ukrainian government personnel with a highly advanced malware strain, dubbed ASHVEIN RAT. What’s striking about this attack is its unique method of command execution, where malicious code is concealed within HTML files. This clever trick allows the attackers to evade traditional … Read more