Video Call Exploit Chains Two Flaws in Unisoc Modems

Security researchers have uncovered a new vulnerability in Unisoc modem firmware that, when combined with an existing flaw, allows an attacker to take control of an Android device by exploiting its cellular connectivity. This attack chain is particularly insidious because it requires only that the victim answer a video call on their affected phone. The … Read more

Windows Server 2022 reaches end of mainstream support in 60 days

As we approach the end of mainstream support for Windows Server 2022, IT administrators are facing a crucial decision: upgrade to the latest version or risk exposure to security vulnerabilities. In exactly 60 days, on October 13th, Microsoft will stop providing mainstream support updates for this popular server operating system. This shift marks a significant … Read more

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

A Critical Vulnerability in GitLab’s GraphQL API Exposes Public Projects to Unauthenticated Attacks GitLab, a popular software development platform, has disclosed a critical vulnerability in its GraphQL API that could allow unauthenticated attackers to delete public projects. The flaw, discovered by security researchers, affects all versions of GitLab up to the latest patch release and … Read more

Hacker claims 3.6 million Azure account records stolen from major companies

A massive cache of sensitive employee data has been put up for sale on the dark web by a threat actor claiming to have stolen 3.6 million records from major companies that use Microsoft Azure infrastructure. The attacker, known as “TheHatman,” claims to have accessed these records using compromised credentials, exploiting vulnerabilities in Azure’s security. … Read more

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

A sophisticated cyber threat actor has been using a custom-built command-and-control (C2) framework, dubbed Cavern C2, to evade detection and blend into legitimate network traffic. The framework’s unique approach involves leveraging DNS queries and Google Apps Script to maintain a low profile, making it particularly challenging for security teams to detect. The Cavern C2 framework … Read more

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A Critical WordPress Flaw Exposes Sites to Remote Code Execution Attacks A severe vulnerability in Forminator, a popular WordPress plugin used by millions of websites, has been disclosed. The flaw allows attackers to execute arbitrary code on affected sites without authentication, potentially leading to data breaches and complete website takeover. This critical weakness is particularly … Read more

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

A critical vulnerability in GitHub Actions has been discovered, allowing attackers to inject malicious commands on vulnerable repositories. The flaw, found by a security researcher, lets hackers create specially crafted issues that can exploit a weakness in the way GitHub processes user input. This vulnerability affects all users of GitHub’s issue-tracking feature and poses a … Read more

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Critical GitLab GraphQL Flaw Exposes Public Projects to Deletion by Unauthenticated Attackers A serious vulnerability in the GitLab platform’s GraphQL API has been discovered, allowing unauthenticated attackers to delete public projects. The flaw affects all GitLab instances that have the GraphQL feature enabled, making it a widespread issue that requires immediate attention from users and … Read more

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center Suffers Data Breach Exposing Customer Information and Canceling Orders In a concerning development, Pokémon Center has announced that it has suffered a data breach after hackers targeted its third-party logistics provider, CEVA Logistics. The incident has exposed customer personal and order information for customers in the United Kingdom and Germany, prompting the company … Read more