Frank Crast

security, alarm, monitor-5043368.jpg

Deep Panda APT group launches new attacks against Log4Shell vulnerability to install Fire Chili rootkits

In the past month, researchers from FortiLabs have detected a new cyber campaign involving Chinese Advanced Persistent Threat (APT) group Deep Panda that has exploited the Log4Shell (log4j) vulnerability CVE-2021-44228 on vulnerable VMware Horizon servers to install digitally signed Fire Chili rootkits.

Deep Panda APT group launches new attacks against Log4Shell vulnerability to install Fire Chili rootkits Read More »

CISA adds 7 vulnerabilities to Known Exploited Vulnerabilities Catalog (to include Trend Micro, Sophos, Dell, QNAP) 

The Cybersecurity and Infrastructure Security Agency (CISA) has added 7 vulnerabilities to its Known Exploited Vulnerabilities Catalog. Recent additions include vulnerabilities affecting Trend Micro, Sophos, Windows, QNAP, Dell, and Dasan products.

CISA adds 7 vulnerabilities to Known Exploited Vulnerabilities Catalog (to include Trend Micro, Sophos, Dell, QNAP)  Read More »

binary, code, binary code-4791836.jpg

Apple fixes zero-day vulnerabilities in iOS 15.4.1 and macOS Monterey 12.3.1 (with active exploits in the wild)

Apple has released security updates for Apple iOS 15.4.1, iPadOS 15.4.1 and macOS Monterey 12.3.1 products. Apple is aware of known exploits in the wild for a zero-day vulnerabilities CVE-2022-22675 and CVE-2022-22674.

Apple fixes zero-day vulnerabilities in iOS 15.4.1 and macOS Monterey 12.3.1 (with active exploits in the wild) Read More »

Google releases Chrome 100 security update (100.0.4896.60) with fixes for 9 High risk vulnerabilities

Google has released Chrome 100.0.4896.60 for Windows, Mac and Linux with fixes for multiple High risk vulnerabilities. In addition, Google also issued security updates for Chrome for iOS, Chrome for Android and Chrome OS.

Google releases Chrome 100 security update (100.0.4896.60) with fixes for 9 High risk vulnerabilities Read More »

Google releases Chrome 99 security update with fix for zero-day vulnerability (CVE-2022-1096) exploited in the wild

Google has released Chrome 99.0.4844.84 for Windows, Mac and Linux with fixes for multiple vulnerabilities, to include one zero-day (CVE-2022-1096) exploited in the wild.

Google releases Chrome 99 security update with fix for zero-day vulnerability (CVE-2022-1096) exploited in the wild Read More »

CISA adds 66 vulnerabilities to Known Exploited Vulnerabilities Catalog (to include WatchGuard and Mitel)

The Cybersecurity and Infrastructure Security Agency (CISA) has added 66 vulnerabilities to its Known Exploited Vulnerabilities Catalog. Recent additions include WatchGuard, Mitel, Windows and many other product vulnerabilities.

CISA adds 66 vulnerabilities to Known Exploited Vulnerabilities Catalog (to include WatchGuard and Mitel) Read More »

Okta investigating reports of data breach by Lapsus$ ransomware cybercriminal group (updated)

Identity and authentication services firm Okta is investigating reports that the firm has been breached by the Lapsus$ ransomware cybercriminal group.

Okta investigating reports of data breach by Lapsus$ ransomware cybercriminal group (updated) Read More »