Frank Crast

CISA adds 1 Zimbra and 3 Microsoft vulnerabilities to Known Exploited Vulnerabilities Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added one Zimbra and three Microsoft vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence that cyber criminals are actively exploiting the vulnerabilities.

CISA adds 1 Zimbra and 3 Microsoft vulnerabilities to Known Exploited Vulnerabilities Catalog Read More »

Sandworm threat actors using new malware Cyclops Blink to target SOHO devices

Sandworm threat actors, also known as Voodoo Bear, are now using a new malware dubbed Cyclops Blink, a replacement for VPNFilter malware previously exposed in 2018, to target small office/home office (SOHO) routers and network attached storage (NAS) devices.

Sandworm threat actors using new malware Cyclops Blink to target SOHO devices Read More »

CISA adds 2 Zabbix vulnerabilities to Known Exploited Vulnerabilities Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added two Zabbix vulnerabilities (CVE-2022-23131, CVE-2022-23134) to its Known Exploited Vulnerabilities Catalog based on evidence that cyber criminals are actively exploiting the vulnerabilities.

CISA adds 2 Zabbix vulnerabilities to Known Exploited Vulnerabilities Catalog Read More »

Severe vulnerability found in WordPress plugin backup utility UpdraftPlus

A security researcher has discovered a severe vulnerability in WordPress plugin backup utility UpdraftPlus that could allow an attacker to potentially steal sensitive information from backups.

Severe vulnerability found in WordPress plugin backup utility UpdraftPlus Read More »

BlackByte Ransomware compromised multiple entities in US critical infrastructure sectors

The Federal Bureau of Investigation (FBI) and the U.S. Secret Service (USSS) issued a joint Cybersecurity Advisory warning of BlackByte ransomware compromising multiple entities in US critical infrastructure sectors.

BlackByte Ransomware compromised multiple entities in US critical infrastructure sectors Read More »

CISA adds 9 vulnerabilities to Known Exploited Vulnerabilities Catalog (to include new Adobe and Chrome zero-days)

The Cybersecurity and Infrastructure Security Agency (CISA) has added 9 vulnerabilities to its Known Exploited Vulnerabilities Catalog. The issues include recently patched Adobe and Chrome zero-days.

CISA adds 9 vulnerabilities to Known Exploited Vulnerabilities Catalog (to include new Adobe and Chrome zero-days) Read More »

Google releases Chrome 98 security update with fix for zero-day vulnerability (CVE-2022-0609) exploited in the wild

Google has released Chrome 98.0.4758.102 for Windows, Mac and Linux with fixes for multiple vulnerabilities, to include one zero-day (CVE-2022-0609) exploited in the wild.

Google releases Chrome 98 security update with fix for zero-day vulnerability (CVE-2022-0609) exploited in the wild Read More »