The Kimsuky Advanced Persistent Threat (APT) group, a cyber-espionage entity linked to North Korea, has recently intensified its operations by utilizing heavily obfuscated PowerShell scripts […]
Day: May 21, 2025
Hazy Hawk Exploits DNS Misconfigurations to Hijack Subdomains and Distribute Malware
Security researchers have uncovered a sophisticated cyber threat actor, dubbed Hazy Hawk, actively exploiting DNS misconfigurations to hijack subdomains of prominent organizations worldwide. Since at […]
Critical Vulnerabilities in Foscam X5 IP Cameras Expose Users to Remote Code Execution
Recent security analyses have uncovered multiple critical vulnerabilities in Foscam X5 IP cameras, allowing remote attackers to execute arbitrary code without authentication. These flaws, identified […]
Palo Alto GlobalProtect Vulnerability Enables Malicious Code Execution – PoC Released
Palo Alto Networks has disclosed a reflected cross-site scripting (XSS) vulnerability, identified as CVE-2025-0133, affecting the GlobalProtect gateway and portal features of its PAN-OS software. […]
Hackers Exploit AI Tool Popularity to Launch Sophisticated Malware Campaign
In early 2025, cybersecurity researchers uncovered a sophisticated cyberattack campaign where threat actors created counterfeit versions of the popular AI image generation platform, Kling AI, […]
Critical Vulnerability in Lexmark Printers Enables Remote Code Execution
A significant security vulnerability has been identified in numerous Lexmark printer models, potentially allowing attackers to execute arbitrary code remotely. This flaw, designated as CVE-2023-23560, […]
Exploiting Google Cloud Platform: How Hackers Execute Malicious Commands
In the rapidly evolving landscape of cloud computing, security remains a paramount concern. Recent research has unveiled a sophisticated attack vector that allows malicious actors […]
Securing Microsoft Deployment Toolkit: Preventing Credential Exposure
The Microsoft Deployment Toolkit (MDT) is a widely utilized solution for automating the deployment of operating systems and applications within enterprise environments. However, if not […]
Atlassian Releases Critical Security Updates for Data Center and Server Products
Atlassian, a leading provider of collaboration and productivity software, has issued its May 2025 Security Bulletin, disclosing eight high-severity vulnerabilities affecting multiple Data Center and […]
Over 100 Malicious Chrome Extensions Compromise User Security
A sophisticated cyberattack campaign has been identified, involving over 100 malicious Chrome browser extensions that have compromised user security since February 2024. These extensions, while […]