Experts Detail Malicious Code Dropped Using ManageEngine ADSelfService Exploit

At least nine entities across the technology, defense, healthcare, energy, and education industries were compromised by leveraging a recently patched critical vulnerability in Zoho’s ManageEngine ADSelfService Plus self-service password management and … Continue reading Experts Detail Malicious Code Dropped Using ManageEngine ADSelfService Exploit

Posted in Uncategorized

BlackBerry Uncovers Initial Access Broker Linked to 3 Distinct Hacker Groups

A previously undocumented initial access broker has been unmasked as providing entry points to three different threat actors for mounting intrusions that range from financially motivated ransomware attacks to phishing campaigns.
BlackBerry’s research a… Continue reading BlackBerry Uncovers Initial Access Broker Linked to 3 Distinct Hacker Groups

Posted in Uncategorized

U.S. Federal Agencies Ordered to Patch Hundreds of Actively Exploited Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published a catalog of vulnerabilities, including from Apple, Cisco, Microsoft, and Google, that have known exploits and are being actively exploited by malicious cyber actors, in add… Continue reading U.S. Federal Agencies Ordered to Patch Hundreds of Actively Exploited Flaws

Posted in Uncategorized

Hardcoded SSH Key in Cisco Policy Suite Lets Remote Hackers Gain Root Access

Cisco Systems has released security updates to address vulnerabilities in multiple Cisco products that could be exploited by an attacker to log in as a root user and take control of vulnerable systems.
Tracked as CVE-2021-40119, the vulnerability has b… Continue reading Hardcoded SSH Key in Cisco Policy Suite Lets Remote Hackers Gain Root Access

Posted in Uncategorized