Around six million Sky Broadband customer routers in the UK were affected by a critical vulnerability, a DNS rebinding flaw, that took over 17 months to roll out a fix to customers. The disclosed vulnerability could easily be exploit if the user had not changed the default admin password, or a threat actor could brute-force the […]
Do you want to understand the modern cyber threats and the most commonly used attack surfaces behind any malware/cyber-attack?Don’ts:1.) Don’t give everything easily to the attacker, make it harder for him to get. (Control Measures in the network)2.) Don’t enable legitimate vulnerable application if not in use, attackers always use legit applications in the network. (Abuse […]
Internet of Things devices offered in the European Union will no longer be allowed to use standard passwords from mid-2024. Instead, users must set a strong password before first use, the European Commission has determined. It must also become easier to update IoT devices, they must be tested for vulnerabilities and stored personal and financial […]
Microsoft has issued a warning for a zerodaylek in Internet Explorer, where it operates through Office documents to any other. The vulnerability is located in MSHTML, which is the Microsoft-developed browser engine in Internet Explorer. MSHTML in Office applications, is used to display web content in a document.As now observed the attack send the attackers […]
Cybersecurity researchers disclosed details about 13 vulnerabilities in the Nagios network monitoring application that could be abused by an adversary to hijack the infrastructure without any operator intervention. Nagios is an open-source IT infrastructure tool that offers monitoring and alerting services for servers, network cards, applications, and services.
A ransomware group caught targeting a recently patched SonicWall vulnerability leveraged that vulnerability before the patch became available, Mandiant reported.The vulnerability, a SQL injection bug in SonicWall’s SMA-100 series of remote access products, was already used in a headline-grabbing attack. Hackers used the vulnerability as a zero-day to breach SonicWall itself prior to the patch […]

