Tag: zero-day
-
Palo Alto Networks discloses RCE zero-day vulnerability
Tags: exploit, flaw, injection, network, rce, remote-code-execution, software, threat, vulnerability, zero-dayThreat actors have exploited the remote code injection flaw, which affects the GlobalProtect gateway in Palo Alto Networks’ PAN-OS software, in a ‘lim… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366580732/Palo-Alto-Networks-discloses-RCE-zero-day-vulnerability
-
Microsoft corks Windows zero-day on April Patch Tuesday
The company delivered one of its largest security update releases in recent years with a proxy driver spoofing vulnerability topping the patching prio… First seen on techtarget.com Jump to article: www.techtarget.com/searchwindowsserver/news/366580334/Microsoft-corks-Windows-zero-day-on-April-Patch-Tuesday
-
Exploit code for Palo Alto Networks zero-day now public
First seen on theregister.com Jump to article: www.theregister.com/2024/04/17/researchers_exploit_code_for/
-
Über Zero-Day-Schwachstellen: Cisco-Firewalls werden seit Monaten attackiert
Eine zuvor unbekannte Hackergruppe nutzt mindestens seit November 2023 zwei Zero-Day-Schwachstellen in Cisco-Firewalls aus, um Netzwerke zu infiltrier… First seen on golem.de Jump to article: www.golem.de/news/ueber-zero-day-schwachstellen-cisco-firewalls-werden-seit-monaten-attackiert-2404-184540.html
-
Zero-day exploited right now in Palo Alto Networks’ GlobalProtect gateways
First seen on theregister.com Jump to article: www.theregister.com/2024/04/12/palo_alto_pan_flaw/
-
7-Year-Old 0-Day in Microsoft Office Exploited to Drop Cobalt Strike
Hackers are dusting off old tricks! A recent attack exploited vulnerabilities in systems running outdates Microsoft Office to deliver Cobalt Strike ma… First seen on hackread.com Jump to article: www.hackread.com/microsoft-office-0-day-exploited-cobalt-strike/
-
Military Tank Manual, 2017 Zero-Day Anchor Latest Ukraine Cyberattack
The targeted operation utilized CVE-2017-8570 as the initial vector and employed a notable custom loader for Cobalt Strike, yet attribution to any kno… First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/military-tank-manual-zero-day-ukraine-cyberattack
-
Breach Roundup: REvil Hacker Gets Nearly 14-Year Sentence
Also: Another Ivanti Zero-Day? And FBI Calls for Strengthening DMARC Policies. This week, REvil hacker sentenced; ZDI saw possible Ivanti-zero-day; FB… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-revil-hacker-gets-nearly-14-year-sentence-a-25002
-
Over 1,400 CrushFTP Instances Vulnerable To Exploited 0-Day
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/35818/Over-1-400-CrushFTP-Instances-Vulnerable-To-Exploited-0-Day.html
-
MITRE Corporation Breached by Nation-State Hackers Exploiting Ivanti Flaws
The MITRE Corporation revealed that it was the target of a nation-state cyber attack that exploited two zero-day flaws in Ivanti Connect Secure applia… First seen on thehackernews.com Jump to article: thehackernews.com/2024/04/mitre-corporation-breached-by-nation.html
-
Cisco Zero-Days Anchor ‘ArcaneDoor’ Cyber-Espionage Campaign
Attacks by a previously unknown threat actor leveraged two bugs in firewall devices to install custom backdoors on several government networks globall… First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/cisco-zero-days-arcanedoor-cyberespionage-campaign
-
Nation-State Hackers Exploit Cisco Firewall Zero Days To Backdoor Government Networks
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/35815/Nation-State-Hackers-Exploit-Cisco-Firewall-Zero-Days-To-Backdoor-Government-Networks.html
-
Verizon DBIR: Cyber Defenders Are Facing Exploit Fatigue
Experts Warn That Human Failures Have Led to Surge in Successful Zero-Day Exploits. Verizon executives warned that cyber defenders are struggling with… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/verizon-dbir-cyber-defenders-are-facing-exploit-fatigue-a-24989
-
Critical Update: CrushFTP Zero-Day Flaw Exploited in Targeted Attacks
Users of the CrushFTP enterprise file transfer software are being urged to update to the latest version following the discovery of a security flaw tha… First seen on thehackernews.com Jump to article: thehackernews.com/2024/04/critical-update-crushftp-zero-day-flaw.html
-
Zero-Day Nightmare: Palo Alto, Cisco, and MITRE Under Attack
Zero-day threats continue to wreak havoc on organizations worldwide, with recent attacks targeting corporate and government networks. In the last few … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/zero-day-nightmare-palo-alto-cisco-and-mitre-under-attack/
-
Patch Now: CrushFTP Zero-Day Cloud Exploit Targets US Orgs
An exploit for the vulnerability allows unauthenticated attackers to escape a virtual file system sandbox to download system files and potentially ach… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/patch-crushftp-zero-day-cloud-exploit-targets-us-orgs
-
Definition ZDI | Zero Day Initiative – Was ist die Zero Day Initiative?
Tags: zero-dayFirst seen on security-insider.de Jump to article: www.security-insider.de/definition-zero-day-initiative-zdi-a-fd51e987841cb77b2bb482be1000bd8e/
-
Week in review: Two Cisco ASA zero-days exploited, MITRE breach, GISEC Global 2024
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Hackers backdoored Cisco ASA devices via two zero-da… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/04/28/week-in-review-two-cisco-asa-zero-days-exploited-mitre-breach-gisec-global-2024/
-
Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day
More than 1,400 CrushFTP servers remain vulnerable to an actively exploited zero-day for which PoC has been published. The post n 1,400 CrushFTP serve… First seen on securityweek.com Jump to article: www.securityweek.com/over-1400-crushftp-instances-vulnerable-to-exploited-zero-day/
-
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/35800/MITRE-Hacked-By-State-Sponsored-Group-Via-Ivanti-Zero-Days.html
-
5000+ CrushFTP Servers Hacked Using Zero-Day Exploit
Hackers often target CrushFTP servers as they contain sensitive data and are used for file sharing and storage. This makes them attractive targets for… First seen on gbhackers.com Jump to article: gbhackers.com/crushftp-servers-zero-day-hack/
-
Popular File Transfer Software CrushFTP Hit by Zero-Day Exploit
First seen on hackread.com Jump to article: www.hackread.com/crushftp-file-transfer-software-zero-day-exploit/
-
Hackers Exploit Old Microsoft Office 0-day to Deliver Cobalt Strike
Hackers have leveraged an old Microsoft Office vulnerability, CVE-2017-8570, to deploy the notorious Cobalt Strike Beacon, targeting systems in Ukrain… First seen on gbhackers.com Jump to article: gbhackers.com/hackers-exploit-old-microsoft-office/
-
Local Privilege Escalation Vulnerability in Ant Media Server (CVE-2024-32656)
Overview In an effort to safeguard our customers, we perform proactive vulnerability research with the goal of identifying zero-day vulnerabilities th… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/local-privilege-escalation-vulnerability-in-ant-media-server-cve-2024-32656/
-
Hackers backdoored Cisco ASA devices via two zero-days (CVE-2024-20353, CVE-2024-20359)
A state-sponsored threat actor has managed to compromise Cisco Adaptive Security Appliances (ASA) used on government networks across the globe and use… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/04/24/cve-2024-20353-cve-2024-20359/
-
Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networks
Nation-state actor UAT4356 has been exploiting two zero-days in ASA and FTD firewalls since November 2023 to breach government networks. Cisco Talos w… First seen on securityaffairs.com Jump to article: securityaffairs.com/162244/apt/nation-state-actors-exploited-two-zero-days-in-asa-and-ftd-firewalls-to-breach-government-networks.html
-
ArcaneDoor hackers exploit Cisco zero-days to breach govt networks
‹Cisco warned today that a state-backed hacking group has been exploiting two zero-day vulnerabilities in Adaptive Security Appliance (ASA) and Firepo… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/arcanedoor-hackers-exploit-cisco-zero-days-to-breach-govt-networks/

