News

F5 Emergency Patch: Critical NGINX Unauthenticated RCE Hits 40 Percent of Web Servers
Cybersecurity
F5 Emergency Patch: Critical NGINX Unauthenticated RCE Hits 40 Percent of Web Servers
F5 released emergency patches for NGINX enabling unauthenticated RCE across 40 percent of web servers worldwide today in an accelerated disclosure window.
Atlassian and Splunk Patch Critical Flaws Splunk AI Toolkit RCE, Atlassian Dependencies
Cybersecurity
Atlassian and Splunk Patch Critical Flaws: Splunk AI Toolkit RCE, Atlassian Dependencies
Atlassian and Splunk emergency patches include an OS command injection in Splunk AI Toolkit plus dozens of Atlassian Server dependency flaws
Cybersecurity
Critical Command Execution Vulnerability Patched in Cisco ISE
Cisco patched a critical command execution vulnerability in its Identity Services Engine where insufficient input validation enabled root-level system access.
Cybersecurity
Rokarolla Android Banking Trojan Targets 217 Banking and Crypto Apps
The Rokarolla Android banking trojan evolved beyond credential theft with a 137-command C2 framework targeting 217 banking and cryptocurrency applications.
Cybersecurity
Phantom Stealer Fileless Malware Targets Browser Credentials in Memory
Researchers identified Phantom Stealer as a new fileless credential stealer targeting all browsers via in-memory execution and anti-analysis techniques.
Cybersecurity
INC Ransomware Targets Healthcare, Education, and Local Government
Investigation reveals INC ransomware achieves consistent revenue by targeting healthcare, education, and local government with rapid encryption and data exfiltration.
Cybersecurity
ClickFix Campaign Linked to Vice Society Uses Compromised WordPress Sites
A malware campaign using Lorem Ipsum lures pivots to ClickFix delivery through compromised WordPress sites, with research suggesting possible links to Vice Society.
Cybersecurity
FortiBleed Compromises 74K Fortinet Firewall Credentials Worldwide
FortiBleed exposes verified Fortinet FortiGate VPN credentials for 74K devices across 194 countries, covering major corporations and a Turkish NATO contractor.
Cybersecurity
Gentlemen RaaS Group Maintains Purpose-Built EDR Killers
Gentlemen ransomware-as-a-service operation develops and maintains purpose-built endpoint detection kill tools to disable security protections before ransomware deployment.
Cybersecurity
Nintendo Confirms Employee Survey Data Stolen via TinyPulse
Nintendo confirms employee survey data stolen from TinyPulse, the WebMD subsidiary, through a third-party vendor breach affecting corporate HR integration.