Vulnerabilities & Exploits

01
Apr
Ransomware Group Revives Log4j2 Flaw to Hit Hospitals, Factories, Banks

Ransomware Group Revives Log4j2 Flaw to Hit Hospitals, Factories, Banks

A known ransomware syndicate has resurfaced an old but unpatched Log4j2 vulnerability to launch a multi‑stage attack chain. The
1 min read
31
Mar
State‑Backed Espionage Hijacks EDA Tools, Steals Chip Design Secrets

State‑Backed Espionage Hijacks EDA Tools, Steals Chip Design Secrets

The Cybersecurity and Infrastructure Security Agency (CISA) disclosed a coordinated espionage campaign by a nation‑state actor that infiltrated electronic
1 min read
31
Mar
Critical Windows Kernel Zero‑Day Weaponized Against Banks in NA and EU

Critical Windows Kernel Zero‑Day Weaponized Against Banks in NA and EU

Microsoft’s Security Response Center has disclosed a critical zero‑day vulnerability in the Windows kernel that grants attackers system‑
1 min read
31
Mar
Critical XFS Kernel Flaw (CVE‑2024‑2150) Lets Cloud Containers Escape to Root

Critical XFS Kernel Flaw (CVE‑2024‑2150) Lets Cloud Containers Escape to Root

CVE‑2024‑2150 is a critical Linux kernel vulnerability that arises from malformed XFS filesystem operations. The flaw allows a
1 min read
31
Mar
Critical Exchange Server Zero‑Day Exploited in the Wild – Patch Now

Critical Exchange Server Zero‑Day Exploited in the Wild – Patch Now

Microsoft disclosed a critical zero‑day vulnerability (CVE‑2024‑XXXXX) in on‑premises Exchange Server that permits unauthenticated attackers to
1 min read
30
Mar
Microsoft Releases Critical Exchange Server Patch to Close ProxyLogon Gaps

Microsoft Releases Critical Exchange Server Patch to Close ProxyLogon Gaps

Microsoft has published a cumulative update for on‑premises Exchange Server that finally patches the remaining ProxyLogon flaws first disclosed
1 min read
30
Mar
Chinese APT Hijacks DevOps Updates to Steal Aerospace IP

Chinese APT Hijacks DevOps Updates to Steal Aerospace IP

A Chinese state‑sponsored APT group infiltrated the software‑distribution pipeline of a popular DevOps platform, replacing legitimate update packages
1 min read
30
Mar
Active Exploitation of FortiOS Zero‑Day Threatening Healthcare and Manufacturing

Active Exploitation of FortiOS Zero‑Day Threatening Healthcare and Manufacturing

A previously unknown zero‑day flaw in Fortinet’s FortiOS VPN module is being weaponized in the wild. The vulnerability
1 min read
30
Mar

Critical Log4j 2.x Flaw Spurs Immediate Patch Push Across Cloud and Enterprise

A cascade of critical vulnerabilities in Apache Log4j 2.x has been publicly disclosed, prompting major cloud providers and enterprise
1 min read
27
Mar

SolarWinds Issues Emergency Orion Patch After Critical Zero‑Day Revealed

SolarWinds announced an emergency update to its Orion network‑management platform after a critical zero‑day vulnerability was publicly disclosed.
1 min read