A vulnerability in Google Cloud Platform (GCP) could have allowed attackers to maliciously change an OAuth application and hide it to create a stealthy backdoor to any Google account. Exploitation of the bug, referred to as GhostToken, could have allowed attackers to completely hide the malicious application from the Google user and leverage it to ..
Tag : Vulnerabilities
Virtualization technology powerhouse VMware continues to encounter major security problems in its enterprise-facing log analysis product. The company shipped urgent patches on Thursday to cover critical security defects in the VMware Aria Operations for Logs (formerly vRealize Log Insight) product line and warned of the risk of pre-authentication remote root exploits. A critical-level advisory from ..
Print management solutions provider PaperCut has warned organizations that exploitation of a recently patched critical-severity vulnerability has commenced. Papercut offers a print management system called PaperCut MF/NG, which provides monitoring and control capabilities. With PaperCut NG organizations can manage and control printing, while PaperCut MF allows them to manage and track off-the-glass copier activity. Tracked ..
Fortra has completed the investigation into the recent zero-day incident involving its GoAnywhere managed file transfer (MFT) software and the company has shared a summary of its findings. The investigation, conducted with the aid of cybersecurity firm Palo Alto Networks, revealed that malicious activity started on January 18, with cybercriminals exploiting a zero-day vulnerability against ..
Google on Tuesday announced patches for another zero-day vulnerability found in the Chrome browser. Tracked as CVE-2023-2136, the security defect is described as a high-severity integer overflow issue in Skia. The bug was reported by Google Threat Analysis Group researcher Clement Lecigne and, per Google’s policy, no monetary reward was issued for it. “Google is ..
Oracle on Tuesday announced the release of 433 new patches as part of its quarterly set of security updates, including more than 70 fixes for critical-severity vulnerabilities. More than 250 of the addressed vulnerabilities can be exploited remotely and without authentication. Some of the resolved bugs impact multiple products. For the third quarter in a ..
Government agencies in the United States and United Kingdom have issued a joint cybersecurity advisory to warn organizations about attacks in which a Russian threat group has exploited an old vulnerability to hack Cisco routers. The threat actor in question is APT28 (aka Fancy Bear, Strontium, Pawn Storm, Sednit Gang and Sofacy), which has officially ..
Israeli spyware vendor NSO Group used at least three previously unknown iOS zero-click exploits in 2022, according to a new report from Citizen Lab. NSO Group’s Pegasus spyware has often been delivered to targeted iPhones using zero-click and/or zero-day exploits, and while Apple has taken steps to prevent attacks against its customers, NSO’s exploit developers ..
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two flaws to its known exploited vulnerabilities (KEV) catalog: a Chrome bug patched last week and a macOS bug exploited by the DazzleSpy malware. The Chrome vulnerability, tracked as CVE-2023-2033, was patched by Google on Friday with a Chrome 112 update. The flaw has been ..
The low code/no code movement provides simplified app generation – but it needs to be understood to be safe. We are struggling to satisfy the demand for new software – the laborious effort of writing code has become a bottleneck to innovation in general, and being first to market in particular. In other areas of ..


