CVE-2023-20864: VMware Aria Operations for Logs Deserialization Vulnerability
April 21, 2023VMware issues advisory to address two flaws in its VMware Aria Operations for Logs solution, including a critical deserialization flaw assigned a CVSSv3 score of 9.8.
Oracle April 2023 Critical Patch Update Addresses 231 CVEs
April 19, 2023Oracle addresses 231 CVEs in its second quarterly update of 2023 with 433 patches, including 74 critical updates.
Microsoft’s April 2023 Patch Tuesday Addresses 97 CVEs (CVE-2023-28252)
April 11, 2023Microsoft addresses 97 CVEs, including one that was exploited in the wild as a zero day.
3CX Desktop App for Windows and macOS Reportedly Compromised in Supply Chain Attack
March 30, 2023A softphone desktop application from 3CX, makers of a popular VoIP PBX solution used by over 600,000 organizations, has reportedly been trojanized as part of a supply chain attack
OpenAI’s ChatGPT and GPT-4 Used as Lure in Phishing Email, Twitter Scams to Promote Fake OpenAI Tokens
March 17, 2023Hoping to cash in on the massive interest around OpenAI’s GPT-4 – ChatGPT’s new multimodal model – scammers have launched phishing campaigns via email and Twitter designed to steal cryptocurrency. Check out how they’re carrying out the scams and how you can avoid becoming a victim.
Microsoft’s March 2023 Patch Tuesday Addresses 76 CVEs (CVE-2023-23397)
March 14, 2023Microsoft addresses 76 CVEs including two zero-days exploited in the wild, one of which was publicly disclosed.
FBI and CISA Release Cybersecurity Advisory on Royal Ransomware Group
March 3, 2023The FBI and CISA have released a joint Cybersecurity Advisory discussing the Royal ransomware group.
South Korean and American Agencies Release Joint Advisory on North Korean Ransomware
February 16, 2023Several South Korean and American agencies have released a joint cybersecurity advisory on North Korean state-sponsored ransomware operators.
Microsoft’s February 2023 Patch Tuesday Addresses 75 CVEs (CVE-2023-23376)
February 14, 2023Microsoft addresses 75 CVEs including three zero-day vulnerabilities that were exploited in the wild.
ProxyNotShell, OWASSRF, TabShell: Patch Your Microsoft Exchange Servers Now
January 31, 2023Several flaws in Microsoft Exchange Server disclosed over the last two years continue to be valuable exploits for attackers as part of ransomware and targeted attacks against organizations that have yet to patch their systems. Patching the flaws outlined below is strongly recommended.
Sandworm APT Deploys New SwiftSlicer Wiper Using Active Directory Group Policy
January 27, 2023Sandworm, the Russian-backed APT responsible for NotPetya in 2017, has recently attacked an Ukrainian organization using a new wiper, SwiftSlicer.
Oracle January 2023 Critical Patch Update Addresses 183 CVEs
January 19, 2023Oracle addresses 183 CVEs in its first quarterly update of quarterly with 327 patches, including 71 critical updates.