+44 (0)203 88 020 88

Author name: secureteampstg

Windows Error Reporting Tool Abused to Load Malware

A legitimate Windows executable is being abused by malicious actors to stealthily infect devices with malware without raising any alarms. The Windows Error Reporting tool WerFault.exe can be exploited to load malware onto a system using a DLL sideloading technique in an attack K7 Security Labs have published an analysis for last week. This legitimate

Windows Error Reporting Tool Abused to Load Malware Read More »

High Severity Vulnerability in ManageEngine Products

A high severity SQL injection vulnerability has been patched in recent updates for Zoho ManageEngine products Password Manager Pro, PAM360, and Access Manager Plus. The software provider released a security advisory for this vulnerability where they advised customers of all three affected products to upgrade to the latest versions immediately due to the severity of

High Severity Vulnerability in ManageEngine Products Read More »

Critical Vulnerability in Synology Router VPN Servers

A recently discovered vulnerability in Synology routers configured to run as VPN servers has been given a critical severity rating and the maximum CVSS score of 10/10. Synology is a global data management and security company specialising in network attached storage (NAS) and storage area network (SAN) devices. Synology Router Manager (SRM) is the operating

Critical Vulnerability in Synology Router VPN Servers Read More »

Android Update Patches Critical Vulnerabilities

A security update for December has been released by Google for Android that addresses 4 critical severity vulnerabilities. An additional 16 critical flaws have been patched in a Pixel update that has been released for Google Pixel devices. These 16 additional vulnerabilities patched are elevation of privilege flaws found in Pixel firmware, and LDFW, TF-A,

Android Update Patches Critical Vulnerabilities Read More »

Endpoint Detection Systems Used as Data Wipers

Endpoint detection and response (EDR) systems, and antivirus (AV) software, are used to increase the cybersecurity of a device. However, these security software solutions are now able to be exploited for their data deletion capabilities, effectively turning them into data wipers. Security researcher Or Yair at SafeBreach Labs discovered this capability alongside multiple zero-day vulnerabilities

Endpoint Detection Systems Used as Data Wipers Read More »

Apple MacOS Vulnerability Allows Gatekeeper Bypass

Apple have released updates across their macOS platforms to address a vulnerability known as ‘Achilles’ that could allow malicious downloaded apps to bypass Gatekeeper security checks. A patch for this vulnerability was released in a security update last week, which can be found in macOS Ventura 13.1, macOS Monterey 12.6.2, and macOS Big Sur 11.7.2.

Apple MacOS Vulnerability Allows Gatekeeper Bypass Read More »

Citrix Zero-Day Vulnerability Actively Exploited

A critical zero-day vulnerability has been confirmed to be actively exploited by state-backed attackers to gain access to corporate networks. The National Security Agency (NSA), a branch of the US Government, have released a cybersecurity advisory  to help organisations detect and mitigate attacks that exploit this vulnerability. Products affected by this flaw are Citrix ADC

Citrix Zero-Day Vulnerability Actively Exploited Read More »

Scroll to Top