Severity High Analysis Summary A recently disclosed vulnerability in Oracle WebLogic server that we reported earlier today is being actively exploited to install a new variant […]
Severity High Analysis Summary A deserialization vulnerability in Oracle WebLogic Server. This remote code execution vulnerability is remotely exploitable without authentication, i.e., may be exploited over […]
Severity Medium Analysis Summary A new technical support scam (TSS) campaign surfaced using iframe in combination with basic pop-up authentication to freeze a user’s browser. This […]
Severity Medium Analysis Summary Recently, some threat actors distributed their malware by abusing Yandex.Direct and hosted it on GitHub. The group used two well-known backdoors — […]
Severity Medium Analysis Summary Oracle WebLogic application contains a critical deserialization remote code execution vulnerability that affects all versions of the software, which can be triggered […]
Severity Medium Analysis Summary The DNSpionage malware campaign has resurfaced with a new sophisticated operation that infects selected victims with a new variant of the DNSpionage […]
Severity Medium Analysis Summary A phishing email was reported which falsely appears to be coming from Standard Chartered bank, having a malicious DOC file as attachment. […]
Severity High Analysis Summary A number of vulnerabilities are reported in Google Chrome. 1) A use-after-free error related to PDFium can be exploited to corrupt memory. […]
Severity Medium Analysis Summary CVE-2019-6974In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free. CVE-2019-7221The […]