Severity High Analysis Summary TA505 is a prolific cybercriminal group known for its attacks against multiple financial institutions and retail companies using malicious spam campaigns and […]
Severity High Analysis Summary Recently, NSIS installers for fake VPN clients have been detected distributing Cobalt Strike. All of these installers drop “InsHelper.exe” which loads “c2hex”. […]
Severity Medium Analysis Summary A Royal Road RTF maldoc, created by the Royal Road RTF weaponizer, drops a new backdoor developed with Microsoft MFC C++. The […]
Severity High Analysis Summary Node.js safe-eval module could allow a remote attacker to execute arbitrary commands on the system, caused by a sandbox escape flaw. By […]
Severity Medium Analysis Summary IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to perform unauthorized actions on the […]
Severity High Analysis Summary A new ransomware operation named DarkSide began attacking organizations earlier this month with customized attacks that have already earned them million-dollar payouts. […]
Severity High Analysis Summary There are SQLi and unauthenticated stored XSS vulnerabilities in Discount Rules for WooCommerce WordPress plugin. The Discount Rules for WooCommerce plugin (versions […]
Severity Medium Analysis Summary The login screen does not sufficiently sanitize input, which enables an attacker to generate specially crafted log messages. If an unsuspecting user […]
Severity High Analysis Summary Emotet is a Trojan that is primarily spread through spam emails (malspam). The infection may arrive either via maliciousscript, macro-enabled document files, […]