GitLab Patches Critical HTML Injection Flaw Allowing XSS Attacks
GitLab released patches (17.5.1, 17.4.3, and 17.3.6) for both Community and Enterprise Editions, fixing a critical HTML injection vulnerability in the Global Search feature that could lead to XSS attacks, [...]
Lazarus APT Hackers Exploit Chrome Zero-Day via Crypto Game
Lazarus APT exploited a Chrome zero-day using a crypto-themed game as bait, showcasing the group’s evolving financial tactics and social engineering. On May 13, 2024, Kaspersky detected a new infection [...]
Critical Vulnerabilities Found in VMware vCenter Server
Broadcom has issued critical security updates for severe vulnerabilities in VMware vCenter Server that allow remote code execution and privilege escalation. The flaws, CVE-2024-38812 and CVE-2024-38813, impact multiple versions of [...]
Callback Phishing Targets Login Credentials via Google Groups
Phishing attacks trick individuals into revealing sensitive info by impersonating trusted entities, often through urgent emails with malicious links or attachments. Trustwave analysts recently warned of Callback Phishing attacks using [...]
Over 10 million personal and corporate devices hit by information stealers
Kaspersky reports nearly 10 million personal and corporate devices were compromised by data-stealing malware in 2023, a 643% rise in three years. Information stealers, which collect sensitive data like login [...]