Home

GuLoader Malware Utilizing New Techniques to Evade Security Software

Cybersecurity researchers exposed new evasion techniques adopted by an advanced malware downloader called GuLoader.  GuLoader malware GuLoader  is a first-stage trojan designed to infect a system and drop a final payload. Typically other trojans or [...]

CVE-2022-47633 Vulnerability Allows Attackers to Bypass Kyverno Signature Verification

The vulnerability could let attackers introduce malicious code into cloud production environments.  Kyverno’s admission controller offers a signature verification mechanism to ensure that only signed container images can enter a Kubernetes cluster.  The [...]

Vice Society Ransomware Attackers Adopt Robust Encryption Methods

SentinelLabs disclosed that the Vice Society group has adopted a new custom-branded ransomware payload in recent intrusions, dubbed ‘PolyVice,’ which implements an encryption scheme, using NTRUEncrypt and ChaCha20-Poly1305 algorithms. Vice [...]

LastPass Admits to Severe Data Breach, Encrypted Password Vaults Stolen

LastPass has confirmed that cybercriminals stole its customers’ encrypted password vaults, which store its customers’ passwords and other secrets, in a data breach earlier this year. LastPass revealed that this repository of customer [...]

ProxyNotShell Vulnerabilities Being Actively Exploited (CVE-2022-41040 and CVE-2022-41082)

Reports says, the zero-day vulnerabilities CVE-2022-41040 and CVE-2022-41082, dubbed ProxyNotShell, are still being actively exploited.  ProxyNotShell vulnerabilities are exploited by adversaries for remote code execution (RCE) in vulnerable Exchange servers in the wild. [...]

Subscribe to our newsletter to receive security tips everday!