Helldown Ransomware Exploits Zyxel Zero-Day Vulnerability
A new ransomware, "Helldown," is exploiting vulnerabilities in Zyxel firewalls to breach corporate networks. Researchers have linked the group to attacks targeting Zyxel devices, especially those using IPSec VPN for [...]
Windows File Explorer Privilege Escalation (CVE-2024-38100) Exploited
A critical Windows File Explorer flaw, CVE-2024-38100, has been exploited, allowing attackers to gain admin-level access through an Elevation of Privilege (EoP) vulnerability. CVE-2024-38100 The flaw in the ShellWindows DCOM [...]
SQL Injection Vulnerability in Microsoft DevBlogs Enables Malicious SQL
A security researcher recently discovered a critical SQL injection vulnerability on Microsoft's DevBlogs site (https://devblogs.microsoft.com), allowing attackers to manipulate the database with malicious SQL queries, threatening platform security and data [...]
FunkSec Ransomware Leads December Attacks, Compromising 85 Victims
FunkSec, a RaaS operator, utilizes artificial intelligence to evolve threat actor strategies. While AI aids in scaling operations and generating ransomware, its sophistication remains limited. FunkSec Ransomware Recycled or fabricated [...]
ChatGPT Crawler Flaw Enables DDoS Attacks on Websites
A critical vulnerability in OpenAI's ChatGPT API allows attackers to launch DDoS attacks on arbitrary websites by exploiting how the API handles HTTP POST requests to the endpoint https://chatgpt[.]com/backend-api/attributions. The [...]