Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Ransomware exploits Confluence servers

Cybersecurity Threat Advisory: Ransomware exploits Confluence servers

Feral Wolf has targeted Russian organizations through exposed Confluence servers, insecure 1C configurations, and compromised contractors, ultimately deploying ransomware. The campaign exploited the Atlassian Confluence vulnerability CVE-2023-22515. What is the threat? Feral Wolf is a financially motivated ransomware group that...

/ September 28, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: WordPress Click2Shell flaw enables RCE

Cybersecurity Threat Advisory: WordPress Click2Shell flaw enables RCE

Researchers have disclosed a WordPress exploit chain known as Click2Shell, which was addressed in WordPress 7.1.1 as part of a security release containing 11 fixes. When combined with vulnerabilities in affected themes, the attack can lead to remote code execution...

/ September 25, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: KATARU IoT malware

Cybersecurity Threat Advisory: KATARU IoT malware

KATARU is a newly identified IoT malware family that targets internet-facing Linux devices and recruits them into Mirai-style DDoS botnets. It commonly gains access through exposed Telnet services protected by weak or default credentials. What is the threat? KATARU is...

/ September 17, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Linux kernel RDS vulnerability

Cybersecurity Threat Advisory: Linux kernel RDS vulnerability

A critical Linux kernel vulnerability, CVE-2026-43502 (ZcopyReaper), affects the RDS zerocopy send path. The flaw allows unprivileged local attackers to escalate privileges and gain root access on affected systems. A public proof-of-concept (PoC) exploit is available, making immediate patching essential...

/ September 17, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: ScreenConnect file-transfer issue

Cybersecurity Threat Advisory: ScreenConnect file-transfer issue

ConnectWise has issued a security advisory for an undisclosed file-transfer issue affecting ScreenConnect cloud-hosted and on-premises deployments. The company recommends immediate temporary mitigations while it develops a permanent fix and awaits a CVE assignment. What is the threat? This issue...

/ September 14, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SynkLoader Teams phishing campaign

Cybersecurity Threat Advisory: SynkLoader Teams phishing campaign

Security researchers have identified a phishing campaign that uses Microsoft Teams messages impersonating IT support staff to distribute a newly discovered malware known as SynkLoader. Read this Cybersecurity Threat Advisory to understand the risks associated with SynkLoader, identify potential exposure,...

/ September 4, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Malicious Notepad++ plugins

Cybersecurity Threat Advisory: Malicious Notepad++ plugins

CERT-UA has identified an ongoing campaign in which threat group UAC-0099 distributes trojanized Notepad++ bundles that install malware on Windows systems. The campaign primarily targets organizations in Ukraine and is linked to activity associated with APT44 (Sandworm). What is the...

/ July 31, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Credential-stealing RAT

Cybersecurity Threat Advisory: Credential-stealing RAT

Researchers have identified a new remote access trojan (RAT) called ChonkyChicken, which threat actors use to steal browser credentials, hijack active browser sessions, and move laterally across Windows networks. Barracuda advises organizations to focus on detection, monitoring, and security hardening,...

/ July 31, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Qilin exploits GlobalProtect flaw

Cybersecurity Threat Advisory: Qilin exploits GlobalProtect flaw

Threat actors are actively exploiting CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to gain remote access and deploy Qilin ransomware. The attacks target internet-facing firewalls and Prisma Access deployments, allowing attackers to establish VPN sessions that appear...

/ July 27, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall SMA1000 exploits

Cybersecurity Threat Advisory: SonicWall SMA1000 exploits

SonicWall has reported active exploitation of two SMA1000 zero-day vulnerabilities. Organizations should immediately install available hotfixes, as there are no workarounds. Read this Cybersecurity Threat Advisory for more details on how to protect you and your clients’ environments. What is...

/ July 24, 2026