Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical PaperCut vulnerability actively exploited

Cybersecurity Threat Advisory: Critical PaperCut vulnerability actively exploited

A new vulnerability, CVE-2023-27350, has been discovered which affects PaperCut MF and NG print management software. Successful exploitation of the vulnerability would allow attackers to access sensitive user information (usernames, email addresses, office/department information, and card numbers) without authentication. A...

/ May 8, 2023 / 1 Comment
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: EvilExtractor malware surge detected

Cybersecurity Threat Advisory: EvilExtractor malware surge detected

EvilExtractor malware has spiked in Europe and the US. EvilExtractor is distributed through phishing campaigns and can harvest various types of data, including browser history, passwords, and cryptocurrency wallets. This is a concern because of the malware’s ability to evade...

/ April 27, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New QBot malware delivering campaigns discovered

Cybersecurity Threat Advisory: New QBot malware delivering campaigns discovered

A new QBot malware campaign has been discovered. Using hijacked business emails, bad actors are distributing PDF and WSF file formats in reply-chain phishing emails to distribute malware. The campaign is designed to steal sensitive data from the target system,...

/ April 18, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: 3CX supply chain attack updates

Cybersecurity Threat Advisory: 3CX supply chain attack updates

This is a follow-up to the 3CX supply chain attack threat advisory. A malware was found in the 3CX VoIP Desktop Application, which has been delivered to users through legitimate 3CX updates. 3CX has since released security updates, and below...

/ March 31, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Supply chain attack compromised 3CXDesktopApp

Cybersecurity Threat Advisory: Supply chain attack compromised 3CXDesktopApp

A recent compromise has caused trojanized versions of the 3CXDesktopApp executable to be distributed on 3CX’s website as well as pushed through updates. The malicious version of the 3CX application is used to sideload malicious .DLL files. These .DLL files...

/ March 30, 2023 / 11 Comments
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft Outlook elevation of privilege vulnerability

Cybersecurity Threat Advisory: Microsoft Outlook elevation of privilege vulnerability

Last week, Microsoft Threat Intelligence discovered a critical elevation of privilege (EoP) vulnerability in Microsoft Outlook that allows for New Technology LAN Manager (NTLM) credentials to be stolen. Threat actors can potentially authenticate, escalate privileges, and gain access to the...

/ March 21, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New Fortinet vulnerability

Cybersecurity Threat Advisory: New Fortinet vulnerability

Fortinet has released information concerning a FortiOS & FortiProxy Heap Buffer administrative interface vulnerability with a CVSS score of 9.3. The vulnerability allows an unauthenticated attacker to execute commands on the device and/or perform a denial-of-service (DoS) attack on the...

/ March 9, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Malicious packages found in Python Package Index (PyPI)

Cybersecurity Threat Advisory: Malicious packages found in Python Package Index (PyPI)

New malicious packages were discovered on the Python Package Index (PyPI) that can steal passwords, authentication cookies, and cryptocurrency wallets from developers.

/ February 14, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Atlassian critical remote code execution vulnerability

Cybersecurity Threat Advisory: Atlassian critical remote code execution vulnerability

A critical remote code execution vulnerability has been discovered in the Jira Service Management Server and Data Center owned by Atlassian, tracked as CVE-2023-22501. This vulnerability could allow an unauthenticated attacker to impersonate other users and gain remote access to...

/ February 3, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: NortonLifeLock compromised

Cybersecurity Threat Advisory: NortonLifeLock compromised

Recently, thousands of NortonLifeLock customers had their accounts compromised, potentially allowing malicious actors to access user password managers. Gen Digital, Norton LifeLock’s parent company, has sent notices to over 6,000 customers whose accounts were compromised.

/ January 18, 2023