News

Oracle E-Business Suite RCE Zero-day

Actively exploited as a zero-day in data theft and extortion campaigns, with activity linked to the Cl0p ransomware group. Successful exploitation enables complete takeover of Oracle Concurrent Processing, opening the …

Fortra GoAnywhere MFT Attack

A critical deserialization vulnerability in GoAnywhere MFT’s License Servlet (CVSS 10.0) is actively being exploited in the wild. The flaw allows attackers with a forged license response signature to deserialize …

VMScape-Angriff | Offizieller Blog von Kaspersky

Ein Forscherteam der Eidgenössischen Technischen Hochschule Zürich (ETH Zürich) zeigt in einem Paper, wie ein Spectre v2-Angriff für einen Sandbox-Escape in einer virtualisierten Umgebung verwendet werden kann. Schon der Zugriff …

ShadowSilk Data Exfiltration Attack

FortiGuard Labs’ network telemetry has observed active exploitation of known vulnerabilities in Drupal Core and the WP-Automatic WordPress plugin for initial access. Following compromise, attackers deploy multiple web shells and …