Vulnerability summary for the week: April 24, 2020
Weekly vulnerability digest.
Weekly vulnerability digest.
The report includes a list of web application vulnerabilities that are commonly exploited to install malware.
The researchers were able to sinkhole several C&C domains so that they could monitor the botnet’s activity.
The hackers are targeting Revive installations by injecting an obfuscated Javascript payload that gives them the ability to hijack and display their own ads.
APT32 has been conducting a spearphishing campaign against Chinese targets in an attempt to collect information about coronavirus.
The bugs have been exploited in the wild since at least 2018.
Nintendo recommends users to enable two-step verification for their Nintendo account.
Three separate flaws could be chained to achieve unauthenticated remote code execution as root on vulnerable systems.
Almost all antivirus tools run with high privileges on the system, and threat actors can use this to their advantage.
This is the first time when Agent Tesla has been deployed as part of attacks targeting the oil & gas industries.
Showing elements 3711 - 3720