CISA Gives Federal Agencies Three Days to Patch Exploited NetScaler Flaw
Citrix documents denial of service. Separate research demonstrates a SAML path to root code execution but has not confirmed that it maps to this CVE.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
Citrix documents denial of service. Separate research demonstrates a SAML path to root code execution but has not confirmed that it maps to this CVE.
Read article →An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.
Read article →ErrTraffic lures lead users to run Cruciferra, which uses a vulnerable signed driver to terminate security processes before the Remus stealer runs.
Read article →Dindoor uses the signed Deno runtime, encoded stages, and a pre-persistence sandbox check. Hunt the fixed process and registry sequence beneath the changing payload.
Read article →Gitea’s patch API can turn repository content into server code execution. Upgrade to 1.27.2 or later and check server activity for signs of compromise.
Read article →CareCloud says forensic review confirmed patient data exfiltration. HHS reports 3.76 million affected people, while public records do not map specific fields to each person.
Read article →CISA confirmed exploitation of a CVSS 10 Oracle WebLogic proxy flaw. Patch affected Apache and IIS plug-ins, then review requests for unauthorized data access.
Read article →A new Windows loader arrives through a fake Teams help desk; modules sent to Expel’s emulator phish passwords and tunnel into internal services.
Read article →An updated Android banking trojan blocks Google Play traffic, automates wireless ADB pairing, and targets 349 financial apps across 16 countries.
Read article →A 1.1 MB fake installer delivers Vidar, launches installed browsers headlessly, and copies credentials and sessions that can remain useful after cleanup.
Read article →Two exploited miniOrange SAML flaws can mint WordPress admin sessions. Seven independently versioned editions make ordinary update and vulnerability checks unreliable.
Read article →Kaspersky traced malware on DoFun-powered car displays from a trusted updater to ad fraud and a residential proxy. DoFun says it fixed the issue but published no fixed build.
Read article →C2Looper shifted from one-second HTTP beacons to GitHub C2. Hunt its OneDrive DLL, JSON control files, debug marker, commands, hashes, and two IPs.
Read article →