Security researchers at Avast have uncovered evidence that the notorious North Korean hacker group Lazarus exploited a previously unknown zero-day vulnerability in the Windows AFD.sys driver to gain kernel-level access
All posts by admin
Why Training is Critical to Implementing Cisco HyperShield
The imminent release of Cisco HyperShield this month marks a pivotal evolution in the cybersecurity landscape. As an “AI-native” security architecture, HyperShield promises to redefine traditional security protocols through its
Critical Android Vulnerability Impacting Millions of Pixel Devices Worldwide
An Android package, “Showcase.apk,” preinstalled on a significant portion of Pixel devices since 2017, possesses extensive system permissions enabling remote code execution and package installation. It fetches a configuration file
Kubernetes Vulnerability Exposes Clusters to Command Injection Attacks
A recently discovered vulnerability in Kubernetes has raised significant concerns within the cybersecurity community. Akamai researcher Tomer Peled identified a design flaw in Kubernetes’ sidecar project, git-sync, which could allow
Zimbra XSS Flaw Allows Hackers to Execute Malicious JavaScript Code
A critical security flaw has been discovered in the Zimbra Collaboration Suite (ZCS), potentially allowing hackers to execute malicious JavaScript code. This cross-site scripting (XSS) flaw, identified as CVE-2024-33533, has
Cyber Alert! Small Businesses Should Enhance Their Cyber Defenses – NCSC Guide (PDF)
In a recent revelation, law enforcement figures have highlighted a concerning rise in cyber attacks targeting small businesses. The City of London Police reported 1,227 incidents in 2022, which experts
‘EastWind’ Cyber-Spy Campaign Combines Various Chinese APT Tools
How to Investigate Emerging Cyber Threats in 2024 – SOC/DFIR Team Guide
In the rapidly evolving world of cybersecurity, emerging threats pose significant challenges to organizations worldwide. These threats, characterized by their novelty and complexity, often exploit new vulnerabilities and technologies, making
One Click on a Malicious Site Could Exploit Chrome V8 Engine RCE Vulnerability
A critical security vulnerability identified as CVE-2024-5830 has been discovered in Chrome’s V8 JavaScript engine. The flaw, initially reported in May 2024 as bug 342456991. The vulnerability is a type

