A critical security flaw has been discovered in the Zimbra Collaboration Suite (ZCS), potentially allowing hackers to execute malicious JavaScript code. This cross-site scripting (XSS) flaw, identified as CVE-2024-33533, has
Uncategorized
Cyber Alert! Small Businesses Should Enhance Their Cyber Defenses – NCSC Guide (PDF)
In a recent revelation, law enforcement figures have highlighted a concerning rise in cyber attacks targeting small businesses. The City of London Police reported 1,227 incidents in 2022, which experts
‘EastWind’ Cyber-Spy Campaign Combines Various Chinese APT Tools
How to Investigate Emerging Cyber Threats in 2024 – SOC/DFIR Team Guide
In the rapidly evolving world of cybersecurity, emerging threats pose significant challenges to organizations worldwide. These threats, characterized by their novelty and complexity, often exploit new vulnerabilities and technologies, making
One Click on a Malicious Site Could Exploit Chrome V8 Engine RCE Vulnerability
A critical security vulnerability identified as CVE-2024-5830 has been discovered in Chrome’s V8 JavaScript engine. The flaw, initially reported in May 2024 as bug 342456991. The vulnerability is a type
Kootenai Health Ransomware Attack: 464,000 patients Data Exposed
Kootenai Health, a prominent healthcare provider located at 2003 Kootenai Health Way, Coeur d’Alene, Idaho, has been the victim of a significant ransomware attack. The attack exposed sensitive information belonging
Zoom Critical Vulnerabilities Let Attackers Escalate Privileges
Zoom Video Communications has disclosed several critical vulnerabilities affecting its Workplace Apps, SDKs, and Rooms Clients. These vulnerabilities, identified in multiple security bulletins, potentially allow attackers to escalate privileges on
Microsoft Patches 6 Zero-Days That Threat Actors Actively Exploiting
Microsoft has released its August 2024 Patch Tuesday update to address 90 security vulnerabilities. The update includes fixes for six zero-day flaws actively exploited across various products and services, such
Operation Uncle Scam – AI-Powered Phishing Attack Steals Microsoft Dynamics 365 Credentials
Security researchers at Perception Point have uncovered a sophisticated phishing campaign, dubbed “Uncle Scam.” In this AI-powered campaign, threat actors impersonate U.S. government agencies to send fraudulent tender invitations to

