E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Read More Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse...
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Read More Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The...
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Read More The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active...