Vulnerability

Cisco AnyConnect SSL VPN Flaw Let Remote Attacker Launch DoS Attack

A vulnerability of medium severity, identified as CVE-2023-20042, with a CVSS score of 6.8, was found in the AnyConnect SSL…

1 year ago

CitrixBleed Flaw Widely Exploited, Primarily by a Ransomware Gang

At the end of October, AssetNote released a proof-of-concept for the CVE-2023–4966 associated with sensitive information disclosure for Citrix Netscaler…

1 year ago

Hackers Weaponize HWP Documents to Attack Defense and Press Sectors

HWP documents are primarily associated with the Hangul Word Processor software used in South Korea.  Hackers may opt for HWP…

1 year ago

The Risk of RBAC Vulnerabilities – A Prevention Guide

Role-Based Access Control (RBAC) is a security paradigm focused on assigning system access to users based on their organizational role.…

1 year ago

Hackers Abusing OAuth Token to Take Over Millions of Accounts

A new OAuth vulnerability has been discovered in three of the major extensions such as Grammarly, Vidio, and Bukalapak. These…

1 year ago

Raven: Open-source CI/CD Pipeline Vulnerability Scanner Tool

Cycode is excited to introduce Raven, a state-of-the-art security scanner for CI/CD pipelines.  Raven stands for Risk Analysis and Vulnerability…

1 year ago

D-LINK SQL Injection Vulnerability Let Attacker Gain Admin Privileges

A security flaw called SQL injection has been uncovered in the D-Link DAR-7000 device. SQL injection is a malicious attack…

1 year ago

VMware Tools Flaw Let Attackers Escalate Privileges

Two high vulnerabilities have been discovered in VMware Tools, which were assigned with CVE-2023-34057 and CVE-2023-34058. These vulnerabilities were associated…

1 year ago

Firefox Memory Corruption Flaw Let Attacker Execute Arbitrary Code

Mozilla Firefox 119 was released with updates for 11 vulnerabilities, including three issues of high severity, seven issues of moderate severity,…

1 year ago

SEIKO Cyber Attack: Customers Personal Data Exposed

SEIKO Group Corporation (SGC) has announced that they suffered a cyber attack that exposed customer data.  The attack lasted for…

1 year ago