Fortinet is concerned that many of its customers’ devices are still unprotected against attacks exploiting the recently disclosed zero-day vulnerability and the company has urged them to take action.
New ‘Black Lotus’ UEFI Rootkit Provides APT-Level Capabilities to Cybercriminals
A threat actor is promoting on underground criminal forums a vendor-independent UEFI rootkit that can disable security software and controls, cybersecurity veteran Scott Scheferman warns.
New ‘Alchimist’ Attack Framework Targets Windows, Linux, macOS
Cisco’s Talos security researchers warn of a newly identified attack framework and its associated remote access trojan (RAT) targeting Windows, Linux, and macOS systems.
Seven ‘Creepy’ Backdoors Used by Lebanese Cyberspy Group in Israel Attacks
ESET has published an analysis of the seven backdoors that Lebanese advanced persistent threat (APT) actor Polonium has been using since September 2021 in attacks targeting Israeli organizations.
PoC Published for Fortinet Vulnerability as Mass Exploitation Attempts Begin
Details and a proof-of-concept (PoC) exploit have been published for the recent Fortinet vulnerability tracked as CVE-2022-40684, just as cybersecurity firms are seeing what appears to be the start of mass exploitation attempts.
Chinese Cyberspies Targeting US State Legislature
A China-linked cyberespionage group was recently observed targeting a state legislature in the United States, Symantec warns.
QBot Malware Infects Over 800 Corporate Users in New, Ongoing Campaign
More than 800 corporate users have been infected in a new QBot malware distribution campaign since September 28, Kaspersky warns.
LofyGang Cybercrime Group Used 200 Malicious NPM Packages for Supply Chain Attacks
A cybercrime group named LofyGang has distributed roughly 200 malicious NPM packages that have been downloaded thousands of times over the past year, according to Checkmarx.
Fortinet Confirms Zero-Day Vulnerability Exploited in One Attack
Fortinet has confirmed that the critical vulnerability whose existence came to light last week is a zero-day flaw that has been exploited in at least one attack.
Critical Zimbra RCE Vulnerability Exploited in Attacks
The Zimbra Collaboration Suite is impacted by a critical remote code execution vulnerability that remains unpatched, despite being exploited in attacks.












