LR pixel

CrushFTP VFS Sandbox Escape Vulnerability (CVE-2024-4040)

What is the Vulnerability ? A zero-day security vulnerability has been uncovered in an enterprise file-transfer software CrushFTP. The vulnerability tagged as CVE-2024-4040 is actively being exploited in targeted attacks and has also been added to the CISA Known...

ArcaneDoor Attack (CVE-2024-20353 and CVE-2024-20359)

What is the Attack? Cisco issued an advisory on 24th April, regarding its Adaptive Security Appliances, multifunctional devices combining firewall, VPN, and other security functions. It reported that these appliances had become the focus of state-sponsored espionage,...

Akira Ransomware Attack

What is the Akira Ransomware Attack? The Akira ransomware attack has actively and widely impacting businesses. According to CISA advisory, the ransomware group has impacted over 250 organizations and claimed approximately $42 million (USD) in ransomware proceeds. The...

XZ Utils Supply Chain Attack (CVE-2024-3094)

What is the vulnerability/attack? A malicious code was discovered embedded in the XZ Utils which is a data compression software included in major Linux distributions. This vulnerability tracked under CVE-2024-3094 is a result of a supply chain attack on the versions...