Tag: zero day attack

Russia-Linked APT28 Exploited MDaemon Zero Day to Hack Government Webmail Servers
News

Russia-Linked APT28 Exploited MDaemon Zero Day to Hack Government Webmail Servers

A cyber espionage campaign targeting webmail systems including Roundcube, Horde, MDaemon, and Zimbra via cross-site scripting (XSS) vulnerabilities, including a then-zero-day in MDaemon, has been traced to a threat actor with ties to Russia, according to new findings from ESET. The Slovak cybersecurity firm has called the activity, which started in 2023, Operation RoundPress. The Russian state-sponsored hacker collective known as APT28—also known as BlueDelta, Fancy Bear, Fighting Ursa, Forest Blizzard, FROZENLAKE, Iron Twilight, ITG05, Pawn Storm, Sednit, Sofacy, and TA422—has been credited with medium confidence with the hack. In a report provided to The Hacker News, ESET researcher Matthieu Faou stated that the ultimate objective of this operation is to acquire private informatio...
What is a Zero-Day Attack and How It Works
Security

What is a Zero-Day Attack and How It Works

Zero-day attack is one of the dreadful threats existing on the Internet in the updated world of Cybersecurity. These attacks take advantage of flaws in existing software, hardware or firmware that are unknown to the vendor or to the public. Undiscovered vulnerabilities are unpatched ones, offering a treasure chest for cybercriminals to sneak through this article discusses What is a Zero-Day Attack and How It Works effects and protection against zero-day attacks. What Is a Zero-Day Vulnerability or Exploit ? A zero-day vulnerability is a software defect or security fault for which there is no patch or repair because the program manufacturer is unaware of it. These flaws can be used by hackers to carry out illegal activities including data theft, system compromise, or malwar...
Firefox Zero-Day Under Attack: Update Your Browser Immediately
News

Firefox Zero-Day Under Attack: Update Your Browser Immediately

Mozilla has disclosed that active exploitation of a significant security hole that affects Firefox and Firefox Extended Support Release (ESR) has occurred in the wild. It has been stated that the vulnerability, identified as CVE-2024-9680 (CVSS score: 9.8), is a use-after-free flaw in the Animation timeline component. By taking advantage of a use-after-free in Animation timelines, an attacker was able to obtain code execution in the content process, Mozilla stated in an alert on Wednesday. "We have had reports of this vulnerability being exploited in the wild." The vulnerability was found and reported by security researcher Damien Schaeffer of the Slovakian corporation ESET read more about Firefox Zero-Day Under Attack Update Your Browser Immediately. Get up to date on the ...