Tag: zero-day security vulnerability

Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers
News

Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers

As part of a cyber espionage attack campaign that began in April 2024, a threat actor with ties to Turkey took use of a zero-day security vulnerability in an Indian enterprise communication platform called Output Messenger. The Microsoft Threat Intelligence team reported that these exploits have led to the gathering of relevant user data from targets in Iraq. According to previously noted Marbled Dust targeting criteria, the attack's targets are connected to the Kurdish armed forces stationed in Iraq. The threat organization Marbled Dust (previously Silicon), also known as Cosmic Wolf, Sea Turtle, Teal Kurma, and UNC1326, has been blamed for the activities. Although Cisco Talos didn't identify assaults on public and private businesses in the Middle East and North Africa until two ye...
Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack
News

Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack

An open-source enterprise resource planning (ERP) system called Apache OfBiz has a newly found zero-day security vulnerability that might be used to get around authentication safeguards. The vulnerability, identified by the tracking number CVE-2023-51467, is related to the login functionality and arises from an insufficient patch that was previously provided earlier this month for another significant vulnerability (CVE-2023-49070, CVSS score: 9.8). "The authentication bypass was still present because the security measures taken to patch CVE-2023-49070 left the root issue intact," the threat research team from SonicWall Capture Labs read more Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack. Get up to date on the latest cybersecurity news and enhance your ...