company · 5 records
Censys

Apache Syncope vulnerability enables arbitrary SQL command execution
Rapid7 released a public proof-of-concept script for a critical authentication bypass vulnerability in Check Point SmartConsole that allows unauthenticated attackers to gain administrative privileges.

Plex encourages users to update software to address security vulnerabilities
Plex is encouraging users to update to the latest versions of Plex Media Server and Plex Desktop to patch undisclosed security vulnerabilities.

Threat actor deploys GHOSTBLADE malware on Apple iOS devices
An unknown Chinese-speaking threat actor has been observed using a leaked DarkSword exploit kit to deploy GHOSTBLADE malware targeting Apple iOS devices.

New NadMesh botnet targets exposed cloud credentials and API keys
A new Go botnet named NadMesh is targeting exposed AI and development services to harvest cloud credentials, Kubernetes tokens, and API keys, with operators claiming thousands of compromised AWS keys.

Russian intelligence uses compromised cameras to monitor military logistics in Europe
Russian intelligence services are systematically hijacking internet-connected IP cameras across Europe and Ukraine to monitor military logistics and target Ukrainian personnel, according to a joint advisory by Dutch intelligence agencies.