Cyber Defense Advisors

News

High severity flaw patched in widely used curl tool

The developers of the curl open-source software application and library have released patches for two vulnerabilities in the widely used command-line tool. One of the flaws is rated with high severity and could potentially be exploited by rogue servers to execute malicious code on systems that access them with curl under certain conditions. Curl, which […]

Cyber News, Cyber Threat Trends

CISOs Receive Smaller Raises and Bonuses in 2023

Most CISOs are considering a job change in the next 12 months

Cyber News, Cyber Threat Trends

CISOs Receive Smaller Raises and Bonuses in 2023

Most CISOs are considering a job change in the next 12 months

Cyber News, Cyber Threat Trends

CISOs Receive Smaller Raises and Bonuses in 2023

Most CISOs are considering a job change in the next 12 months

Cyber News, Cyber Threat Trends

CISOs Receive Smaller Raises and Bonuses in 2023

Most CISOs are considering a job change in the next 12 months

Cyber News, Cyber Threat Trends

Vulnerability Exposed in WordPress Plugin User Submitted Posts

With over 20,000 active installations, the plugin is used for user-generated content submissions

Cyber News, Cyber Threat Trends
  • by
  • October 12, 2023

Misleading IAM CloudFormation Error Message — Role Name Is Invalid

I was deploying some new roles and policies using my common code when I got this message: Continue reading on Bugs That Bite »

Cyber News, Cyber Threat Trends

Chinese APT ToddyCat Targets Asian Telecoms, Governments

A cyber espionage campaign tied to the Chinese group ToddyCat is targeting high-profile organizations in Kazakhstan, Uzbekistan, Pakistan, and Vietnam

Cyber News, Cyber Threat Trends
  • by
  • October 12, 2023

Malicious NuGet Package Targeting .NET Developers with SeroXen RAT

A malicious package hosted on the NuGet package manager for the .NET Framework has been found to deliver a remote access trojan called SeroXen RAT. The package, named Pathoschild.Stardew.Mod.Build.Config and published by a user named Disti, is a typosquat of a legitimate package called Pathoschild.Stardew.ModBuildConfig, software supply chain security firm Phylum said in a report today. While

Cyber News, Cyber Threat Trends