Friday , February 28 2025

Recent Posts

CISA alerts active exploitation of Palo Alto networks vuln

paloalto

CISA has added a patched critical security flaw in Palo Alto Networks Expedition to its Known Exploited Vulnerabilities catalog due to signs of active exploitation. The vulnerability CVE-2024-5910 (CVSS score: 9.3) involves missing authentication in the Expedition migration tool, potentially allowing an admin account takeover. “Palo Alto Expedition contains a …

Read More »

Critical bug in Cisco UWRB access points to run commands as root

cisco

Cisco has fixed a critical vulnerability, CVE-2024-20418, that allowed unauthenticated remote attackers to gain root access on Ultra-Reliable Wireless Backhaul (URWB) access points used in industrial wireless automation. The vulnerability is found in the web management interface of Cisco Unified Industrial Wireless Software for URWB Access Points. The vulnerability lets …

Read More »

“ToxicPanda” banking trojan from Asia hit Europe and LATAM

Icon

In late October 2024, Cleafy’s Threat Intelligence team noticed a surge in a new Android malware known as TgToxic. However, deeper analysis showed that, despite some similarities to TgToxic commands, the code is quite different. Many typical TgToxic features are missing, and some commands are just placeholders. Consequently, the team …

Read More »