Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware – OfficialSarkar

Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware – OfficialSarkar

The Lazarus Group, an infamous threat actor linked to the Democratic People’s Republic of Korea (DPRK), has been observed leveraging a “complex infection chain” targeting at least two employees belonging to an unnamed nuclear-related organization within the span of one month in January 2024. The attacks, which culminated in the deployment of a new modular…

Indian Army DG EME Group C Offline Form 2024 [Career]

Indian Army DG EME Group C Offline Form 2024 [Career]

Indian Army DG EME Group C Recruitment 2024 Author: government examination team tag: 10th/12th/ITI/Diploma Jobs brief information: Directorate General of Electronics and Mechanical Engineers (DG EME) Notification has been issued for the recruitment of Group C posts in various Army Base Workshops and Static Workshops in India. This recruitment has been issued for 625 posts….

Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation – OfficialSarkar

Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation – OfficialSarkar

Dec 20, 2024Ravie LakshmananFirewall Security / Vulnerability Sophos has released hotfixes to address three security flaws in Sophos Firewall products that could be exploited to achieve remote code execution and allow privileged system access under certain conditions. Of the three, two are rated Critical in severity. There is currently no evidence that the shortcomings have…

Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack – OfficialSarkar

Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack – OfficialSarkar

Dec 20, 2024Ravie LakshmananMalware / Supply Chain Attack The developers of Rspack have revealed that two of their npm packages, @rspack/core and @rspack/cli, were compromised in a software supply chain attack that allowed a malicious actor to publish malicious versions to the official package registry with cryptocurrency mining malware. Following the discovery, versions 1.1.7 of…

Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools – OfficialSarkar

Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools – OfficialSarkar

Dec 20, 2024Ravie LakshmananVulnerability / Cyber Attack A now-patched critical security flaw impacting Fortinet FortiClient EMS is being exploited by malicious actors as part of a cyber campaign that installed remote desktop software such as AnyDesk and ScreenConnect. The vulnerability in question is CVE-2023-48788 (CVSS score: 9.3), an SQL injection bug that allows attackers to…

IIT Mandi Junior Assistant Recruitment 2024 Out Apply for 22 Posts [Career]

You are here > Government Result » IIT Mandi Junior Assistant Online Form 2024 – Last Date Today Post date: 20 December 2024 10:31 am brief information: Indian Institute of Technology (IIT) Mandi has released the notification for the post of Junior Assistant. This recruitment has been issued for 22 posts. The online application process…

CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List – OfficialSarkar

CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List – OfficialSarkar

Dec 20, 2024Ravie LakshmananCISA / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2024-12356 (CVSS score: 9.8),…

10+2 -B.Tech Cadet Entry July 2025 Notification Out [Career]

10+2 -B.Tech Cadet Entry July 2025 Notification Out [Career]

You are here > Sarkari Result » Indian Navy 10+2 B.Tech Cadet Admission July 2025 Online Form – Last Date Today Post date: 20 December 2024 10:36 am brief information: join indian navy has recently invited applications for 10+2 B.Tech Cadet Entry July 2025. This recruitment has been issued for 36 posts. Candidates can also…

Thousands Download Malicious npm Libraries Impersonating Legitimate Tools – OfficialSarkar

Thousands Download Malicious npm Libraries Impersonating Legitimate Tools – OfficialSarkar

Dec 19, 2024Ravie LakshmananSupply Chain / Software Security Threat actors have been observed uploading malicious typosquats of legitimate npm packages such as typescript-eslint and @types/node that have racked up thousands of downloads on the package registry. The counterfeit versions, named @typescript_eslinter/eslint and types-node, are engineered to download a trojan and retrieve second-stage payloads, respectively. “While…