Cisco Warns of Exploitation of Decade-Old ASA WebVPN Vulnerability

December 3, 2024 at 08:57AM Cisco has updated its advisory regarding a decade-old vulnerability (CVE-2014-2120) in its Adaptive Security Appliance, which is being actively exploited. The flaw allows cross-site scripting attacks via the WebVPN login page. Users are urged to update their systems as it was added to the CISA’s KEV catalog for urgent remediation. … Read more

Chinese APT Volt Typhoon Linked to Unkillable SOHO Router Botnet 

December 13, 2023 at 12:24PM Malware hunters in the US have uncovered a resilient botnet built from outdated SOHO routers, serving as a covert data transfer network for Chinese government-backed hacker group Volt Typhoon. The botnet spans various sectors, including critical infrastructure organizations. Black Lotus Labs plans to release detailed technical analysis of the threat, … Read more