company logo

Product

Our Product

We are Reshaping the way Developers find and fix vulnerabilities before they get exploited.

Solutions

By Industry

BFSI

Healthcare

Education

IT & Telecom

Government

By Role

CISO

Application Security Engineer

DevsecOps Engineer

IT Manager

Resources

Resource Library

Get actionable insight straight from our threat Intel lab to keep you informed about the ever-changing Threat landscape.

Subscribe to Our Weekly Threat Digest

Company

Contact Us

Have queries, feedback or prospects? Get in touch and we shall be with you shortly.

loading..

Recently discovered NPM malware poses as a legitimate Javascript library but lau...

loading..

Google TAG discloses a two-year-old phishing campaign actively targeting the cha...

loading..

Intel SGX vulnerability can be exploited with a new 'SmashEx' attack that allows...

Loading...

Cryptomining

NPM

Javascript

NPM Packages disguise as Javascript libraries to launch Cryptominers

Recently discovered NPM malware poses as a legitimate Javascript library but launches cryptocurrency miners in Windows, macOS, & Linux machines. ...

  21-Oct-2021
  2 min read
Loading...

Cookie Stealer

YouTube

Phishing

YouTubers at stake, following the discovery of two years old Phishing campaign, ...

Google TAG discloses a two-year-old phishing campaign actively targeting the channels of YouTube creators using a cookie stealing malware, later sold to the highest bidder or used for cryptocurrency scams......

  21-Oct-2021
  3 min read
Loading...

Intel SGX

SmashEx

Intel SGX vulnerable to a new 'SmashEx' Attack that leads to privilege escalatio...

Intel SGX vulnerability can be exploited with a new 'SmashEx' attack that allows privilege escalation and discloses arbitrary memory in enclaves......

  21-Oct-2021
  2 min read
Loading...

XSLeak Vulnerability

Slack

Slack has no plans to patch the exploitable XSLeak Vulnerability to de-anonymize...

Slack's XSLeak vulnerability in its file-sharing functionality can allow threat actors to de-anonymize workspace members; Slack does not plan to release a fix for it... ...

  20-Oct-2021
  2 min read
Loading...

FlawedGrace

TA505

RAT

TA505 resurfaces with new tools to deliver updated FlawedGrace RAT

TA505 campaigns have returned to distributing tens to hundreds of thousands malicious emails targetting German-speaking countries, now uses additional loaders to deliver the FlawedGrace RAT......

  20-Oct-2021
  5 min read
Loading...

Botnet

PurpleFox

WebSocket

PurpleFox deploys new backdoor that leverages WebSockets for C&C communication

PurpleFox botnet now has an updated arsenal with a new backdoor that uses WebSockets for C&C communication...

  20-Oct-2021
  3 min read
Loading...

NEMTY

KARMA

NEFILM

Karma Ransomware, a newly evolving group derived from NEMTY

Analysis by Sentinel labs observed that KARMA Ransomware Group has similarities with other malware families such as NEMTY & JSWorm...

  19-Oct-2021
  3 min read
Loading...

Argentina

RENAPER

Data Breach

RENAPER database breached by threat actors, intends to publicize over the intern...

Argentinian Government Database that stores the ID card details of citizens has been stolen following a data breach and currently being sold online over private portals... ...

  19-Oct-2021
  2 min read
Loading...

HRS

Node.js

Node.Js releases security patch for two HTTP REQUEST SMUGGLING (HRS) VULNERABILI...

NODE.JS has released an update for HRS Vulnerabilities that arise due to space in headers and incorrect parsing of chunk extensions...

  19-Oct-2021
  2 min read
Loading...

Backdoor

Harvester

Telecommunication

Harvester, a state-sponsored group, deploys custom malware targeting telcos & IT...

State-sponsored threat groups target telecom & IT organizations across South Asia by deploying a custom toolset on victims machines...

  19-Oct-2021
  3 min read