AmberWolf researchers identified two vulnerabilities, dubbed “NachoVPN,” in popular VPN products SonicWall NetExtender and Palo Alto Networks GlobalProtect, which can be exploited by cyber-attackers to steal login credentials and drop malware. The vulnerabilities were reported and have since been addressed. AmberWolf also released a tool called NachoVPN, which simulates these attacks, aiming to support community contributions and identification of future vulnerabilities.
Bootkitty is the first UEFI Bootkit designed for Linux systems
Cybersecurity researchers from ESET identified the first-ever UEFI bootkit for Linux systems, known as Bootkitty. The bootkit targets the system’s signature verification feature, disabling it