A critical Cross-Site Scripting (XSS) vulnerability, CVE-2024-57004, has been found in Roundcube Webmail version 1.6.9, allowing remote authenticated users to upload malicious files as email attachments. This flaw can lead to data theft, account compromise, and malware propagation. Users are advised to upgrade to version 1.6.10, which includes a patch for stricter input validation and security measures.
Threefold Increase in Malware Targeting Credential Stores
Cybersecurity provider, Picus Security’s recent Red Report revealed that infostealers, malware that targets credential stores, have spiked in use, reflecting an increased market for compromised