228Articles
8Categories
2023-07-18Date
πŸ›
Vulnerability impacting FortiGate/FortiOS (CVE-2023-27997) – Update 2
πŸ›
β€œNever Assume Anything” – Unauthenticated Stored Cross-Site Scripting Vulnerability Exposed in 14 Email Logging Plugins
πŸ›
New critical Citrix ADC and Gateway flaw exploited as zero-days
πŸ›
WordPress Sites Hacked via Critical Vulnerability in WooCommerce Payments Plugin
πŸ›
New critical Citrix ADC and Gateway flaw exploited as zero-day
πŸ›
Cybercriminals Exploiting WooCommerce Payments Plugin Flaw to Hijack Websites
πŸ›

Exploit Attempts for "Stagil navigation for Jira Menus & Themes" CVE-2023-26255 and CVE-2023-26256, (Tue, Jul 18th)
πŸ›
Adobe Releases Security Updates for ColdFusion
πŸ›
Citrix Releases Security Updates for NetScaler ADC and Gateway
⚠️
Foundational cyber security actions for small organizations - ITSAP.10.300
⚠️
National Cyber Threat Assessments
⚠️
Istio graduates to top level at CNCF
⚠️
Novel NoEscape ransomware operation believed to be Avaddon rebrand
⚠️
Cisco to acquire Oort for identity security boost
⚠️
Malicious Android apps deployed via WebAPK exploitation
⚠️
Nearly 350 organizations impacted by Cl0p MOVEit hack
⚠️
JumpCloud 'nation state’ phishing attack spotlights third-party risk management
⚠️
Architecting Cloud Instrumentation
⚠️
Implementing an ISO-compliant threat intelligence program
⚠️
Mass attack on WordPress sites targets bug in WooCommerce plugin
⚠️
HTML Attachments Used in Malicious Phishing Campaigns Skyrocket: Increase 168% from 2022 and 450% from 2021
⚠️
Security Alert: Exploit Chain Actively Hits ColdFusion
⚠️
Fostering a More Inclusive Culture to Close the Skills Gap
⚠️
Army Alert on Free Smartwatches: Don't Sport These Wearables
⚠️
CISA orders govt agencies to mitigate Windows and Office zero-days
⚠️
Growing Scam Activity Linked to Social Media and Automation
⚠️
Suspected Scareware Fraudster Arrested After Decade on the Run
⚠️
Patch Adobe ColdFusion zero-days, CISA urges security teams
⚠️
Two New Adobe ColdFusion Vulnerabilities Exploited in Attacks
KEV
⚠️
Number of Victims Breached Via MOVEit Zero-Day Keeps Climbing
⚠️
The tail of the MOVEit hack may be longer than we realize
⚠️
Trail of Bits’s Response to OSTP National Priorities for AI RFI
⚠️
Spanish Police End a Decade on the Run for Ukrainian Hacker
⚠️
US Gov Mercenary Spyware Clampdown Hits Cytrox, Intellexa
⚠️
LeakedSource Owner Quit Ashley Madison a Month Before 2015 Hack
⚠️
VirusTotal Data Leak Exposes Some Registered Customers' Details
⚠️
CISA Releases Seven Industrial Control Systems Advisories
⚠️
Oracle Releases Security Updates
⚠️
Microsoft Inspire: Partner resources to prepare for the future of security with AI
⚠️
Spearphishing Campaign Targets Zimbra Webmail Portals of Government Organizations
πŸ“’
Citrix security advisory (AV23-416)
πŸ“’
SonicWall security advisory (AV23-415)
πŸ“’
Adobe security advisory (AV23-414)
πŸ“’
Dell security advisory (AV23-413)
πŸ“’
IBM security advisory (AV23-412)
πŸ“’
Ubuntu security advisory (AV23-411)
πŸ“’
Microsoft Edge security advisory (AV23-410)
πŸ“’
HPE security advisory (AV23-409)
πŸ“’
[Control systems] BD Alaris security advisory (AV23-408)
πŸ“’
[Control systems] Rockwell Automation security advisory (AV23-407)
πŸ“’
[Control systems] Honeywell security advisory (AV23-406)
πŸ“’
Drupal security advisory (AV23-405)
πŸ“’
Apple security advisory (AV23-404)
πŸ“’
HPE security advisory (AV23-403)
πŸ“’
SonicWall security advisory (AV23-402)
πŸ“’
Juniper Networks security advisory (AV23-401)
πŸ“’
Cisco security advisory (AV23-400)
πŸ“’
[Control systems] Rockwell Automation security advisory (AV23-399)
πŸ“’
Apple security advisory (AV23-398)
πŸ“’
Fortinet security advisory (AV23-397)
πŸ“’
Citrix security advisory (AV23-396)
πŸ“’
Adobe security advisory (AV23-395)
πŸ“’
Microsoft security advisory – July 2023 monthly rollup (AV23-394)
πŸ“’
[Control systems] Panasonic security advisory (AV23-393)
πŸ“’
[Control systems] Sensormatic Electronics security advisory (AV23-392)
πŸ“’
[Control systems] Rockwell Automation security advisory (AV23-391)
πŸ“’
SAP security advisory – July 2023 monthly rollup (AV23-390)
πŸ“’
Mozilla security advisory (AV23-389)
πŸ“’
[Control systems] Schneider Electric security advisory (AV23-388)
πŸ“’
[Control systems] Siemens security advisory (AV23-387)
πŸ“’
Apple security advisory (AV23-386)
πŸ“’
Ubuntu security advisory (AV23-385)
πŸ“’
IBM security advisory (AV23-384)
πŸ“’
Dell security advisory (AV23-383)
πŸ“’
MOVEit Transfer security advisory (AV23-382)
πŸ“’
[Control systems] ABUS security advisory (AV23-381)
πŸ“’
[Control systems] PiiGAB security advisory (AV23-380)
πŸ“’
Android security advisory – July 2023 Monthly Rollup (AV23-379)
πŸ“’
Increased Truebot activity infects U.S. and Canada based networks - Joint Cybersecurity Advisory
πŸ“’
GitLab security advisory (AV23-378)
πŸ“’
Mozilla security advisory (AV23-377)
πŸ“’
Ubuntu security advisory (AV23-376)
πŸ“’
IBM security advisory (AV23-375)
πŸ“’
Dell security advisory (AV23-374)
πŸ“’
Microsoft Edge security advisory (AV23-373)
πŸ“’
[Control systems] Medtronic security advisory (AV23-372)
πŸ“’
[Control systems] Mitsubishi Electric security advisory (AV23-371)
πŸ“’
[Control systems] Schneider Electric security advisory (AV23-370)
πŸ“’
[Control systems] Ovarro security advisory (AV23-369)
πŸ“’
Joint cyber security advisory on Truebot malware
πŸ“’
Top 10 IT security actions: No. 3 managing and controlling administrative privileges - ITSM.10.094
πŸ“’
CSE and international partners publish a cyber security advisory on LockBit ransomware
πŸ“’
NIST announces lightweight cryptography selection
πŸ“’
CSE and its Canadian Centre for Cyber Security release advisory on People's Republic of China state-sponsored cyber threat
πŸ“’
Statement from the Minister of National Defence – Cyber Threats to Critical Infrastructure
πŸ“’
Citrix security advisory (AV23-416)
πŸ“’
BreachForums' Admin Pleads Guilty, Faces 40 Years in Prison
πŸ“’
ENISA: Cybersecurity Aspects in the Maritime Sector
πŸ“’
ENISA: Guidelines on Incident Reporting
πŸ“’
ENISA: Technical Guidelines on Minimum Security Measures
πŸ“’
ENISA Launches Information Security Awareness Videos
πŸ“’
White House Unveils Consumer Labeling Program to Strengthen IoT Security
πŸ“’
[Control systems] GE Digital security advisory (AV23-417)
πŸ“’
[Control systems] Iagona security advisory (AV23-418)
πŸ“’
[Control systems] GE Digital security advisory (AV23-417)
πŸ“’
[Control systems] Rockwell Automation security advisory (AV23-419)
πŸ“’
[Control systems] Keysight security advisory (AV23-422)
πŸ“’
[Control systems] GeoVision security advisory (AV23-421)
πŸ“’
[Control systems] WellinTech security advisory (AV23-420)
πŸ“’
[Control systems] GeoVision security advisory (AV23-421)
πŸ“’
[Control systems] Keysight security advisory (AV23-422)
πŸ“’
[Control systems] WellinTech security advisory (AV23-420)
πŸ“’
[Control systems] Iagona security advisory (AV23-418)
πŸ“’
[Control systems] Rockwell Automation security advisory (AV23-419)
πŸ“’
NSA, CISA Issue Guidance on 5G Network Slicing Security
πŸ“’
International Engagement – Brussels and Beyond
πŸ“’
International Engagement – Brussels and Beyond
πŸ”₯
Steps for effectively deploying multi-factor authentication (MFA) - ITSAP.00.105
πŸ”₯
Defending against data exfiltration threats - ITSM.40.110
πŸ”₯
Separate ransomware attacks take toll on Wisconsin, California cities
πŸ”₯
Insights on bolstering healthcare incident response with AI detailed
πŸ”₯
JumpCloud attributes breach to nation-state threat operation
πŸ”₯
Live EMEA Webinar | Where Did the Hackers Go? They Ran(somware): Insights into Ransomware Recovery
πŸ”₯
Application Security Testing vs. API Security Testing
πŸ”₯
FIN8 deploys ALPHV ransomware using Sardonic malware variant
πŸ”₯
Google Cloud Build bug lets hackers launch supply chain attacks
πŸ”₯
UK: IT Worker Jailed for Impersonating Ransomware Gang to Extort Employer
πŸ”₯
Update: UKG Agrees to Pay Up to $6M in Lawsuit Tied to 2021 Breach
πŸ”₯
Black Hat Hacker Exposes Real Identity After Infecting Own Computer With Malware
πŸ”₯
Phoenician Medical Center Cyberattack Affects Up to 162,500 Patients
πŸ”₯
Dating App That Claims 50 Million Users Suffered a Data Breach
πŸ”₯
FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware
πŸ”₯
Cybersecurity firm Sophos impersonated by new SophosEncrypt ransomware
πŸ”₯
Netcraft Snags $100M, Names Former DigiCert Executive as CEO
πŸ”₯
Sophos Discovers Ransomware Abusing β€œSophos” Name
πŸ”₯
Sophos Discovers Ransomware Abusing β€œSophos” Name
πŸ”₯
Utility Experts Highlight Chinese Threat to US Electric Grid
πŸ”₯
Pakistani Entities Targeted in Sophisticated Attack Deploying ShadowPad Malware
πŸ”₯
Go Beyond the Headlines for Deeper Dives into the Cybercriminal Underground
πŸ”₯
FIN8 Group Using Modified Sardonic Backdoor for BlackCat Ransomware Attacks
πŸ”₯
Owner of BreachForums Pleads Guilty to Cybercrime and Child Pornography Charges
πŸ”₯
JumpCloud Blames 'Sophisticated Nation-State' Actor for Security Breach
πŸ”₯
Roblox Developer Conference - 3,943 breached accounts
πŸ•΅οΈ
Disabling Self-Driving Cars with a Traffic Cone
πŸ•΅οΈ
Best practices for setting up a security operations centre (SOC) - ITSAP.00.500
πŸ•΅οΈ
Sophos Firewall Receives the 2023 Competitive Strategy Leadership Award
πŸ•΅οΈ
SaaS Management tool by Auvik launches
πŸ•΅οΈ
Cisco rolls out speedier Secure Network Analytics version
πŸ•΅οΈ
Inadvertent leak of millions of US military emails to Mali reported
πŸ•΅οΈ
New Russian RedCurl attacks detailed
πŸ•΅οΈ
SaaS security startup Savvy emerges from stealth
πŸ•΅οΈ
Protect yourself from ticketing scams ahead of the Premier League Summer Series USA Tour
πŸ•΅οΈ
Protect Your Systems from Malicious Packages: What You Need to Know
πŸ•΅οΈ
A Look at the Email Threat Landscape in Q1 2023
πŸ•΅οΈ
Exposure Management: Best Practices for Getting Ahead of Cyber Risk
πŸ•΅οΈ
WormGPT: How GPT's Evil Twin Could Be Used in BEC Attacks
πŸ•΅οΈ
BlotchyQuasar RAT Targets Users in LATAM Region
πŸ•΅οΈ
China Raises Cybersecurity Barriers to Tech Investments
πŸ•΅οΈ
OT Security Is More Than Just Cybersecurity
πŸ•΅οΈ
Gamaredon APT Steals Data Within an Hour
πŸ•΅οΈ
Nigerian Man Sentenced to 8 Years in US Prison for $8 Million BEC Scheme
πŸ•΅οΈ
Black Hat Hacker Exposes Real Identity After Infecting Own Computer With Malware
πŸ•΅οΈ
White House Unveils Cybersecurity Labeling Program for Smart Devices
πŸ•΅οΈ
Hacker Conversations: Inside the Mind of Daniel Kelley, ex-Blackhat
πŸ•΅οΈ
Netcraft Raises $100M, Hires New CEO for Global Expansion
πŸ•΅οΈ
Norway Threatens $100,000 Daily Fine on Meta Over Data
πŸ•΅οΈ
Why Bitcoin Is No Longer Cybercriminals' Currency of Choice
πŸ•΅οΈ
ISC Stormcast For Tuesday, July 18th, 2023 https://isc.sans.edu/podcastdetail/8576, (Tue, Jul 18th)
🌐
The cyber threat to Canada’s oil and gas sector
🌐
Learning Hub
🌐
The cyber threat from supply chains
🌐
Protecting your organization from software supply chain threats – ITSM.10.071
🌐
Federal partners remind Canadian consumers to be vigilant for cyber threats this Black Friday and Cyber Monday
🌐
VirusTotal Data Leak Exposes Some Registered Customers' Details
πŸŽ™οΈ
MDM: Balancing the Need for User Privacy, Corporate Control
πŸŽ™οΈ
Navigating the Complexities of Cyber Insurance
πŸ“‘
Leading the Way with Radical Transparency
πŸ“‘
Generative artificial intelligence (AI) - ITSAP.00.041
πŸ“‘
Quality manual v4.2
πŸ“‘
Products in evaluation
πŸ“‘
CSE urges the Canadian cyber security community to adopt a heightened state of vigilance
πŸ“‘
Cloud network security zones - ITSP.80.023
πŸ“‘
GeekWeek 8
πŸ“‘
About the Cyber Centre
πŸ“‘
Top 10 IT security actions: No. 5 segment and separate information – ITSM.10.092
πŸ“‘
Device security for travel and telework abroad - ITSAP.00.188
πŸ“‘
Certified products
πŸ“‘
Academic Outreach and Cyber Skills Development
πŸ“‘
Common Criteria
πŸ“‘
Canadian Common Criteria program requirements and procedures for testing laboratories
πŸ“‘
Using information technology asset management (ITAM) to enhance cyber security – ITSM.10.004
πŸ“‘
Joint publication on cyber security best practices for smart cities
πŸ“‘
Communications Security Establishment (CSE) and international partners publish joint guide on secure-by-design and -default principles
πŸ“‘
A zero trust approach to security architecture - ITSM.10.008
πŸ“‘
Top 10 IT security actions: No. 9 Isolate web-facing applications - ITSM.10.099
πŸ“‘
Obsolete products - ITSAP.00.095
πŸ“‘
Cyber security guide for campaign teams
πŸ“‘
Satellite communications - ITSAP.80.029
πŸ“‘
Use of personal social media in the workplace - ITSAP.00.066
πŸ“‘
CSE urges the Canadian cyber security community to adopt a heightened state of vigilance after one-year mark of Russia’s full-scale invasion of Ukraine
πŸ“‘
Top 10 IT security actions – No. 7 protect information at the enterprise level - ITSM.10.097
πŸ“‘
Cryptocurrency - ITSAP.00.650
πŸ“‘
Protect how you connect
πŸ“‘
Connected communities - ITSAP.00.222
πŸ“‘
Network security logging and monitoring - ITSAP.80.085
πŸ“‘
Network security auditing - ITSAP.80.086
πŸ“‘
Data transfer and upload protection - ITSAP.40.212
πŸ“‘
Certifications in the field of cyber security
πŸ“‘
Course 104: IT security risk management: A lifecycle approach (ITSG-33)
πŸ“‘
Zero Trust security model - ITSAP.10.008
πŸ“‘
Security considerations for exposure of classified IT systems to mobile devices and wireless signals - ITSB-104
πŸ“‘
Sophos Firewall Receives the 2023 Competitive Strategy Leadership Award
πŸ“‘
Webinar | The Role of Resilience in Reducing Burnout: A Cybersecurity Discussion About People
πŸ“‘
OnDemand EU Webinar | Generative AI, Cybersecurity Friend or Foe?
πŸ“‘
Security Awareness Matters: How to Build Awareness that Transforms Culture and Reduces Risk
πŸ“‘
The Surveillance Society and Digital Freedom
πŸ“‘
Critical Vendor Risk Considerations for AI Use in Healthcare
πŸ“‘
Leveraging Usage-Based Licensing
πŸ“‘
Who Should Pay for Payment Scams - Banks, Telcos, Big Tech?
πŸ“‘
Strengthening Password Security may Lower Cyber Insurance Premiums
πŸ“‘
Microsoft Exchange Online hit by new outage blocking emails
πŸ“‘
drIBAN Fraud Operations Target Corporate Banking Customers
πŸ“‘
'Millions of emails' for US military sent to .ml addresses
πŸ“‘
Netcraft Raises $100M, Hires New CEO for Global Expansion
πŸ“‘
President Xi Wants to Make the Great Firewall of China Even Greater
πŸ“‘
U.S. preparing Cyber Trust Mark for more secure smart devices
πŸ“‘
The XDR Payoff: Better Security Posture
πŸ“‘
Protect yourself from ticketing scams ahead of the Premier League Summer Series USA Tour