99Articles
7Categories
2023-07-21Date
πŸ›
P2PInfect Worm: A Stealthy Cross-Platform Threat Targeting Redis Servers
πŸ›
Adobe Releases New Patches for Exploited ColdFusion Vulnerabilities
KEV
πŸ›
New AMI BMC Flaws Allowing Takeover and Physical Damage Could Impact Millions of Devices
πŸ›
Citrix Zero-Day Exploited Against Critical Infrastructure Organization
πŸ›
Citrix Zero-Day Exploited Against Critical Infrastructure Organization
πŸ›
CISA: Citrix RCE bug exploited to breach critical infrastructure org
πŸ›
Netscaler ADC bug exploited to breach US critical infrastructure org
πŸ›
Threat Actors exploiting Citrix CVE-2023-3519 to implant webshells - CISA cybersecurity advisory
πŸ›
Atlassian Releases Security Updates
πŸ›
CVE-2023-24881 Microsoft Teams Information Disclosure Vulnerability
πŸ›
CVE-2023-33151 Microsoft Outlook Spoofing Vulnerability
πŸ›
CVE-2023-38173 Microsoft Edge for Android Spoofing Vulnerability
πŸ›
CVE-2023-35311 Microsoft Outlook Security Feature Bypass Vulnerability
πŸ›
CVE-2023-35392 Microsoft Edge (Chromium-based) Spoofing Vulnerability
πŸ›
CVE-2023-38187 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
πŸ›
Chromium: CVE-2023-3727 Use after free in WebRTC
πŸ›
Chromium: CVE-2023-3728 Use after free in WebRTC
πŸ›
Chromium: CVE-2023-3730 Use after free in Tab Groups
πŸ›
Chromium: CVE-2023-3732 Out of bounds memory access in Mojo
πŸ›
Chromium: CVE-2023-3733 Inappropriate implementation in WebApp Installs
πŸ›
Chromium: CVE-2023-3734 Inappropriate implementation in Picture In Picture
πŸ›
Chromium: CVE-2023-3735 Inappropriate implementation in Web API Permission Prompts
πŸ›
Chromium: CVE-2023-3736 Inappropriate implementation in Custom Tabs
πŸ›
Chromium: CVE-2023-3737 Inappropriate implementation in Notifications
πŸ›
Chromium: CVE-2023-3738 Inappropriate implementation in Autofill
πŸ›
Chromium: CVE-2023-3740 Insufficient validation of untrusted input in Themes
πŸ›
CVE-2023-21531 Azure Service Fabric Container Elevation of Privilege Vulnerability
πŸ›
CVE-2021-27075 Azure Virtual Machine Information Disclosure Vulnerability
⚠️
The case for phishing-resistant MFA
⚠️
Android SpyNote attacks electric and water public utility users in Japan
⚠️
LLMs and AI positioned to dominate the AppSec world
⚠️
AI and Microdirectives
⚠️
Android Spyware WyrmSpy and DragonEgg Attributed to APT41
⚠️
OpenMeetings Flaws Allow Hackers to Hijack Instances, Execute Code on Servers
⚠️
Mallox Ransomware Activity Surges by 174%
⚠️
Apache OpenMeetings Web Conferencing Tool Exposed to Critical Vulnerabilities
⚠️
HotRat as Hidden Script in Cracked Software
⚠️
Multiple Vulnerabilities in Mozilla Thunderbird Could Allow for Arbitrary Code Execution
⚠️
Local Governments Targeted for Ransomware – How to Prevent Falling Victim
⚠️
DDoS Botnets Hijacking Zyxel Devices to Launch Devastating Attacks
⚠️
Citrix NetScaler ADC and Gateway Devices Under Attack: CISA Urges Immediate Action
⚠️
Victims sue US healthcare network for breach of patient data. Multiple blanks impacted in MOVEit data breaches. A closer look at Cl0p.
πŸ“’
Update: Cyberattack on Github Customers Linked to North Korean Hackers, Microsoft Says
πŸ“’
Evolving CDM to Transform Government Cybersecurity Operations and Enable CISA’s Approach to Interactive Cyber Defense
πŸ“’
Navigating NIS2 Compliance: Key Considerations for UKI Organisations in the Evolving Cybersecurity Landscape
πŸ”₯
IOTW: Estee Lauder data stolen in cyber attack
πŸ”₯
JumpCloud Blames North Korean Hackers for Breach
πŸ”₯
FakeSG: A SocGholish Competitor Delivers NetSupport RAT
πŸ”₯
UK: Most CNI Firms Think Climate Tech is Increasing Cyber Risk
πŸ”₯
Threat Group Assessment: Mallox Ransomware
πŸ”₯
Tampa General Hospital Says Patient Information Stolen in Ransomware Attack
πŸ”₯
Exploring the Macro Shifts in Enterprise Security
πŸ”₯
Update: Chinese Hackers Breached Ambassador’s Email According to New Report
πŸ”₯
Pro-Russian Hacktivists Attributed to the Surge in DDoS Attacks in Q2
πŸ”₯
Sophisticated BundleBot Malware Disguised as Google AI Chatbot and Utilities
πŸ”₯
Clop gang to earn over $75 million from MOVEit extortion attacks
πŸ”₯
Count of Organizations Breached via MOVEit Campaign Hits 400
πŸ”₯
Cyber Security Today, Week in Review for Friday, July 21, 2023
πŸ”₯
Florida Hospital Says Data Theft Attack Affects 1.2 Million
πŸ”₯
The Week in Ransomware - July 21st 2023 - Avaddon Back as NoEscape
πŸ”₯
Stolen Azure AD key offered widespread access to Microsoft cloud services
πŸ”₯
Stolen Microsoft key offered widespread access to Microsoft cloud services
πŸ”₯
Few Fortune 100 Firms List Security Pros in Their Executive Ranks
πŸ”₯
Sophisticated BundleBot Malware Disguised as Google AI Chatbot and Utilities
πŸ•΅οΈ
Shodan's API For The (Recon) Win!, (Fri, Jul 21st)
πŸ•΅οΈ
ISC Stormcast For Friday, July 21st, 2023 https://isc.sans.edu/podcastdetail/8582, (Fri, Jul 21st)
πŸ•΅οΈ
Update: Attacker Infrastructure Links JumpCloud Intrusion to North Korean APT Activity
πŸ•΅οΈ
Tech Titans Promise Watermarks to Expose AI Creations
πŸ•΅οΈ
GitHub Warns of North Korean Social Engineering Attacks Targeting Tech Firm Employees
πŸ•΅οΈ
VirusTotal Provides Clarifications on Data Leak Affecting Premium Accounts
πŸ•΅οΈ
In Other News: Military Emails Leaked, Google Restricts Internet Access, Chinese Spyware
πŸ•΅οΈ
Russia Seeks 18 Years in Jail for Founder of Cybersecurity Firm
πŸ•΅οΈ
Google Creates Red Team to Test Attacks Against AI Systems
πŸ•΅οΈ
Merck's Success Story: Boosting Efficiency With RPA and Bots
πŸ•΅οΈ
Microsoft Cloud Hack Exposed More than Exchange, Outlook Emails
πŸ•΅οΈ
JumpCloud Hackers Likely Targeting GitHub Accounts Too
πŸ•΅οΈ
ISMG Editors: Microsoft's Move to Expand Logging Access
πŸ•΅οΈ
7 Tech Firms Pledge to White House to Make AI Safe, Secure
πŸ•΅οΈ
Friday Squid Blogging: Chromatophores
πŸ•΅οΈ
Weekly Update 357
KEV
πŸ•΅οΈ
Azure AD Token Forging Technique in Microsoft Attack Extends Beyond Outlook, Wiz Reports
πŸ•΅οΈ
HotRat: New Variant of AsyncRAT Malware Spreading Through Pirated Software
πŸ•΅οΈ
ISC Stormcast For Friday, July 21st, 2023 https://isc.sans.edu/podcastdetail/8582, (Fri, Jul 21st)
🌐
Report: DDoS Attacks, Growing More Sophisticated, Surged in Q2
🌐
Cyber Security Today, July 21, 2023 - MOVEit victim numbers climb higher, news on spyware, and more
🌐
Android SpyNote Attacks Electric and Water Public Utility Users in Japan
🌐
HotRat: New Variant of AsyncRAT Malware Spreading Through Pirated Software
πŸ“‘
Report: Microsoft the Most Phished Brand in Q2 2023
πŸ“‘
VirusTotal apologizes for data leak affecting 5,600 customers
πŸ“‘
Report: 67% of Daily Security Alerts Overwhelm SOC Analysts
πŸ“‘
Critical API Security Gaps Found in Financial Services
πŸ“‘
Amazon agrees to $25 million fine for Alexa children privacy violations
πŸ“‘
Suzuki Dealership Websites in Brazil and Bahrain Leave Credentials, Secret Tokens Exposed
πŸ“‘
Amazon Agrees to $25 Million Fine for Alexa Children Privacy Violations
πŸ“‘
Take the First Steps Towards Better Cybersecurity With these Four Goals
πŸ“‘
Shodan's API For The (Recon) Win!, (Fri, Jul 21st)
πŸ“‘
What happens if AI is wrong? – Week in security with Tony Anscombe
πŸ“‘
Sensor Intel Series: Top CVEs in June 2023
πŸ“‘
Sensor Intel Series: Top CVEs in June 2023