84Articles
9Categories
2023-08-02Date
🚨
2022 Top Routinely Exploited VulnerabilitiesSUMMARY The following cybersecurity agencies coauthored this joint Cybersecurity Advisory (CSA): United States: The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) Australia: Australian Signals Dir…
KEV
🐛
Ivanti Zero-Day Exploited by APT Since at Least April in Norwegian Government Attack
🐛
CISA Published a Warning About Ivanti EPMM Zero-day Vulnerabilities
🐛
Firefox Fixes a Flurry of Flaws in the First of Two Releases This Month
🐛
Over 640 Citrix servers backdoored with web shells in ongoing attacks
⚠️
Norwegian Entities Targeted in Ongoing Attacks Exploiting Ivanti EPMM Vulnerability
⚠️
CISA and NCSC-NO Release Joint Cybersecurity Advisory on Threat Actors Exploiting Ivanti EPMM Vulnerabilities
⚠️
Socket Lands $20M Investment to Help Companies Secure Open Source Software
⚠️
New Collide+Power Exploit Let Attacker Steal Sensitive Data From All Modern CPUs
⚠️
Researchers Uncover AWS SSM Agent Misuse as a Covert Remote Access Trojan
⚠️
Firefox 116 Patches High-Severity Vulnerabilities
⚠️
Hackers exploited Salesforce zero-day in Facebook phishing attack
⚠️
Cyberattack on Montclair Township Led to $450K Settlement
⚠️
Industrial Control Systems Vulnerabilities Soar: Over One-Third Unpatched in 2023
⚠️
Phishers Exploit Salesforce's Email Services Zero-Day in Targeted Facebook Campaign
⚠️
Beware! Hacker-Sold macOS HVNC Tool Allows Complete Takeover
KEV
⚠️
Mozilla Releases Security Updates for Firefox and Firefox ESR
⚠️
Nile, Which Offers Enterprise Networks as a Service, Raises $175M
⚠️
Amazon's AWS SSM agent can be used as post-exploitation RAT malware
⚠️
Millions Stolen From Crypto Platforms Through Exploited ‘Vyper’ Vulnerability
⚠️
Researchers Uncover AWS SSM Agent Misuse as a Covert Remote Access Trojan
⚠️
Expel: Firms Still Threatened by Old Vulnerabilities
⚠️
Tenable CEO Slams Microsoft for Failing to Quickly Patch Bug
⚠️
Ivanti discloses new critical auth bypass bug in MobileIron Core
⚠️
Ivanti Norway Hacks Began in April, Says US CISA
⚠️
Performance and security clash yet again in “Collide+Power” attack
⚠️
“PhishForce” — Vulnerability Uncovered in Salesforce’s Email Services Exploited for Phishing Facebook Accounts In-The-Wild
📋
Cloud Tech Debt Puts Millions of Apps at Risk, Says New Report
📢
Cyber Security Today, August 2, 2023 - A valuable report from the CISA
📢
UK Military Embraces Security by Design
📢
HPE security advisory (AV23-455)
📢
Possible Chinese Malware in US Systems a ‘Ticking Time Bomb’: Report
📢
Mitel security advisory (AV23-456)
📢
KnowBe4 Chooses Drata as Their Exclusive GRC Partner
📢
F5 security advisory (AV23-457)
🔥
Data Breach Reported in Arizona’s School Voucher Program
🔥
Hot Topic hit by wave of cyber attacks
🔥
New SEC Rules around Cybersecurity Incident Disclosures
🔥
Chattanooga Heart Institute Notifies 170,000 of Hacking, Data Breach
🔥
Study Downplays Cyber Insurance as Incentive to Pay Ransom
🔥
Kazakhstan Refuses to Extradite Detained Russian Cyber Expert to Us
🔥
Bad Actor Uses Fake Android Chat to Install Malware
🔥
Cloudzy With a Chance of Global Cybercrime
🔥
Retail Chain Hot Topic Discloses Wave of Credential-Stuffing Attacks
🔥
Privacy Watchdog Slams Sharing of Patient Data Via WhatsApp
🔥
Slack down: Outage causing connection errors, blurry images
🔥
The Urgent Need For Cyber Resilience in Healthcare
🔥
Class Action Attorneys Circling Major Healthcare Breaches
🔥
MagicDuel - 138,443 breached accounts
🕵️
ISC Stormcast For Wednesday, August 2nd, 2023 https://isc.sans.edu/podcastdetail/8598, (Wed, Aug 2nd)
🕵️
Iranian Company Cloudzy Accused of Aiding Cybercriminals and Nation-State Hackers
🕵️
New Infostealer Uncovered in Phishing Scam Targeting Facebook Business Accounts
🕵️
Threat Actors Abuse Google AMP for Evasive Phishing Attacks
🕵️
US Internet Hosting Company Appears to Facilitate Global Cybercrime, Researchers Say
🕵️
Newly Discovered WikiLoader Malware Used to Install Ursnif Trojan
🕵️
Top Industries Significantly Impacted by Illicit Telegram Networks
🕵️
Google AMP Abused in Phishing Attacks Aimed at Enterprise Users
🕵️
Russian Cyber Adversary BlueCharlie Alters Infrastructure in Response to Disclosures
🕵️
New hVNC macOS Malware Advertised on Hacker Forum
🕵️
Cyble Raises $24 Million for AI-Powered Threat Intelligence Platform
🕵️
Users of Facebook for Business are the Target of a New Phishing Attack
🕵️
Researchers Uncovered a New Flaw in ChatGPT to Turn Them Evil
🕵️
Shield and Visibility Solutions Target Phishing From Inside the Browser
🕵️
Malware Campaign Targets Eastern European Air-Gapped Systems
🕵️
Russian hackers target govt orgs in Microsoft Teams phishing attacks
🕵️
Microsoft Catches Russian Government Hackers Phishing with Teams Chat App
🕵️
Midnight Blizzard conducts targeted social engineering over Microsoft Teams
🌐
OT/IoT Malware Surges Tenfold in First Half of the Year
📡
Zeek and Defender Endpoint, (Wed, Aug 2nd)
📡
UK: NHS Staff Reprimanded for WhatsApp Data Sharing
📡
Meow Attack Campaign Evolves to Target Jupyter Notebooks
📡
Forgepoint Capital Places $15M Series A Bet on Converge Insurance
📡
Silk Security Emerges from Stealth With $12.5 Million Seed Funding
📡
Sha zhu pan scam uses AI chat tool to target iPhone and Android users
📡
Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack
📡
Why Every Security Practitioner Should Attend mWISE
📡
Lawsuit Alleges Bytedance’s Capcut App Secretly Reaps Massive Amounts of User Data
📡
The Most Important Part of the Internet You’ve Probably Never Heard Of
📡
The Gap in Users’ Identity Security Knowledge Gives Cybercriminals an Opening
📡
New Collide+Power side-channel attack impacts almost all CPUs
📡
Fake FlipperZero sites promise free devices after completing offer
📡
Tech Consolidation – How and When?
📡
How to set up privacy and security in Threads | Kaspersky official blog
📡
The grand theft of Jake Moore’s voice: The concept of a virtual kidnap