194Articles
9Categories
2023-08-08Date
๐Ÿ›
Update: All Versions of Ivanti Product Affected by Vulnerability Used in Norway Government Attack
๐Ÿ›
CVE-2023-29328 Microsoft Teams Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-29330 Microsoft Teams Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-35359 Windows Kernel Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-35368 Microsoft Exchange Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36865 Microsoft Office Visio Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36866 Microsoft Office Visio Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36869 Azure DevOps Server Spoofing Vulnerability
๐Ÿ›
CVE-2023-36873 .NET Framework Spoofing Vulnerability
๐Ÿ›
CVE-2023-36876 Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36882 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36889 Windows Group Policy Security Feature Bypass Vulnerability
๐Ÿ›
CVE-2023-36898 Tablet Windows User Interface Application Core Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36899 ASP.NET Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36900 Windows Common Log File System Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36903 Windows System Assessment Tool Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36904 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36905 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36906 Windows Cryptographic Services Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36907 Windows Cryptographic Services Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36908 Windows Hyper-V Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36909 Microsoft Message Queuing Denial of Service Vulnerability
๐Ÿ›
CVE-2023-36910 Microsoft Message Queuing Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36911 Microsoft Message Queuing Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36912 Microsoft Message Queuing Denial of Service Vulnerability
๐Ÿ›
CVE-2023-36913 Microsoft Message Queuing Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36914 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability
๐Ÿ›
CVE-2023-35376 Microsoft Message Queuing Denial of Service Vulnerability
๐Ÿ›
CVE-2023-38254 Microsoft Message Queuing Denial of Service Vulnerability
๐Ÿ›
CVE-2023-35377 Microsoft Message Queuing Denial of Service Vulnerability
๐Ÿ›
CVE-2023-35378 Windows Projected File System Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-35379 Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-35380 Windows Kernel Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-35381 Windows Fax Service Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-35382 Windows Kernel Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-35383 Microsoft Message Queuing Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-35384 Windows HTML Platforms Security Feature Bypass Vulnerability
๐Ÿ›
CVE-2023-35385 Microsoft Message Queuing Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-35386 Windows Kernel Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-35387 Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-35389 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-35393 Azure Apache Hive Spoofing Vulnerability
๐Ÿ›
CVE-2023-35394 Azure HDInsight Jupyter Notebook Spoofing Vulnerability
๐Ÿ›
CVE-2023-38188 Azure Apache Hadoop Spoofing Vulnerability
๐Ÿ›
CVE-2023-38186 Windows Mobile Device Management Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38185 Microsoft Exchange Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-38184 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-38175 Microsoft Windows Defender Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38172 Microsoft Message Queuing Denial of Service Vulnerability
๐Ÿ›
CVE-2023-38170 HEVC Video Extensions Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-38169 Microsoft OLE DB Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-38167 Microsoft Dynamics Business Central Elevation Of Privilege Vulnerability
๐Ÿ›
CVE-2023-21709 Microsoft Exchange Server Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-35371 Microsoft Office Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-35372 Microsoft Office Visio Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36877 Azure Apache Oozie Spoofing Vulnerability
๐Ÿ›
CVE-2023-36881 Azure Apache Ambariย Spoofing Vulnerability
๐Ÿ›
CVE-2023-36890 Microsoft SharePoint Server Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36891 Microsoft SharePoint Server Spoofing Vulnerability
๐Ÿ›
CVE-2023-36892 Microsoft SharePoint Server Spoofing Vulnerability
๐Ÿ›
CVE-2023-36893 Microsoft Outlook Spoofing Vulnerability
๐Ÿ›
CVE-2023-36894 Microsoft SharePoint Server Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36895 Microsoft Outlook Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36896 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36897 Visual Studio Tools for Office Runtime Spoofing Vulnerability
๐Ÿ›
CVE-2023-35388 Microsoft Exchange Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-20569 AMD: CVE-2023-20569 Return Address Predictor
๐Ÿ›
CVE-2023-35390 .NET and Visual Studio Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-35391 ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-38182 Microsoft Exchange Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-38181 Microsoft Exchange Server Spoofing Vulnerability
๐Ÿ›
CVE-2023-38180 .NET and Visual Studio Denial of Service Vulnerability
๐Ÿ›
CVE-2023-38178 .NET Core and Visual Studio Denial of Service Vulnerability
๐Ÿ›
CVE-2023-38176 Azure Arc-Enabled Servers Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38154 Windows Kernel Elevation of Privilege Vulnerability
๐Ÿ›
Fortinet Releases Security Update for FortiOS
๐Ÿ›
Microsoft Office update breaks actively exploited RCE attack chain
KEV
๐Ÿ›
Downfall and Zenbleed: Googlers helping secure the ecosystem
๐Ÿ›
CVE-2017-11882 is still being exploited | Kaspersky official blog
โš ๏ธ
New PaperCut NG/MF Flaw Let Attackers Execute Code on Unpatched Windows Servers
โš ๏ธ
LOLBAS in the Wild: 11 Living-Off-The-Land Binaries Used for Malicious Purposes
โš ๏ธ
Spanish Police Arrest Three Behind Payment Card Fraud
โš ๏ธ
Microsoft Shares Guidance and Resources for AI Red Teams
โš ๏ธ
Understanding Active Directory Attack Paths to Improve Security
โš ๏ธ
UK Think Tank Proposes Greater Ransomware Reporting From Cyberinsurance to Government
โš ๏ธ
Bug Bounty Program: Microsoft Rewarded $13.8M for 345 Security Researches
โš ๏ธ
[INFOGRAPHIC] Q2 2023 Top-Clicked Phishing Test Results Favor HR-Related Subjects
โš ๏ธ
5 Intriguing Ways AI Is Changing the Landscape of Cyber Attacks
โš ๏ธ
Threat Actors Using an Armed OpenBullet Pentesting Tool to Manipulate Script Kids
โš ๏ธ
Spanish Police Arrest 3 Suspected of Payment Card Fraud
โš ๏ธ
White House Pushes Cybersecurity Defense for K-12 Schools
โš ๏ธ
UK Electoral Commission data breach exposes 8 years of voter data
โš ๏ธ
Google Cybersecurity Action Team Threat Horizons Report #7 Is Out!
โš ๏ธ
ADV190023 Microsoft Guidance for Enabling LDAP Channel Binding and LDAP Signing
โš ๏ธ
CISA Releases Two Industrial Control Systems Advisories
โš ๏ธ
Ukrainian State Agencies Targeted with Open-Source Malware MerlinAgent
โš ๏ธ
ADV230004 Memory Integrity System Readiness Scan Tool Defense in Depth Update
โš ๏ธ
New Downfall attacks on Intel CPUs steal encryption keys, data
โš ๏ธ
Microsoft August 2023 Patch Tuesday warns of 2 zero-days, 87 flaws
KEV
โš ๏ธ
Meet the Brains Behind the Malware-Friendly AI Chat Service โ€˜WormGPTโ€™
โš ๏ธ
Microsoft August 2023 Patch Tuesday, (Tue, Aug 8th)
โš ๏ธ
Microsoft Releases August 2023 Security Updates
โš ๏ธ
Patch Tuesday: Microsoft (Finally) Patches Exploited Office Zero-Days
โš ๏ธ
Critical Patches Issued for Microsoft Products, August 08, 2023
โš ๏ธ
Adobe Releases Security Updates for Multiple Products
โš ๏ธ
Kyiv Cyber Defenders Spot Open-Source RAT in Phishing Emails
โš ๏ธ
News alert: SandboxAQ launches new open source framework to simplify cryptography management
โš ๏ธ
Android 14 introduces first-of-its-kind cellular connectivity security features
KEV
โš ๏ธ
An update on Chrome Security updates โ€“ shipping security fixes to you faster
โš ๏ธ
Congratulations to the MSRC 2023 Most Valuable Security Researchers!
โš ๏ธ
Updating our Vulnerability Severity Classification for AI Systems
โš ๏ธ
Multiplying Force with Automation โ€” Reducing the Soul Crushing Work
๐Ÿ“‹
ICS Patch Tuesday: Siemens Fixes 7 Vulnerabilities in Ruggedcom Products
๐Ÿ“‹
Patch Tuesday: Adobe Patches 30 Acrobat, Reader Vulns
๐Ÿ“ข
You Canโ€™t Rush Post-Quantum-Computing Cryptography Standards
๐Ÿ“ข
CISA Unveils Cybersecurity Strategic Plan for Next Three Years
๐Ÿ“ข
CISA and FEMA Partner to Provide $374.9 Million in Grants to Bolster State and Local Cybersecurity
๐Ÿ“ข
CISA Recognizes Mark Buchholz During Bi-Annual SAFECOM Meeting
๐Ÿ“ข
IBM security advisory (AV23-465)
๐Ÿ“ข
Android security advisory โ€“ August 2023 Monthly Rollup (AV23-464)
๐Ÿ“ข
Dell security advisory (AV23-463)
๐Ÿ“ข
White House Holds First-Ever Summit on the Ransomware Crisis Plaguing the Nationโ€™s Public Schools
๐Ÿ“ข
Adobe security advisory (AV23-466)
๐Ÿ“ข
[Control systems] Schneider Electric security advisory (AV23-468)
๐Ÿ“ข
[Control systems] Hitachi Energy security advisory (AV23-467)
๐Ÿ“ข
News alert: DigiCert extends cert management platform to support Microsoft CA, AWS Private CA
๐Ÿ“ข
Ensuring Compliance with DORA: How Qualys Solutions Can Help
๐Ÿ”ฅ
Report: Manufacturing Sector Lost $46 Billion to Ransomware Attacks
๐Ÿ”ฅ
TargetCompany Ransomware Abuses FUD Obfuscator Packers
๐Ÿ”ฅ
New Yashma Ransomware Variant Targets Multiple English-Speaking Countries
๐Ÿ”ฅ
Clustering attacker behavior reveals hidden patterns
๐Ÿ”ฅ
Budget Constraints Threaten Cybersecurity in Government Bodies
๐Ÿ”ฅ
UK: Over 200 Million Brits Have Data Compromised in Four Years
๐Ÿ”ฅ
Hackers Abusing Cloudflare Tunnels for Covert Communications
๐Ÿ”ฅ
HHS Warns Healthcare Sector of Attacks by Rhysida Ransomware Group
๐Ÿ”ฅ
New Threat Actor Targets Bulgaria, China, Vietnam, and Other Countries With Customized Yashma Ransomware
๐Ÿ”ฅ
Hackers Increasingly Abuse Cloudflare Tunnels for Stealthy Connections
๐Ÿ”ฅ
Big Cyberespionage Attack Against Japan Attributed to China
๐Ÿ”ฅ
UK Electoral Commission Suffered 'Complex' Hack in 2021
๐Ÿ”ฅ
Microsoft Purview data security mitigations for BazaCall and other human-operated data exfiltration attacks
๐Ÿ”ฅ
Electoral Commission hack exposed data of 40 million UK voters
๐Ÿ”ฅ
News alert: Picus Security attack simulations report reveals organizations prevent 6 of 10 attacks
๐Ÿ”ฅ
Lower Data Breach Insurance Costs with These Tips
๐Ÿ”ฅ
CraftRise - 2,532,527 breached accounts
๐Ÿ•ต๏ธ
ISC Stormcast For Tuesday, August 8th, 2023 https://isc.sans.edu/podcastdetail/8606, (Tue, Aug 8th)
๐Ÿ•ต๏ธ
New Microsoft Azure AD CTS Feature can be Abused for Lateral Movement
๐Ÿ•ต๏ธ
North Korean Hackers Compromise Sanctioned Russian Missile Engineering Company
๐Ÿ•ต๏ธ
Black Hat Preview: The Business of Cyber Takes Center Stage
๐Ÿ•ต๏ธ
CyberheistNews Vol 13 #32 [HEADS UP] Google's Huge Inactive Account Deletion - What You Need to Know
๐Ÿ•ต๏ธ
Identity-Based Attacks Soared in Past Year: Report
๐Ÿ•ต๏ธ
43 Malicious Android Apps With Over 2.5 Million Installs Display Secret Ads
๐Ÿ•ต๏ธ
Most Organizations Using Weak Multifactor Authentication
๐Ÿ•ต๏ธ
Protection is No Longer Straightforward โ€“ Why More Cybersecurity Solutions Must Incorporate Context
๐Ÿ•ต๏ธ
Horizon3 AI Raises $40 Million to Expand Automated Pentesting Platform
๐Ÿ•ต๏ธ
KnowBe4โ€™s Interactive Phishing Analysis Center: Keep Your Finger On The Pulse
๐Ÿ•ต๏ธ
Norway Threatens Meta With Fines for Ad Violations
๐Ÿ•ต๏ธ
Lawmaker Quizzes Google on 'Guardrails' for AI in Healthcare
๐Ÿ•ต๏ธ
Boost identity protection with Axiad Cloud and Microsoft Entra ID
๐Ÿ•ต๏ธ
Black Hat Fireside Chat: โ€˜UEMโ€™ solutions seek to protect endpoints, preserve user experience
๐Ÿ•ต๏ธ
The Forrester Consulting TEI of Guardium Data Protection study: 5 data security lessons
๐Ÿ•ต๏ธ
Unmasking hypnotized AI: The hidden risks of large language models
๐Ÿ•ต๏ธ
Disrupting Japan podcast: The forgotten mistake that killed Japan's software industry - 33 minutes
๐Ÿ•ต๏ธ
DHS Announces Additional $374.9 Million in Funding to Boost State, Local Cybersecurity | Homeland Security
๐ŸŒ
Latest Batloader Campaigns Use Pyarmor Pro for Evasion
๐ŸŒ
Nigerian Man Admits to $1.3M Business Email Compromise Scam
๐ŸŒ
Stealthy npm Malware Exposes Developer Data
๐ŸŒ
QakBot Malware Operators Expand C2 Network with 15 New Servers
๐ŸŒ
New Malware Campaign Targets Inexperienced Cybercriminals with OpenBullet Configs
๐ŸŒ
Cybersecurity Threat 1H 2023 Brief with Generative AI
๐ŸŽ™๏ธ
ADV230003 Microsoft Office Defense in Depth Update
๐Ÿ“ก
Extended warranty robocallers fined $300 million after 5 billion scam calls
๐Ÿ“ก
Cyberinsurance Firm Resilience Raises $100 Million to Expand Its Cyber Risk Platform
๐Ÿ“ก
Teach a Man to Phish and Heโ€™s Set for Life โ€“ Krebs on Security
๐Ÿ“ก
Enough attribution to count
๐Ÿ“ก
Points.com Vulnerabilities Allowed Customer Data Theft, Rewards Program Hacking
๐Ÿ“ก
DHS Grants $375 Million to State and Local Government Cyber-Resilience Efforts
๐Ÿ“ก
Massive Phishing Campaign Impersonates 340 Companies Using Over 800 Scam Domains
๐Ÿ“ก
Invisible Ad Fraud Campaign Targets South Korean Android Users
๐Ÿ“ก
Report: Two-Thirds of UK Sites Vulnerable to Bad Bots
๐Ÿ“ก
Android 14 to block connections to unencrypted cellular networks
๐Ÿ“ก
New Inception attack leaks secrets from all AMD Zen CPUs
๐Ÿ“ก
New Inception attack leaks sensitive data from all AMD Zen CPUs
๐Ÿ“ก
Android 14 to let you block connections to unencrypted cellular networks
๐Ÿ“ก
Interpol takes down 16shop phishing-as-a-service platform
๐Ÿ“ก
Windows 10 KB5029244 and KB5029247 updates released
๐Ÿ“ก
Sophos Named Customersโ€™ Choice for Managed Detection and Response (MDR) in the Inaugural Gartnerยฎ Voice of the Customer Peer Insightsโ„ข Report
๐Ÿ“ก
Windows 11 KB5029263 cumulative update released with 27 fixes
๐Ÿ“ก
Malicious extensions can abuse VS Code flaw to steal auth tokens
๐Ÿ“ก
Microsoft Visual Studio Code flaw lets extensions steal passwords
๐Ÿ“ก
Googleโ€™s Messages app will now use RCS by default and encrypt group chats
๐Ÿ“ก
Rubrik acquires Laminar to expand in data security across public clouds
๐Ÿ“ก
Horizon3 secures $40M to expand its pen testing platform
๐Ÿ“ก
Serious Security: Why learning to touch-type could protect you from audio snooping
๐Ÿ“ก
Leverage the AWS Sustainability Pillar to Minimize Environmental Impact