123Articles
8Categories
2023-09-07Date
πŸ›
PHPFusion Critical Flaw Allows Attackers to Read Critical System Data
πŸ›
Alert: Apache SuperSet Vulnerabilities Expose Servers to Remote Code Execution Attacks
πŸ›
Cisco Patches Critical Vulnerability in BroadWorks Platform
πŸ›
CISA, FBI, and CNMF Release Advisory on Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
πŸ›
Chromium: CVE-2023-4761 Out of bounds memory access in FedCM
πŸ›
Chromium: CVE-2023-4762 Type Confusion in V8
πŸ›
Chromium: CVE-2023-4763 Use after free in Networks
πŸ›
Chromium: CVE-2023-4764 Incorrect security UI in BFCache
πŸ›
Apple Releases iOS/iPadOS 16.6.1, macOS 13.5.2, watchOS 9.6.2 fixing two zeroday vulnerabilities, (Thu, Sep 7th)
KEV
πŸ›
CISA warns of critical Apache RocketMQ bug exploited in attacks
KEV
πŸ›
MAR-10454006.r5.v1 SUBMARINE, SKIPJACK, SEASPRAY, WHIRLPOOL, and SALTWATER Backdoors
⚠️
Baseline standards for BYOD access requirements
⚠️
LibreOffice: Stability, security, and continued development
⚠️
MITRE and CISA Release Open Source Tool for OT Attack Emulation
⚠️
Emerging cyber threats in 2023 from AI to quantum to data poisoning
⚠️
Why Data Privacy is Being Overhauled in 2023 - Dan Frechtling - ESW Vault
⚠️
Feds Publicly Name 130 Healthcare Firms Using Web Trackers
⚠️
The Hacker Tool to Get Personal Data from Credit Bureaus
⚠️
Cisco Finds 8 Vulnerabilities in OAS Industrial IoT Data Platform
⚠️
IBM Discloses Data Breach Impacting Janssen Healthcare Platform
⚠️
Perception Point tackles QR code phishing attacks
⚠️
Hackers Exploit Multiple Bugs in Hotel Booking Platform
⚠️
IAM, cloud security to drive new cybersecurity spending
⚠️
Cisco Patches Critical Vulnerability In BroadWorks Platform
⚠️
Crash Dump Error: How A Chinese Espionage Group Exploited Microsoft's Mistakes
⚠️
Thousands of Popular Websites Found Leaking Secrets, Source Code
⚠️
CISA Releases Four Industrial Control Systems Advisories
⚠️
New Hive0117 phishing campaign imitates conscription summons to deliver DarkWatchman malware
⚠️
Cisco Releases Security Advisories for Multiple Products
⚠️
Google: State hackers attack security researchers with new zero-day
⚠️
Apple discloses 2 new zero-days exploited to attack iPhones, Macs
⚠️
Interview with Dr. Gene Spafford - Eugene Spafford - PSW Vault
⚠️
Cisco BroadWorks impacted by critical authentication bypass flaw
⚠️
Apple zero-click iMessage exploit used to infect iPhones with spyware
⚠️
Apple Patches Actively Exploited iOS, macOS Zero-Days
KEV
⚠️
Rigged Software and Zero-Days: North Korean APT Caught Hacking Security Researchers
⚠️
Apple fixes zero-day bugs used to plant Pegasus spyware
⚠️
Iranian hackers breach US aviation org via Zoho, Fortinet bugs
⚠️
Detection Engineering is Painfulβ€Šβ€”β€Šand It Shouldn’t Be (Part 1)
⚠️
Iranian hackers breach US aviation org via ManageEngine, Fortinet bugs
⚠️
UPDATED – Multiple Vulnerabilities in Apple Products Could Allow for Arbitrary Code Execution
πŸ“‹
Mirai Botnet Variant 'Pandora' Hijacks Android TVs for Cyberattacks
πŸ“’
Shifting left and right, innovating product security
πŸ“’
Hawai’i State Department of Health Resolves Website Defacement
πŸ“’
Peiter 'Mudge' Zatko Lands Role as CISA Senior Technical Adviser
πŸ“’
CISA Seeks Vendor Commitments to Boost Cybersecurity in K-12 Schools
πŸ“’
UK National Cyber Security Centre Gets a New CTO
πŸ“’
Social Engineering Seeks Okta Credentials
πŸ“’
HPE security advisory (AV23-530)
πŸ“’
CISA Releases Guidance on Adopting DDoS Mitigations
πŸ“’
Tattletale Ransomware Gangs Threaten to Reveal GDPR Breaches
πŸ“’
[Control systems] Dover Fueling Solutions security advisory (AV23-533)
πŸ“’
[Control systems] Phoenix Contact security advisory (AV23-532)
πŸ“’
[Control systems] SOCOMEC security advisory (AV23-531)
πŸ“’
Apple security advisory (AV23-534)
πŸ“’
California Executive Order Hopes to Ensure 'Trustworthy AI'
πŸ”₯
Outlook Breach: Microsoft Reveals How a Crash Dump Led to a Major Security Breach
πŸ”₯
Minneapolis School District Says Data Breach Affected More Than 100,000 People
πŸ”₯
Ukraine's CERT Thwarts APT28's Cyberattack on Critical Energy Infrastructure
πŸ”₯
Coffee Meets Bagel Says Recent Outage Caused by Destructive Cyberattack
πŸ”₯
Avoidable Digital Certificate Issues Fuel Data Breaches
πŸ”₯
Australian Official Slams Firms for Data Breach Reporting Delays
πŸ”₯
AI Abuse Grows Beyond Phishing To Multistage Cyberattacks
πŸ”₯
US and UK sanction 11 TrickBot and Conti cybercrime gang members
πŸ”₯
Johnson & Johnson discloses IBM data breach impacting patients
πŸ”₯
Just Kids Dental Says Nearly 130,000 People Affected by Cyberattack
πŸ”₯
Traderie, a marketplace for in-game items, alerts users to data breach
πŸ”₯
Update: University of Michigan Requires Password Resets After Cyberattack
πŸ”₯
Dunghill Leak Ransomware Gang Claims Credit for Sabre Data Breach
πŸ”₯
Microsoft: North Korean hackers target Russian govt, defense orgs
πŸ”₯
US, UK Sanction 11 Russian Cybercriminals Tied to TrickBot
πŸ”₯
Breach Roundup: Swedish Insurer Fined $3M for GDPR Breach
πŸ”₯
Experts Probe AI Risks Around Malicious Use, China Influence
πŸ•΅οΈ
ISC Stormcast For Thursday, September 7th, 2023 https://isc.sans.edu/podcastdetail/8648, (Thu, Sep 7th)
πŸ•΅οΈ
Cybersecurity pros battle discontent amid skills shortage
πŸ•΅οΈ
How cybercriminals use look-alike domains to impersonate brands
πŸ•΅οΈ
3 ways to strike the right balance with generative AI
πŸ•΅οΈ
An introduction to ISO 27001 with Edgar Reinke - 42 minutes
πŸ•΅οΈ
ISO 27001:2022 changes in new version & its linkage to ISO 27022 – Webinar by SGS MidEast
πŸ•΅οΈ
What’s in a NoName? Researchers See a Lone-Wolf DDoS Group
πŸ•΅οΈ
Hackers Use Weaponized LNK Files to Deploy RedEyes Malware
πŸ•΅οΈ
Webinar | Improvise, Adapt - Overcome | Splunk TTP Top Tips (In German)
πŸ•΅οΈ
Chinese Hack of Microsoft Consumer Key Stemmed From its Engineer’s Corporate Account
πŸ•΅οΈ
Tenable to Acquire Cloud Security Firm Ermetic for $240 Million
πŸ•΅οΈ
Why consumer drones represent a special cybersecurity risk
πŸ•΅οΈ
North Korea Hackers Going After Russian Targets, Microsoft Says
πŸ•΅οΈ
Chinese Hacker Steals Microsoft Signing Key, Spies on US Government
πŸ•΅οΈ
Tenable to Buy Startup Ermetic for $265M to Safeguard Clouds
πŸ•΅οΈ
See Tickets Alerts 300,000 Customers After Another Web Skimmer Attack
πŸ•΅οΈ
β€˜Atomic macOS Stealer’ Malware Delivered via Malvertising Campaign
πŸ•΅οΈ
The Team8 Foundry Method for Selecting Investable Startups
πŸ•΅οΈ
Cryptohack Roundup: Tornado Cash, Privacy Pools
πŸ•΅οΈ
Wealthy Russian With Kremlin Ties Gets 9 Years in Prison for Hacking and Insider Trading Scheme
πŸ•΅οΈ
Boot Unguarded: x86 Trust Anchor Downfalls to The Leaked OEM Internal Tools and Signing Keys
πŸ•΅οΈ
Trail of Errors Led to Chinese Hack of Microsoft Cloud Email
πŸ•΅οΈ
Cloud storage security: What’s new in the threat matrix
πŸ•΅οΈ
NextWave Cloud Service Provider Path β€” Breakaway 1=5
🌐
The State of the Virtual CISO Report: MSP/MSSP Security Strategies for 2024
🌐
Thousands of dollars stolen from Texas ATMs using Raspberry Pi
🌐
Mac Users Beware: Malvertising Campaign Spreads Atomic Stealer macOS Malware
🌐
Mac Users Targeted in New Malvertising Campaign Delivering Atomic Stealer
🌐
&#xa&#x3b;Fleezeware/Scareware Advertised via Facebook Tags&#x3b; Available in Apple App Store, (Thu, Sep 7th)
🌐
Why Connected Devices Are Such a Risk to Outpatient Care
πŸ“‘
How Zero Trust and XDR Work Together
πŸ“‘
Experts Uncover Underground Phishing β€œEmpire” W3LL Targeting 56,000 Microsoft 365 Accounts
πŸ“‘
Russia Undertakes Disinformation Campaign Across Africa
πŸ“‘
UK Boards Are Growing Less Concerned About Cyber-Risk
πŸ“‘
System time jumps in Windows: possible cause | Kaspersky official blog
πŸ“‘
Rogers silent as Canadian customers report internet outages
πŸ“‘
Battery Ventures Buys GrammaTech's Application Security Unit
πŸ“‘
ActiveFence snaps up Spectrum Labs, last valued at $137M, to help fight the harmful content creep
πŸ“‘
How China Gets Free Intel On Tech Companies' Vulnerabilities
πŸ“‘
China Bans iPhones From More Government Offices
πŸ“‘
The Initial Access Broker Economy: A Deep Dive into Dark Web Hacking Forums
πŸ“‘
Tenable to Acquire Cloud Security Firm Ermetic for $240 Million
πŸ“‘
US, UK authorities sanction more alleged Trickbot gang members
πŸ“‘
Debugging Windows Isolated User Mode (IUM) Processes
πŸ“‘
Windows cryptomining attacks target graphic designer's high-powered GPUs
πŸ“‘
The perils of the platforms of paranoia
πŸ“‘
Google Looker Studio abused in cryptocurrency phishing attacks
πŸ“‘
Google is enabling Chrome real-time phishing protection for everyone
πŸ“‘
Building a Use Policy For Generative AI
πŸ“‘
Microsoft Paint in Windows 11 gets a background removal tool