194Articles
9Categories
2023-09-12Date
๐Ÿšจ
CISA Adds Recently Discovered Apple Zero-Days to Known Exploited Vulnerabilities CatalogThe Cybersecurity and Infrastructure Security Agency (CISA) added the security vulnerabilities chained in the zero-click iMessage exploit BLASTPASS to its Known Exploited Vulnerabilities Catalog.
KEV
๐Ÿšจ
CISA Adds Two Known Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2023-36761 Microsoft Word Information Disclosure Vulnerability CVE-2023-36802 Microsoft Streaming Service Proxy Elevation of Privilege Vulnerabiliโ€ฆ
KEV
๐Ÿ›
Google Rushes to Patch Critical Chrome Vulnerability Exploited in the Wild - Update Now
KEV
๐Ÿ›
Google Patches Chrome Zero-Day Reported by Apple, Spyware Hunters
๐Ÿ›
Google Patches Chrome Zero-Day Reported by Apple, Spyware Hunters
๐Ÿ›
Apple backports BLASTPASS zero-day fixes to older iPhones
KEV
๐Ÿ›
Apple backports BLASTPASS zero-day fix to older iPhones
KEV
๐Ÿ›
CVE-2023-35355 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38162 DHCP Server Service Denial of Service Vulnerability
๐Ÿ›
CVE-2023-38161 Windows GDI Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38156 Azure HDInsight Apache Ambari Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38152 DHCP Server Service Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-38150 Windows Kernel Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38149 Windows TCP/IP Denial of Service Vulnerability
๐Ÿ›
CVE-2023-38148 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-38147 Windows Miracast Wireless Display Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-38146 Windows Themes Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-38144 Windows Common Log File System Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38143 Windows Common Log File System Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38142 Windows Kernel Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38141 Windows Kernel Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-38140 Windows Kernel Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-38139 Windows Kernel Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36805 Windows MSHTML Platform Security Feature Bypass Vulnerability
๐Ÿ›
CVE-2023-36804 Windows GDI Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36803 Windows Kernel Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36802 Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36801 DHCP Server Service Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36767 Microsoft Office Security Feature Bypass Vulnerability
๐Ÿ›
CVE-2023-36766 Microsoft Excel Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36765 Microsoft Office Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36759 Visual Studio Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36758 Visual Studio Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36757 Microsoft Exchange Server Spoofing Vulnerability
๐Ÿ›
CVE-2023-36756 Microsoft Exchange Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36745 Microsoft Exchange Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36744 Microsoft Exchange Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36742 Visual Studio Code Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36736 Microsoft Identity Linux Broker Arbitrary Code Execution Vulnerability
๐Ÿ›
CVE-2023-41764 Microsoft Office Spoofing Vulnerability
๐Ÿ›
CVE-2022-41303 AutoDesk: CVE-2022-41303 use-after-free vulnerability in Autodeskยฎ FBXยฎ SDK 2020 or prior
๐Ÿ›
CVE-2023-29332 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-33136 Azure DevOps Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36886 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
๐Ÿ›
CVE-2023-38164 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
๐Ÿ›
CVE-2023-38163 Windows Defender Attack Surface Reduction Security Feature Bypass
๐Ÿ›
CVE-2023-38160 Windows TCP/IP Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-38155 Azure DevOps Server and Team Foundation Server Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36800 Dynamics Finance and Operations Cross-site Scripting Vulnerability
๐Ÿ›
CVE-2023-36799 .NET Core and Visual Studio Denial of Service Vulnerability
๐Ÿ›
CVE-2023-36796 Visual Studio Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36794 Visual Studio Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36793 Visual Studio Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36792 Visual Studio Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36788 .NET Framework Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36777 Microsoft Exchange Server Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36773 3D Builder Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36772 3D Builder Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36771 3D Builder Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36770 3D Builder Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36764 Microsoft SharePoint Server Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2023-36763 Microsoft Outlook Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36762 Microsoft Word Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36761 Microsoft Word Information Disclosure Vulnerability
๐Ÿ›
CVE-2023-36760 3D Viewer Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-39956 Electron: CVE-2023-39956 -Visual Studio Code Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36740 3D Viewer Remote Code Execution Vulnerability
๐Ÿ›
CVE-2023-36739 3D Viewer Remote Code Execution Vulnerability
๐Ÿ›
Chromium: CVE-2023-4863 Heap buffer overflow in WebP
โš ๏ธ
The global cybersecurity skills shortage: Still crazy after all these years
โš ๏ธ
North Korean hackers targeting vulnerability researchers with zero-day attacks, Google warns
โš ๏ธ
Security and privacy laws, regulations, and compliance: The complete guide
โš ๏ธ
NIST releases Cybersecurity Framework 2.0 draft
โš ๏ธ
MGM Resorts Confirms โ€˜Cybersecurity Issueโ€™, Shuts Down Systems
โš ๏ธ
Critical GitHub Vulnerability Exposes 4,000+ Repositories to Repojacking Attack
โš ๏ธ
Code Intelligence unveils new LLM-powered software security testing solution
โš ๏ธ
ICS Patch Tuesday: Critical CodeMeter Vulnerability Impacts Several Siemens Products
โš ๏ธ
New Sentra tool to help classify sensitive enterprise data using LLMs
โš ๏ธ
FBI Investigates Cyberattack That Forced Hinds County Government Offices to Close
โš ๏ธ
Multiple Vulnerabilities in Notepad++ Could Allow for Arbitrary Code Execution
โš ๏ธ
CISA Releases its Open Source Software Security Roadmap
โš ๏ธ
CISA Announces Open Source Software Security Roadmap
โš ๏ธ
Cisco Secure Application brings app and security teams together
โš ๏ธ
CISA Releases Three Industrial Control Systems Advisories
โš ๏ธ
Email campaigns leverage updated DBatLoader to deliver RATs, stealers
โš ๏ธ
Google Patches Chrome 0-Day Reported By Apple, Spyware Hunters
โš ๏ธ
Charming Kitten Snares Unpatched Exchange Servers
โš ๏ธ
Building a Scanner and a Community with Zed Attack Proxy - Simon Bennetts - ASW #254
โš ๏ธ
Adobe Says Critical PDF Reader Zero-Day Being Exploited
โš ๏ธ
New WiKI-Eve Attack can Steal Numerical Passwords Over WiFi
โš ๏ธ
Adobe warns of critical Acrobat and Reader zero-day exploited in attacks
โš ๏ธ
Microsoft September 2023 Patch Tuesday fixes 2 zero-days, 59 flaws
KEV
โš ๏ธ
AP Stylebook Data Breach Compromises Customer Personal Information
โš ๏ธ
Zero Day Summer: Microsoft Warns of Fresh New Software Exploits
โš ๏ธ
Adobe Releases Security Updates for Multiple Products
โš ๏ธ
From Terminal Output to Arbitrary Remote Code Execution
โš ๏ธ
Critical Patches Issued for Microsoft Products, September 12, 2023
โš ๏ธ
Iranian Hackers 'Ballistic Bobcat' Deploy New Backdoor
โš ๏ธ
Mozilla patches Firefox, Thunderbird against zero-day exploited in attacks
KEV
โš ๏ธ
Microsoft September 2023 Patch Tuesday, (Tue, Sep 12th)
โš ๏ธ
Apple Releases Security Updates for iOS and macOS
โš ๏ธ
Microsoft Releases September 2023 Updates
โš ๏ธ
Adobe, Apple, Google & Microsoft Patch 0-Day Bugs
โš ๏ธ
Google Fixes Chrome Zero-Day Exploited in the Wild
KEV
โš ๏ธ
Malware distributor Storm-0324 facilitates ransomware access
โš ๏ธ
Data โ€” The Lifeblood of Security and Detection Engineering
โš ๏ธ
5 ways to secure external identities
โš ๏ธ
Operationalizing identity security in the public cloud
โš ๏ธ
ESET Research Podcast: Sextortion, digital usury and SQL brute-force
๐Ÿ“‹
A 59-CVE Patch Tuesday with something for nearly everyone
๐Ÿ“ข
[Control systems] Siemens security advisory (AV23-542)
๐Ÿ“ข
SAP security advisory โ€“ September 2023 monthly rollup (AV23-541)
๐Ÿ“ข
[Control systems] Schneider Electric security advisory (AV23-543)
๐Ÿ“ข
CISA offers free security scans for public water utilities
๐Ÿ“ข
NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats
๐Ÿ“ข
Fujitsu security advisory (AV23-545)
๐Ÿ“ข
[Control systems] Hitachi Energy security advisory (AV23-544)
๐Ÿ“ข
Microsoft security advisory โ€“ September 2023 monthly rollup (AV23-547)
๐Ÿ“ข
Adobe security advisory (AV23-546)
๐Ÿ“ข
IBM, Nvidia, Others Commit to Develop 'Trustworthy' AI
๐Ÿ“ข
US Lawmakers Warned That AI Needs a 'Safety Brake'
๐Ÿ”ฅ
Ransomware Attack Wipes Out Four Months of Sri Lankan Government Data
๐Ÿ”ฅ
Update: FBI Blames North Korean Hackers for $41 Million Stake.com Heist
๐Ÿ”ฅ
Beware of Fake Browser Updates that Install Malware on Systems
๐Ÿ”ฅ
'Redfly' hackers infiltrated power supplier's network for 6 months
๐Ÿ”ฅ
Ransomware Attack Wipes Out Four Months of Sri Lankan Government Data
๐Ÿ”ฅ
Chinese Redfly Group Compromised a Nation's Critical Grid in 6-Month ShadowPad Campaign
๐Ÿ”ฅ
Sophisticated Phishing Campaign Deploying Agent Tesla, OriginBotnet, and RedLine Clipper
๐Ÿ”ฅ
AuthMind raises seed funding for its identity SecOps platform
๐Ÿ”ฅ
Charming Kitten Introduces Sponsor Backdoor
๐Ÿ”ฅ
OriginBotnet, RedLine Clipper, and AgentTesla Distributed Via Phishing Emails
๐Ÿ”ฅ
BianLian Ransomware Gang Claims to Have Hit Save The Children
๐Ÿ”ฅ
Looks Like MGM Resorts Just Got Hacked
๐Ÿ”ฅ
Sophisticated Phishing Campaign Deploying Agent Tesla, OriginBotnet, and RedLine Clipper
๐Ÿ”ฅ
Microsoft Dumps a Key, Grafana Logs a Key, URL Parsers Disagree, Old Bug in Ubuntu - ASW #254
๐Ÿ”ฅ
Ransomware Attacks Hit Record Level in UK, According To Neglected Official Data
๐Ÿ”ฅ
MGM Resorts shuts down IT systems and slot machines go quiet following โ€œcybersecurity incidentโ€
๐Ÿ”ฅ
Feds Fine LA Health Plan $1.3M for 'Systemic' HIPAA Issues
๐Ÿ”ฅ
Ransomware access broker steals accounts via Microsoft Teams phishing
๐Ÿ”ฅ
The State of Security Leadership
๐Ÿ•ต๏ธ
Beware: MetaStealer Malware Targets Apple macOS in Recent Attacks
๐Ÿ•ต๏ธ
Webinar | Improvise, Adapt - Overcome | TTP Top Tips (In German)
๐Ÿ•ต๏ธ
Hacker Group Infrastructure That Uses Weaponized MS Word Docs Uncovered
๐Ÿ•ต๏ธ
Spies, Hackers, Informants: How China Snoops on the West
๐Ÿ•ต๏ธ
Cars Have Terrible Data Privacy
๐Ÿ•ต๏ธ
ISC Stormcast For Tuesday, September 12th, 2023 https://isc.sans.edu/podcastdetail/8654, (Tue, Sep 12th)
๐Ÿ•ต๏ธ
China-Linked โ€˜Redflyโ€™ Group Targeted Power Grid
๐Ÿ•ต๏ธ
Finding Your Way in Cloud Security
๐Ÿ•ต๏ธ
Cleafy Raises โ‚ฌ10 Million for Online Banking Fraud Prevention Platform
๐Ÿ•ต๏ธ
Court Convicts Portuguese Hacker in Football Leaks Trial and Gives Him a 4-Year Suspended Sentence
๐Ÿ•ต๏ธ
DFIR Company Binalyze Raises $19 Million in Series A Funding
๐Ÿ•ต๏ธ
Cybercriminals Selling "Golden Tickets" to Phish Microsoft 365... $500,000 in Sales in 10 Months
๐Ÿ•ต๏ธ
Phishing Scammers are Using Artificial Intelligence To Create Perfect Emails
๐Ÿ•ต๏ธ
Charming Kitten's New Backdoor 'Sponsor' Targets Brazil, Israel, and the UAE
๐Ÿ•ต๏ธ
Top 10 SaaS Security Checklist in 2023
๐Ÿ•ต๏ธ
CyberheistNews Vol 13 #37 Scary New IT Admin Attack Exposes Your MFA Weakness
๐Ÿ•ต๏ธ
After Microsoft and X, Hackers Launch DDoS Attack on Telegram
๐Ÿ•ต๏ธ
Vector Embeddings โ€“ Antidote to Psychotic LLMs and a Cure for Alert Fatigue?
๐Ÿ•ต๏ธ
Iranian Cyberspies Deployed New Backdoor to 34 Organizations
๐Ÿ•ต๏ธ
Collective Defense: The Importance of Partnerships in Cybersecurity - Jamil Farshchi - CSP 139
๐Ÿ•ต๏ธ
Thousands of Code Packages Vulnerable to Repojacking Attacks
๐Ÿ•ต๏ธ
New Sponsor Malware Attacking Government & Healthcare Organizations
๐Ÿ•ต๏ธ
Mopria, Cisco, Seimens , Word, DarkGate, AP Stylebook, More News, and Jason Wood - SWN #324
๐Ÿ•ต๏ธ
Intel Capital Bets on Zenity for Low-Code/No-Code Security
๐Ÿ•ต๏ธ
3.5 TB of data stolen from Datadvance: NDAs, scripts, and contracts leaked
๐ŸŒ
China Unleashes AI-Powered Image Generation For Influence Operations
๐ŸŒ
7 Steps to Kickstart Your SaaS Security Program
๐ŸŒ
White House mulls rating system to boost cybersecurity for critical infrastructure
๐ŸŒ
New Family of Obfuscated Go Info-stealers 'MetaStealer' Spread in Targeted Attacks
๐ŸŒ
Free Download Manager site redirected Linux users to malware for years
๐ŸŒ
New 'MetaStealer' malware targets Intel-based macOS systems
๐Ÿ“ก
Azure vs. AWS Developer Tools Guide
๐Ÿ“ก
LIVE Webinar | Safeguarding Servers
๐Ÿ“ก
Email Forwarding Flaws Enable Attackers to Impersonate High-Profile Domains
๐Ÿ“ก
New Quantum Random Number Generator Could Revolutionize Encryption
๐Ÿ“ก
How to manage subscription costs | Kaspersky official blog
๐Ÿ“ก
Powerful Ethnic Militia in Myanmar Repatriates 1,200 Chinese Suspected of Involvement in Cybercrime
๐Ÿ“ก
Live Webinar | Homegrown Security & Innovation: 4 Processes For Security to Flourish
๐Ÿ“ก
Live Webinar | From Data to Disclosure: Decoding Cyber Risk Reporting for the SEC and Board
๐Ÿ“ก
Google Rolls Out Privacy Sandbox to Use Chrome Browsing History for Ads
๐Ÿ“ก
Vietnamese Hackers Deploy Python-Based Stealer via Facebook Messenger
๐Ÿ“ก
UK Data Protection Regulator to Investigate Fertility App Security Concerns
๐Ÿ“ก
HiddenLayer raises $50M for its AI-defending cybersecurity tools
๐Ÿ“ก
G2 Names Sophos a Leader for Endpoint Protection, EDR, XDR, Firewall, and MDR
๐Ÿ“ก
Why Network Visibility Doesnโ€™t Have to be so Complicated
๐Ÿ“ก
Zenity strives to keep no code/low code apps secure
๐Ÿ“ก
Cleafy Raises $10.7 Million for Online Banking Fraud Prevention Platform
๐Ÿ“ก
Managing Cyber Risk for CISOs Under Pressure
๐Ÿ“ก
Huge DDoS Attack Against US Financial Institution Thwarted
๐Ÿ“ก
Thousands Of Code Packages Vulnerable To Repojacking Attacks
๐Ÿ“ก
DFIR Company Binalyze Raises $19 Million in Series A Funding
๐Ÿ“ก
Windows 11 KB5030219 cumulative update released with 24 fixes, changes
๐Ÿ“ก
Windows 10 KB5030211 update released with 11 improvements
๐Ÿ“ก
EMEA Webinar | Zero Trust Fundamentals: Start Your Journey Here