127Articles
10Categories
2023-09-21Date
🚨
Key findings from the CISA 2022 Top Routinely Exploited Vulnerabilities reportOne of the best ways to mitigate risk and insulate your organization from malicious actors is to understand where they're focusing their time and attention as well as leveraging recommended practices to avoid becoming a victim. The recently published CISA 2022 Top Routinely Explo…
KEV
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2023-41179 Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability These types of vulnerabilities are frequent att…
KEV
🐛
Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT
🐛
Trend Micro Zero-day Vulnerability Let Attackers Run Arbitrary Code
🐛
Gitlab fixes bug that exploited internal policies to trigger hostile pipelines
🐛
ISC Releases Security Advisories for BIND 9
🐛
Apple Patches Three New 0-Day Vulnerabilities Affecting iOS/iPadOS/watchOS/macOS, (Thu, Sep 21st)
⚠️
MGM Resorts Computers Back Up After 10 Days as Analysts Eye Effects of Casino Cyberattacks
⚠️
Beware: Fake Exploit for WinRAR Vulnerability on GitHub Infects Users with VenomRAT
⚠️
AMBERSQUID Cryptojacking Operation: Unusual AWS Services Under Attack
⚠️
Ukrainian Hacker Suspected to be Behind "Free Download Manager" Malware Attack
⚠️
LLM Guard: Open-Source Toolkit for Securing Large Language Models
⚠️
The Rise of the Malicious App
⚠️
New Revelations from the Snowden Documents
⚠️
Cybercriminals Exploit the Moroccan Tragedy in New Scam Campaign
⚠️
Ncurses & Bad Things, LVFS is NOT a Backdoor, Physical Proximity, & Oh, Fortinet! - PSW #799
⚠️
Drupal Releases Security Advisory to Address Vulnerability in Drupal Core
⚠️
Ukrainian Hacker Suspected to be Behind "Free Download Manager" Malware Attack
⚠️
MOVEit Transfer SQL Injection Let the Attacker Gain Unauthorized Access to the Database
⚠️
Proactive OT security requires visibility + prevention
⚠️
CISA Releases Six Industrial Control Systems Advisories
⚠️
China accuses US of cyberattacks, spying on Huawei
⚠️
Balancing Budget and System Security: Approaches to Risk Tolerance
⚠️
Atlassian Releases September Security Bulletin
⚠️
Navigating the Digital Frontier in Cybersecurity Awareness Month 2023
⚠️
Scaling Rust Adoption Through Training
⚠️
China’s offensive cyber operations support “soft power” agenda in Africa
⚠️
Apple emergency updates fix 3 new zero-days exploited in attacks
⚠️
Unmasking ransomware threat clusters: Why it matters to defenders
⚠️
Detection Engineering and SOC Scalability Challenges (Part 2)
⚠️
2024 Security Planning with Forrester - Merritt Maxim - ESW #332
⚠️
A Vulnerability in Drupal Could Allow for Privilege Escalation
⚠️
Meredith Whittaker reaffirms that Signal would leave UK if forced by privacy bill
⚠️
News alert: MxD roundtable with White House officials highlights cybersecurity workforce needs
📋
Atlassian Security Updates Patch High-Severity Vulnerabilities
📢
White House Grapples With Harmonizing Thicket of Cybersecurity Rules
📢
CIO Accuses Penn State of Faking Cybersecurity Compliance
📢
China Accuses U.S. of Decade-Long Cyber Espionage Campaign Against Huawei Servers
📢
Critical Infrastructure Organizations Warned of Snatch Ransomware Attacks
📢
OnDemand: New EMEA FinServ Compliance: Digital Operational Resilience Act (DORA)
📢
China Accuses U.S. of Decade-Long Cyber Espionage Campaign Against Huawei Servers
📢
Snatch ransomware – what you need to know
📢
Singapore Police Warn of New Scam Campaign Spreading Android Malware
📢
CISA Publishes New Cybersecurity Career Awareness Challenges
📢
[Control systems] Delta Electronics security advisory (AV23-573)
📢
[Control systems] Siemens security advisory (AV23-572)
📢
[Control systems] Siemens security advisory (AV23-571)
📢
[Control systems] Rockwell Automation security advisory (AV23-570)
📢
Cryptohack Roundup: Private Key Compromise Led to CoinEx Hit
📢
Feds Warn About Snatch Ransomware
🔥
Network Device Supply Chain Security - Nate Warfield - BTS #13
🔥
T-Mobile App Glitch Exposes Other User’s Sensitive Data
🔥
Update: Transunion Denies it Was Hacked, Links Leaked Data to Third Party
🔥
Cyber Group 'Gold Melody' Selling Compromised Access to Ransomware Attackers
🔥
Critical Infrastructure Organizations Warned of Snatch Ransomware Attacks
🔥
Most organizations want security vendor consolidation
🔥
International Criminal Court Reveals Security Breach
🔥
'Gold Melody' Group Sells Access to Compromised Networks to Ransomware Attackers
🔥
DHS Council Seeks to Simplify Cyber Incident Reporting Rules
🔥
GUEST ESSAY: Caring criminals — why some ransomware gangs now avoid targeting hospitals
🔥
Pizza Hut Australia warns 193,000 customers of a data breach
🔥
Vanishing Act: The Secret Weapon Cybercriminals Use in Your Inbox
🔥
Donald Trump Jr’s hacked Twitter account announces his father has died
🔥
International Criminal Court hacked amid Russia probe
🔥
MGM Resorts Operations Resume 10 Days After Cyberattack
🔥
Feds Issue Snatch Ransomware Warning
🔥
TransUnion Denies Breach After Hacker Publishes Allegedly Stolen Data
🔥
ApexSMS - 23,246,481 breached accounts
🔥
New SEC Rules Add Challenges in Uncertain Cyber Insurance Market
🔥
Breach Roundup: Effects of ISP Ransomware Attack in Colombia
🔥
Chinese Spies Infected Dozens of Networks With Thumb Drive Malware
🔥
Making tabletop exercises better! - Ryan Fried - ESW #332
🔥
Ohio Community College Data Theft Breach Affects Nearly 300K
🔥
Cyberattack on Kansas town affects email, phone, payment systems
🕵️
AI Attacks and LLM Security Matters - Nathan Hamiel - PSW #799
🕵️
ISC Stormcast For Thursday, September 21st, 2023 https://isc.sans.edu/podcastdetail/8668, (Thu, Sep 21st)
🕵️
Omron Patches PLC, Engineering Software Flaws Discovered During ICS Malware Analysis
🕵️
System Admin Pleads Guilty for Selling Pirated Business Phone Software Licenses
🕵️
Car Cybersecurity Study Shows Drop in Critical Vulnerabilities Over Past Decade
🕵️
UK’s New Online Safety Law Adds to Crackdown on Big Tech Companies
🕵️
Is QakBot Malware Officially Dead?
🕵️
Security Fest 2022 - Gothenburg, Sweden - 12 hours of video
🕵️
SecurityFest 2023 - Gothenburg, Sweden - 2 days, 15 hours of talks
🕵️
LUCR-3 Attacking Fortune 2000 Companies Using Victims’ Own Tools & Apps
🕵️
Cisco to Bring XDR, SIEM Together With $28B Splunk Purchase
🕵️
Encrypted email provider Proton has built its own CAPTCHA service
🕵️
Every Network Is Now an OT Network. Can Your Security Keep Up?
🕵️
Legit Security Raises $40 Million in Series B Financing
🕵️
Cisco to Acquire Splunk for $28 Billion
🕵️
New ways to inject system CA certificates in Android 14
🕵️
‘Sandman’ hackers backdoor telcos with new LuaDream malware
🕵️
New ‘Sandman’ APT Group Hitting Telcos With Rare LuaJIT Malware
🕵️
Dutch Police Warns Users of Credentials Leak Site
🕵️
Massive valuations and acquisitions - Cato, Cisco, Splunk & SentinelOne! - ESW #332
🕵️
Why Palo Alto Networks Was Named Google Cloud Partner of the Year
🕵️
New Microsoft security tools to protect families and businesses
🌐
Researchers Witness 600X Increase in P2Pinfect Botnet Traffic
🌐
Omron Patches PLC, Engineering Software Flaws Discovered During ICS Malware Analysis
🌐
Researchers Raise Red Flag on P2PInfect Malware with 600x Activity Surge
🌐
GitHub launches passkey support into general availability
🎙️
Smashing Security podcast #340: Heated seats, car privacy, and Graham’s porn video
🎙️
Reversing Windows Container, episode I: Silo
📡
Another $40m Dispersed to Western Union Fraud Victims
📡
Australia to Build ‘Six Cyber Shields’ to Defend Nation
📡
T-Mobile App Glitch Let Users See Other People’s Account Info
📡
Microsoft SAS misconfiguration causes 38TB data leak
📡
UK Passes the Online Safety Bill — And No, It Doesn’t Ban End-to-End Encryption
📡
What is the Fediverse, and how does it work? | Kaspersky official blog
📡
Solarium Commission Wants Action on Stalled Cybersecurity Recommendations
📡
Cisco to acquire Splunk in $28B mega deal
📡
Companies Still Don’t Know How to Handle Generative AI Risks
📡
Cyber Experts Urge House Committee to Avoid Federal Shutdown
📡
Never Use Your Master Password as a Password on Other Accounts
📡
Poland Investigates OpenAI Over Privacy Concerns
📡
Cisco Beefs Up Cybersecurity Play With $28 Billion Splunk Deal
📡
India's Biggest Tech Centers Named As Cyber Crime Hotspots
📡
Canada Blames Border Airport Check-in and Electronic Gate Outages on DDoS Attack
📡
Cisco Acquiring Cybersecurity Company Splunk in Cash Deal Worth $28 Billion
📡
Microsoft Copilot rolls out with Windows 11 22H2 update next week
📡
Decoding Turla: Trend Micro's MITRE Performance
📡
GitHub passkeys generally available for passwordless sign-ins
📡
Kindo aims to take the security stress out of AI workflows
📡
Journey to the Cloud: Navigating the Transformation - Part 3
📡
Canada Confirms DDoS Attack Disrupted Airport Arrival Kiosks
📡
Forecasts of SIEM Death Premature - Just Ask Cisco, Splunk
📡
OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes
📡
Zero Trust Adoption: Tips to Win Over Leadership