121Articles
9Categories
2023-09-28Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2023-14667 Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability These types of vulnerabilities are frequent attack vectors …
KEV
🐛
Vulnerability in popular ‘libwebp’ code more widespread than expected
🐛
Snowden Revelations, Cult of The Dead Cow Saves The Internet, & Stealing Your Pixels - PSW #800
🐛
Update Chrome Now: Google Releases Patch for Actively Exploited Zero-Day Vulnerability
KEV
🐛
Actively Exploited Chrome Zero-day Patched: Update Now!
KEV
🐛
Researchers Release Details of New RCE Exploit Chain for SharePoint
🐛
Google Releases Patch for Actively Exploited Zero-Day Vulnerability in Chrome
KEV
🐛
Google Rushes to Patch New Zero-Day Exploited by Spyware Vendor
⚠️
Cisco advisory: Reports about bad Actors Hiding in Router Firmware
⚠️
Firefox 118 Patches High-Severity Vulnerabilities
⚠️
Threat Actors Exploit the Tensions Between Azerbaijan and Armenia
⚠️
New Trojan ZenRAT masquerades as Bitwarden password manager
⚠️
Network Flight Simulator: Open-Source Adversary Simulation Tool
⚠️
Simple Membership Plugin Flaws Expose WordPress Sites
⚠️
macOS 14 Sonoma Patches 60 Vulnerabilities
⚠️
‘Snatch’ Ransom Group Exposes Visitor IP Addresses
⚠️
The Dark Side of Browser Isolation – and the Next Generation Browser Security Technologies
⚠️
Cisco Warns of IOS Software Zero-Day Exploitation Attempts
⚠️
Russian Zero-Day Acquisition Firm Offers $20 Million for Android, iOS Exploits
⚠️
[LIVE DEMO] Are Your Users Making Risky Security Mistakes? Deliver Real-Time Coaching in Response to Risky User Behavior with SecurityCoach
⚠️
ZYXEL Buffer Overflow vulnerability Let Attacker Launch DoS Attack
⚠️
China's BlackTech Hacking Group Exploited Routers to Target U.S. and Japanese Companies
⚠️
EchoMark releases watermarking solution to secure private communications, detect insider threats
⚠️
Cisco urges admins to fix IOS software zero-day exploited in attacks
⚠️
Google patches zero-day exploited by commercial spyware vendor
⚠️
CISA Releases Three Industrial Control Systems Advisories
⚠️
Cisco Warns Of IOS Software Zero-Day Exploitation Attempts
⚠️
Google Rushes To Patch New Zero-Day Exploited By Spyware Vendor
⚠️
Apple Releases Security Updates for Multiple Products
⚠️
Unraveling the CACTUS Ransomware Group’s Recent Exploits
⚠️
Cisco Releases Security Advisories for Multiple Products
⚠️
Vulnerability resolution enhanced by integrations
⚠️
Progress warns of maximum severity WS_FTP Server vulnerability
⚠️
Build for Detection Engineering, and Alerting Will Improve (Part 3)
⚠️
Chrome Patches 0-Day Exploited by Commercial Spyware Vendor
KEV
📢
Critical Cisco WAN Manager Vulnerabilities Let Attacker Conduct DoS Attack
📢
Exploring the DORA: Key Takeaways from the New EU Financial Sector Risk Regulation
📢
Google Chrome security advisory (AV23-588)
📢
Mozilla security advisory (AV23-587)
📢
Government Shutdown Could Bench 80% of CISA Staff
📢
Companies are already feeling the pressure from upcoming US SEC cyber rules
📢
CISA Rolls Dice on Public Service Campaign to Raise Cyber Awareness
📢
White House Set to Publish AI Executive Order This Fall
📢
CISA Kicks Off 20th Anniversary of Cybersecurity Awareness Month with New Public Awareness Campaign to Secure Our World
📢
[Control systems] Rockwell automation security advisory (AV23-590)
📢
NIST Unveils Newly Named Human-Centered Cybersecurity Program
🔥
CommonSpirit Details Financial Fallout of $160M Cyberattack
🔥
Podcast #141: Uber CISO Trial Learnings for CISOs: In the CISO's Own Words - Joe Sullivan ex-Uber - 40 minutes
🔥
Snatch Ransomware Group Leaked User’s Location and Internal Data
🔥
Building Automation Giant Johnson Controls Hit by Dark Angels Ransomware Attack
🔥
Chinese Hackers Stole Emails From US State Department in Microsoft Breach, Senate Staffer Says
🔥
DHS to Host Latin American Cyber Summit as Region Faces an Onslaught of Digital Attacks
🔥
How I got started: SIEM engineer
🔥
Amid MGM, Caesars Incidents, Attackers Focus on Luxury Hotels
🔥
Campbell Soup Says Summer Cyberattack Caused Limited Business Impact
🔥
Swan Retail Cyberattack Woes Continue for Independent UK Retailers
🔥
Ransomware group demands $51 million from Johnson Controls after cyber attack
🔥
UK data regulator warns that data breaches put abuse victims’ lives at risk
🔥
Cryptohack Roundup: $200M Mixin Network Hack
🔥
Black Hat Fireside Chat: In a hyper connected world, effectively securing APIs is paramount
🔥
Chinese Hackers Stole Emails From US State Dept In MS Breach
🔥
Misconfigured TeslaMate Instances Put Tesla Car Owners at Risk
🔥
GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contributions
🔥
FBI: Dual ransomware attack victims now get hit within 48 hours
🔥
Breach Roundup: Johnson Controls Suffers Ransomware Attack
🔥
Infusion Firm Faces Lawsuit After Hackers Hit Parent Company
🔥
Ransomware Now Considered a “Crisis” in the Financial Services Sector
🔥
Pharma Industry Seeing Reduction in Data Breach Costs, But Still Have Much to Do
🔥
Microsoft breach led to theft of 60,000 US State Dept emails
🔥
Study Reveals Conti Affiliates Money Laundering Practices
🔥
Combating Ransomware Attacks: Insights from Unit 42 Incident Response
🕵️
The Right Skills For The Job - Kayla Williams - PSW #800
🕵️
ISC Stormcast For Thursday, September 28th, 2023 https://isc.sans.edu/podcastdetail/8678, (Thu, Sep 28th)
🕵️
BlackTech APT Hackers Break into Cisco Firmware to Attack the US and Japan
🕵️
China-Linked Budworm Targeting Middle Eastern Telco and Asian Government Agencies
🕵️
Chinese State-Sponsored BlackTech Hackers Caught Hiding in Cisco Router Firmware
🕵️
Sysdig Launches Realtime Attack Graph for Cloud Environments
🕵️
Cannot Depend on Dependabot: Found Contributing Malicious Code
🕵️
SpecterOps to use in-house approximation to test for global attack variations
🕵️
[Cybersecurity Awareness Month] Frankenphisher – The Monster of Social Engineering Artificial Intelligence
🕵️
[HEADS UP] If You're a LastPass User, You May be the Next Phishing Email Target
🕵️
New Threat Actor Impersonates the Red Cross to Deliver Malware
🕵️
Case Study: Blocking Botnet-Driven Low-Rate HTTP DDoS Attacks
🕵️
Budworm hackers target telcos and govt orgs with custom malware
🕵️
Verisoul Raises $3.25 Million in Seed Funding to Detect Fake Users
🕵️
Lumu Raises $30 Million for Threat Detection and Response Platform
🕵️
Moving From Qualitative to Quantitative Cyber Risk Modeling
🕵️
Russian Hackers Target Ukrainian Government Systems Involved in War Crimes Investigations
🕵️
Zero-Point Fonts in Phishing Emails
🕵️
Cyber Insurance Claims Increased by 12% in First Half of 2023, Attacks More Frequent and Severe Than Ever
🕵️
Progress Software Patches Critical Pre-Auth Flaws in WS_FTP Server Product
🕵️
It’s Official – Generative AI Has Made Phishing Emails Foolproof
🕵️
Threat Group UNC3944 Continues to See Success Using Text-Based Social Engineering
🕵️
Facebook Messenger Becomes the Delivery Mechanism for Infostealer Malware Attack
🕵️
[Heads Up] China Invests Billions in Huge Global Disinformation Campaign
🕵️
SaaS Security in the Golden Age of SaaS - Yoni Shohet - ESW #333
🕵️
Nord Security Raises $100M on $3B Valuation to Go After M&A
🕵️
Security's Role in Edge Computing Today - Theresa Lanowitz, Chris Goettl - ESW #333
🕵️
Join the new Microsoft Security experience at Microsoft Ignite 2023
🌐
Fake Bitwarden Site Distributes Novel RAT Malware
🌐
Bing Chat responses infiltrated by ads pushing malware
🎙️
Transatlantic Cable podcast, episode 316 | Kaspersky official blog
📡
AWS Graviton Use Cases
📡
IPv4 Addresses in Little Endian Decimal Format, (Thu, Sep 28th)
📡
Gem Security Raises $23M for Its Cloud Security Platform
📡
RICO Class-Action Data Privacy Lawsuit Filed Against H&R Block, Google, Meta
📡
KSOC says it’s tackling cloud-native security in a way that is Kubernetes-first
📡
New Marvin Attack Impacts 25-Year-Old PKCS#1 v1.5 Padding Scheme for RSA Key Exchange
📡
Cybersecurity firm Lumu raises $30M to detect network intrusions
📡
Security researcher stopped at US border for investigating crypto scam
📡
Nexusflow raises $10.5 to build a conversational interface for security tools
📡
How to Improve Cybersecurity Awareness and Training
📡
Cisco Catalyst SD-WAN Manager flaw allows remote server access
📡
Caesars Entertainment Faces Class Action Lawsuits Following Rewards Database Hack
📡
SSH Keys Stolen by Stream of Malicious PyPI and npm Packages
📡
Right Wing Elon Scraps Tool To Report Electoral Fake News
📡
After Failing At Privacy Again, Google Is Working To Keep Bard Chats Out Of Search
📡
Millions of Files With Potentially Sensitive Information Exposed Online, Researchers Say
📡
Are Developers Giving Enough Thought to Prompt Injection Threats When Building Code?
📡
Cyber Resilient 911 Symposium
📡
Region 8 Invites You to Secure Our World