98Articles
8Categories
2023-09-29Date
🚨
CISA Warns of Old JBoss RichFaces Vulnerability Being Exploited in AttacksCISA has added CVE-2018-14667, an old critical JBoss RichFaces flaw to its known exploited vulnerabilities catalog. The post CISA Warns of Old JBoss RichFaces Vulnerability Being Exploited in Attacks appeared first on SecurityWeek .
KEV
🚨
Transforming Vulnerability Management: CISA Adds OASIS CSAF 2.0 Standard to ICS Advisories
πŸ›
Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts
KEV
πŸ›
Progress Software Releases Urgent Hotfixes for Multiple Security Flaws in WS_FTP Server
πŸ›
Progress Software Patches Critical Pre-Auth Flaws in WS_FTP Server Product
πŸ›
Hackers Set Sights on Apache NiFi Flaw That Exposes Many Organizations to Attacks
πŸ›
Chromium: CVE-2023-1999 Use after free in libwebp
πŸ›
Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
πŸ›
Chromium: CVE-2023-5186 Use after free in Passwords
πŸ›
Chromium: CVE-2023-5187 Use after free in Extensions
⚠️
Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts
KEV
⚠️
Cyber Security Today, Sept. 29, 2023 - Protect your routers from this attacker, new open source malware packages found, and more
⚠️
Progress Software Says Business Impact β€˜Minimal’ From MOVEit Attack Spree
⚠️
Budworm Strikes Again: Updated SysUpdate Targets Government and Telecom Sectors
⚠️
Hackers Set Sights on Apache NiFi Flaw That Exposes Many Organizations to Attacks
⚠️
Nexusflow Raises $10.6m to Build Conversational Interface for Security Tools
⚠️
UK data regulator orders end to spreadsheet FOI requests after serious data breaches
⚠️
A New Chrome 0-Day Is Sending The Internet Into A New Chapter Of Groundhog Day
⚠️
Splunk Acquisition and The Blob with Allie Mellen - ESW #333
⚠️
IronNet Ceases Operations, Terminates All Remaining Staffers
⚠️
Generative AI Startup Nexusflow Raises $10.6 Million
⚠️
Mozilla Releases Security Updates for Multiple Products
⚠️
Exploit released for Microsoft SharePoint Server auth bypass flaw
⚠️
Inside Look: FDA's Cyber Review Process for Medical Devices
⚠️
Millions of Exim mail servers exposed to zero-day RCE attacks
⚠️
Vulns Found In Another Progress Software File Transfer App
⚠️
The Week in Ransomware - September 29th 2023 - Dark Angels
⚠️
CrowdStrike Boosts Israeli Startup Ties With AWS Partnership
πŸ“’
Bsides Leeds 2023 - 28 talks
πŸ“’
Zero Trust, Auditability and Identity Governance
πŸ“’
NIST Publishes Final Version of 800-82r3 OT Security Guide
πŸ“’
GitLab security advisory (AV23-591)
πŸ“’
Tech Industry Leaders and White House Clash Over Plan for Improved Cloud Security
πŸ“’
Kuwait isolates some government systems following attack on its Finance Ministry
πŸ“’
Progress security advisory (AV23-592)
πŸ“’
Editors' Panel: What Impact Will Cisco's Splunk Acquisition Have on Industry?
πŸ“’
CISA and UK NCSC Hold Inaugural Meeting of Strategic Dialogue on Cybersecurity of Civil Society Under Threat of Transnational Repression
πŸ“’
ROUNDTABLE: CISA’s prominent role sharing threat intel could get choked off this weekend
πŸ”₯
More than 3.8 billion records exposed in DarkBeam data leak
πŸ”₯
Chinese hackers stole emails from US State Dept in Microsoft breach, Senate staffer says
πŸ”₯
Infusion Firm Faces Lawsuit After Hackers Hit Parent Company
πŸ”₯
Booking.com Customers Hit by Phishing Campaign Delivered Via Compromised Hotels Accounts
πŸ”₯
FBI Warns Organizations of Dual Ransomware, Wiper Attacks
πŸ”₯
Johnson Controls Hit by Ransomware
πŸ”₯
Lazarus hackers breach aerospace firm with new LightlessCan malware
πŸ”₯
FBI Warns Organizations of Dual Ransomware, Wiper Attacks
πŸ”₯
Johnson Controls Hit By Ransomware
πŸ”₯
City of Fort Lauderdale, Florida, Taken for $1.2m in Email Scam
πŸ”₯
Cyber Security Today, Week in Review for the week ending Friday, Sept. 28 ,20023
πŸ•΅οΈ
US State Department Says 60,000 Emails Taken in Alleged Chinese Hack
πŸ•΅οΈ
ISC Stormcast For Friday, September 29th, 2023 https://isc.sans.edu/podcastdetail/8680, (Fri, Sep 29th)
πŸ•΅οΈ
BlackTech APT Breaks in Cisco Routers, Targets U.S. and Japanese Companies
πŸ•΅οΈ
APT34 Deploys Phishing Attack With New Malware
πŸ•΅οΈ
Podcast: How to detect software supply chain attacks with Honeytokens? - Cloud Native Security Series - 20 minutes
πŸ•΅οΈ
Wifi without internet on a Southwest flight
πŸ•΅οΈ
Budworm: APT Group Uses Updated Custom Tool in Attacks on Government and Telecoms Organization
πŸ•΅οΈ
Cloudflare Users Exposed to Attacks Launched From Within Cloudflare: Researchers
πŸ•΅οΈ
A Key US Government Surveillance Tool Should Face New Limits, a Divided Privacy Oversight Board Says
πŸ•΅οΈ
[Live Demo] Ridiculously Easy Security Awareness Training and Phishing
πŸ•΅οΈ
Lazarus Group Impersonates Recruiter from Meta to Target Spanish Aerospace Firm
πŸ•΅οΈ
Your KnowBe4 Fresh Content Updates from September 2023
πŸ•΅οΈ
ZeroFont Phishing: Hackers Manipulating Font Size to Bypass Office 365 Security
πŸ•΅οΈ
National Security Agency is Starting an Artificial Intelligence Security Center
πŸ•΅οΈ
Lazarus APT Lures Employees of Spanish Aerospace Company with Trojanized Coding Challenges
πŸ•΅οΈ
In Other News: RSA Encryption Attack, Meta AI Privacy, ShinyHunters Hacker Guilty Plea
πŸ•΅οΈ
Researchers Extract Sounds From Still Images on Smartphone Cameras
πŸ•΅οΈ
Cybercriminals Using New ASMCrypt Malware Loader Flying Under the Radar
πŸ•΅οΈ
NarcBots, Blacktech, ZenRat, Chrome, CISOs, Privacy, More News & Aaran Leyland - SWN #329
πŸ•΅οΈ
AWS Using MadPot Decoy System to Disrupt APTs, Botnets
πŸ•΅οΈ
Critical Progress Bug Infests WS_FTP Software
πŸ•΅οΈ
NSA Stands Up New Organization to Harness AI
πŸ•΅οΈ
Security Awareness Is Dead. Long Live Security Awareness
πŸ•΅οΈ
Friday Squid Blogging: Protecting Cephalopods in Medical Research
πŸ•΅οΈ
Bankrupt IronNet Shuts Down Operations
πŸ•΅οΈ
How Lazarus impersonated Meta to attack a target in Spain – Week in security with Tony Anscombe
πŸ•΅οΈ
Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company
🌐
Are You Still Storing Passwords In Plain Text Files?, (Fri, Sep 29th)
🌐
Microsoft's AI-Powered Bing Chat Ads May Lead Users to Malware-Distributing Sites
🌐
Malicious Ads Served Inside Bing's AI Chatbot to Infect Victims with Malware
🌐
ZeroFont trick makes users think that message has been scanned for threats
πŸ“‘
Nord Security Raises $100M on $3B Valuation to Go After M&A
πŸ“‘
Security Researcher Stopped at US Border for Investigating Crypto Scam
πŸ“‘
Stealing Credentials Through Legitimate Dropbox Pages
πŸ“‘
Asian Banks are a Favorite Target of Cybercooks, and Malicious Bots Their Preferred Tool
πŸ“‘
NSA is Creating a Hub for AI Security, Nakasone Says
πŸ“‘
Post-Quantum Cryptography: Finally Real in Consumer Apps?
πŸ“‘
Discord is investigating cause of β€˜You have been blocked’ errors
πŸ“‘
Russian Flight Booking System Leonardo Suffers Massive DDoS Attack
πŸ“‘
Beware of scammers! Dangerous apps in the App Store | Kaspersky official blog
πŸ“‘
Misconfigured AWS Storage Bucket of WSBC Leaks 4,600 Passports
πŸ“‘
The NSA Is Starting An Artificial Intelligence Security Center
πŸ“‘
Chinese Snoops Stole 60,000 State Department Emails
πŸ“‘
Russian State Hackers Attempted To Block Ukrainians From Opening US Bank Accounts
πŸ“‘
Norway Wants Facebook Behavioral Advertising Banned Across Europe
πŸ“‘
ShinyHunters member pleads guilty to $6 million in data theft damages
πŸ“‘
Three men found guilty of laundering $2.5 million in Target gift card tech support scam
πŸ“‘
What Happens to Government Devices During a Shutdown?
πŸ“‘
Defending Democracy and Standing Up for Civil Society