103Articles
9Categories
2023-10-04Date
🚨
CISA Adds Two Known Exploited Vulnerabilities to Catalog, Removes Five KEVsCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation: CVE-2023-42793 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability CVE-2023-28229 Microsoft Windows CNG Key Isolation Service Privilege Escalation…
KEV
🐛
Arm, Qualcomm warn GPU drivers are likely being exploited by hackers
🐛
Hackers seen exploiting bugs in browsers and popular file transfer tool
🐛
Qualcomm Releases Patch for Three New Zero-Days Under Active Exploitation
🐛
Looney Tunables: New Linux Flaw Enables Privilege Escalation on Major Distributions
🐛
New critical AI vulnerabilities in TorchServe put thousands of AI models at risk
🐛
Severe Glibc Privilege Escalation Vulnerability Impacts Major Linux Distributions
🐛
X.Org Hit By New Security Vulnerabilities - Two Date Back To 1988 With X11R2
🐛
Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11 (CVE-2023-38545) · curl/curl · Discussion #12026
🐛
PoC exploit for CVE-2023-4911 "Looney Tunables"
🐛
Chromium: CVE-2023-5346 Type Confusion in V8
⚠️
Experts Discover Multiple Malicious npm Packages
⚠️
New ‘Looney Tunables’ Linux Bug Gives Root Privileges on Major Distros
⚠️
Safe, Secure, Anonymous, and Other Misleading Claims
⚠️
Qualcomm Patches 3 Zero-Days Reported by Google
⚠️
ChatGPT “not a reliable” tool for detecting vulnerabilities in developed code
⚠️
Microsoft Warns of Cyber Attacks Attempting to Breach Cloud via SQL Server Instance
⚠️
Rogue npm Package Deploys Open-Source Rootkit in New Supply Chain Attack
⚠️
Okta launches Cybersecurity Workforce Development Initiative
⚠️
Dead Grandma Locket Request Tricks Bing Chat’s AI Into Solving Security Puzzle
⚠️
Typosquatting Campaign Delivers R77 Rootkit Through Malicious JavaScript Package
⚠️
Open-Source Intelligence (OSINT): Learn the Methods Bad Actors Use to Hack Your Organization
⚠️
Qualcomm Patches 3 Zero Days Reported By Google
⚠️
Sony Confirms Data Breach Impacting Thousands of US Employees
⚠️
Researchers Link DragonEgg Android Spyware to LightSpy iOS Surveillanceware
⚠️
Cisco fixes hard-coded root credentials in Emergency Responder
⚠️
Atlassian Ships Urgent Patch for Exploited Confluence Zero-Day
⚠️
Atlassian patches critical Confluence zero-day exploited in attacks
⚠️
Apple emergency update fixes new zero-day used to hack iPhones
⚠️
Apple Warns of Newly Exploited iOS 17 Kernel Zero-Day
⚠️
Apple fixes vulnerabilities in iOS and iPadOS., (Wed, Oct 4th)
⚠️
Microsoft won’t say if its products were exploited by spyware zero-days
⚠️
Cyber Mavens Slam Europe's Cyber Resilience Act
⚠️
Hundreds of malicious Python packages found stealing sensitive data
⚠️
Amazon Web Services Warns of TorchServe Flaws
⚠️
Attackers Exploit SQL Server to Penetrate Azure Cloud
📋
New Supermicro BMC Vulnerabilities Could Expose Many Servers to Remote Attacks
📢
C-Suite Leaders to Boost Cybersecurity Compliance Amid SEC Disclosure Rule: Deloitte
📢
NIST CSF (Cybersecurity Framework) 2.0 is just around the corner
📢
IBM security advisory (AV23-597)
📢
Google Chrome security advisory (AV23-598)
📢
CISA and NSA Release New Guidance on Identity and Access Management
📢
Cisco security advisory (AV23-599)
📢
Red Hat security advisory (AV23-600)
📢
Apple security advisory (AV23-601)
📢
Yesterday, Daniel J. Bernstein published a paper alleging that Kyber-512, an encryption algorithm selected as a NIST post-quantum contender, wasn't nearly as secure as its stewards say.
🔥
NATO 'actively addressing' alleged cyberattack affecting some websites
🔥
LightSpy Spyware Evolves to Add New Plugins for Data Exfiltration
🔥
Payment card details accessed in Motel One hack
🔥
Ransomware Reinfections on the Rise From Improper Remediation
🔥
Indiana Attorney General Sues Provider Over Violation of Consumer Protection, Privacy Laws
🔥
Wisconsin County Dealing With Ransomware Attack on Public Health Department
🔥
Make these 5 changes to avoid becoming the next cybersecurity headline
🔥
Sony confirms data breach impacting thousands in the U.S.
🔥
NATO Investigates Alleged Cyberattack Affecting Some Unclassified Websites
🔥
Lyca Mobile Services Significantly Disrupted by Cyberattack
🔥
Mozilla Warns of Fake Thunderbird Downloads Delivering Ransomware
🔥
Microsoft: Hackers target Azure cloud VMs via breached SQL servers
🔥
Lyca Mobile Suffers Disruptive Cyberattack; Investigates Ransomware Possibility
🔥
Arietis Health Announces MOVEit Data Breach Impacting Patients of NorthStar Anesthesia Facilities
🔥
Researchers warn of 100,000 industrial control systems exposed online
🔥
Mozilla Warns of Fake Thunderbird Downloads Delivering Ransomware
🔥
Lyca Mobile blames cyberattack for network disruption
🔥
Firm Notifies Patients of 55 Health Practices Hit by MOVEit Hack
🕵️
ISC Stormcast For Wednesday, October 4th, 2023 https://isc.sans.edu/podcastdetail/8686, (Wed, Oct 4th)
🕵️
Security at high speed - How Vipps secures their APIs - BSides Oslo 2023 - 45 minutes
🕵️
What are You Working on Wednesday
🕵️
Malicious Ads in Bing Chat
🕵️
EvilProxy Phishing Attack Targets Indeed
🕵️
Chinese APT41 Actors Target WeChat Users via Trojanized App Version
🕵️
What to know about new generative AI tools for criminals
🕵️
Google, Yahoo Boosting Email Spam Protections
🕵️
[Cybersecurity Awareness Month] Spoofy Steve's Business Email Compromise Scams You Need to Watch Out For
🕵️
AI and ML: The Keys to Better Security Outcomes
🕵️
Okta Buys Personal Password Manager Uno to Service Consumers
🕵️
US FTC Keeping 'Close Watch' on Artificial Intelligence
🕵️
North Korean Hackers Target South Korean Naval Shipyards
🕵️
STEPS FORWARD Q&A: Will ‘proactive security’ engender a shift to risk-based network protection?
🕵️
Protecting The Federal Supply Chain - John Loucaides - BTS #14
🕵️
Atos Taps Senior Accenture Exec to Run Eviden Security Group
🕵️
X.Org Hit By New Security Vulnerabilities - Two Date Back To 1988 With X11R2 - Hack Liberty
🌐
Cyber Security Today, Oct. 4, 2023 - Critical vulnerabilities found in Linux and TorchServe
🌐
EU Parliament Wants Journalists to Have Better Protections From Spyware
🌐
Predator Spyware Linked to Madagascar Government Ahead of Election
📡
ShellTorch Vulnerabilities Put Organizations at Risk of Server Takeover
📡
Don’t Let Zombie Zoom Links Drag You Down
📡
Emergency alert on US phones and TVs today — Don’t worry, it’s just a test
📡
The Hacker Perspective on Generative AI and Cybersecurity
📡
San Francisco Metropolitan Transportation Commission Leaves 26,000 Files Publicly Accessible
📡
Wing Disrupts the Market by Introducing Affordable SaaS Security
📡
Okta acquires a16z-backed password manager Uno to develop a personal tier
📡
Okta plans to weave AI across its entire identity platform using multiple models
📡
Yubico can now ship pre-registered security keys to its enterprise users
📡
Dark Web Sale of FBI LEEP Classified Data Sparks Concerns Over National Security
📡
Enhancing your application security program with continuous monitoring
📡
New Supermicro BMC Vulnerabilities Could Expose Many Servers To Remote Attacks
📡
Rules Of Engagement Issued To Hacktivists After Chaos
📡
TorchServe Flaws Means PyTorch Users Need An Urgent Upgrade
📡
Northern Ireland Police Issue “Quishing” Email Warning
📡
What is SD-WAN? | Kaspersky official blog
📡
Red Cross Tells Hacktivists: Stop Targeting Hospitals
📡
What's Normal? Connection Sizes, (Wed, Oct 4th)
📡
Sophos Firewall v20: VPN Enhancements