103Articles
9Categories
2023-10-27Date
🚨
CISA Updates Guidance for Addressing Cisco IOS XE Web UI Vulnerabilities With Additional ReleasesToday, CISA updated its guidance addressing two vulnerabilities, CVE-2023-20198 and CVE-2023-20273 , affecting Cisco’s Internetworking Operating System (IOS) XE Software Web User Interface (UI). The guidance now notes that Cisco has fixed these vulnerabilities for the 17.6 Cisco …
KEV
πŸ›
VMware warns of critical vulnerability affecting vCenter Server product
πŸ›
Apple issued another patch to stop TriangleDB cyber snooping
KEV
πŸ›
F5 Issues Warning: BIG-IP Vulnerability Allows Remote Code Execution
πŸ›
F5 Issues Warning Over BIG-IP Vulnerability That Allows Remote Code Execution
πŸ›
F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP
πŸ›
F5 fixes BIG-IP auth bypass allowing remote code execution attacks
πŸ›
VMware Tools Flaw Let Attackers Escalate Privileges
πŸ›
Chromium: CVE-2023-5472: Use after free in Profiles
πŸ›
CVE-2023-44323 Adobe: CVE-2023-44323 Adobe PDF Remote Code Execution Vulnerability
⚠️
Dissecting TriangleDB, a Triangulation spyware implant
⚠️
Okta’s Latest Security Breach Is Haunted by the Ghost of Incidents Past
⚠️
iLeakage attack steals passwords, texts from Apple devices
⚠️
Finding You: The Network Effect of Telecommunications Vulnerabilities for Location Disclosure
⚠️
Novel Zero-Day Exploits Fuel Q3 Surge in DDoS Attacks
⚠️
Failure to verify OAuth tokens enables account takeover on websites
⚠️
Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023
⚠️
Google Expands Its Bug Bounty Program to Tackle Artificial Intelligence Threats
⚠️
Record-Breaking 100 Million RPS DDoS Attack Exploits HTTP/2 Rapid Reset Flaw
⚠️
iLeakage Attack Exploits Safari To Steal Sensitive Data From Macs, iPhones
⚠️
Cybersecurity Resilience Quotient Metric for Measuring Security Effectiveness
⚠️
CISA Announces Launch of Logging Made Easy
⚠️
N. Korean Lazarus Group Targets Software Vendor Using Known Flaws
⚠️
Apple fixes bug that undermined iOS privacy feature for years
⚠️
Stripedfly Malware Framework Infects One Million Windows, Linux Hosts
⚠️
North Korean Lazarus Group Targets Software Vendor Using Known Flaws
⚠️
Putting Censorship Circumvention to the Test: Security Audit Findings | Tor Project
⚠️
CISA: Agencies Seeing Steep Decrease in Known Exploited Vulnerabilities on Federal Networks
KEV
⚠️
News alert: Massachusetts awards $2.3 million grant to strengthen cybersecurity ecosystem statewide
⚠️
CCleaner says hackers stole users’ personal data during MOVEit mass-hack
⚠️
Hackers earn over $1 million for 58 zero-days at Pwn2Own Toronto
⚠️
Careless OAuth Implementation Puts Billions at Risk
⚠️
Exabeam Lays Off 20% of Staff, F-Secure to Ax Up to 70 Staff
⚠️
UK's Ofcom Prepares to Enforce Online Safety Bill
⚠️
CISA Launches Logging Tool For Resource-Poor Organizations
⚠️
Roundcube Webmail servers under attack – Week in security with Tony Anscombe
⚠️
What keeps incident responders up at night: Common pitfalls that cyber responders encounter when arriving at the scene
πŸ“’
IOTW: DDoS attacks hit Czech ministries, pro-Russia group allegedly behind them
πŸ“’
Messaging Service Wiretap Discovered through Expired TLS Cert
πŸ“’
UN Chief Appoints 39-Member Panel to Advise on International Governance of Artificial Intelligence
πŸ“’
How to Keep Your Business Running in a Contested Environment
πŸ“’
[Live Demo] Customizing Your Compliance Training to Increase Effectiveness
πŸ“’
CISA Announces New Release of Logging Made Easy
πŸ“’
UK: NCSC Rolls Out Protective DNS Service for Schools
πŸ“’
VMware security advisory (AV23-657)
πŸ“’
FTC Expands Financial Data Breach Reporting Requirements
πŸ“’
[Control systems] NextGen HealthCare security advisory (AV23-659)
πŸ“’
Mozilla security advisory (AV23-658)
πŸ“’
United Nations AI Body to Advise on Risks, Global Governance
πŸ”₯
New England Biolabs leak sensitive data
πŸ”₯
Hackers that breached Las Vegas casinos rely on violent threats, research shows
πŸ”₯
Update: Hackers Spent Three Months Accessing Philadelphia City Government Email Accounts
πŸ”₯
Cyber Security Today, Oct. 27, 2023 - Malware hiding as a cryptominer may have infected 1 million PCs since 2017
πŸ”₯
Russian Artists’ Spotify Accounts Defaced by Pro-Ukraine Hackers
πŸ”₯
Toumei - 76,682 breached accounts
πŸ”₯
Rising Global Tensions Could Portend Destructive Hacks
πŸ”₯
France Says Russian State Hackers Breached Numerous Critical Networks
πŸ”₯
FakeUpdateRU: New Malware Camouflaged as Fake Chrome Update
πŸ”₯
DuckTail Malware Spread via Fake Job Offers From Compromised LinkedIn Profiles
πŸ”₯
California City Warns of Data Breach After Attack Claim by NoEscape Ransomware
πŸ”₯
US Senator Quizzes 23andMe Over Credential-Stuffing Hack
πŸ”₯
Lazarus hackers breached dev repeatedly to deploy SIGNBT malware
πŸ”₯
The Week in Ransomware - October 27th 2023 - Breaking Records
πŸ”₯
Feds Warn Healthcare Sector of AI-Augmented Phishing Threats
πŸ•΅οΈ
Weekly Update 371
πŸ•΅οΈ
ISC Stormcast For Friday, October 27th, 2023 https://isc.sans.edu/podcastdetail/8720, (Fri, Oct 27th)
πŸ•΅οΈ
Malicious Android Apps on Google Play With Over 2 Million Installs
πŸ•΅οΈ
Your KnowBe4 Fresh Content Updates from October 2023
πŸ•΅οΈ
Have you accidentally hired a North Korean IT worker who’s spying on your company?
πŸ•΅οΈ
The evolution of 20 years of cybersecurity awareness
πŸ•΅οΈ
Security Onion Conference 2023 - 7 videos
πŸ•΅οΈ
In Other News: Ex-NSA Employee Spying for Russia, EU Threat Landscape, Cyber Education Funding
πŸ•΅οΈ
Advanced β€˜StripedFly’ Malware With 1 Million Infections Shows Similarities to NSA-Linked Tools
πŸ•΅οΈ
New Amazon-Themed Phishing Campaign Targets Microsoft Live Outlook Users
πŸ•΅οΈ
Now Android and Windows devices aren't safe from Flipper Zero either
πŸ•΅οΈ
Cure53 | Pentest-Report Tor Browser & OONI 02.-03.2023
πŸ•΅οΈ
Pumpkin Spice, VMWARE, RoundCube, Apple, Big-IP, Oktapus, Aaran Leyland and More - SWN #337
πŸ•΅οΈ
Friday Squid Blogging: On the Ugliness of Squid Fishing
πŸ•΅οΈ
ISMG Editors: Business, Cyber Resilience in Israel-Hamas War
πŸ•΅οΈ
StripedFly worming miner hides sophisticated code and espionage-ready capabilities
πŸ•΅οΈ
Cloudflare mitigated 89 hyper-volumetric HTTP distributed DDoS attacks exceeding 100 million rps
🌐
Android Adware Apps on Google Play Amass Two Million Installs
🌐
Apple Drops Urgent Patch Against Obtuse TriangleDB iPhone Malware
🌐
Report: Consumers are Taking Action to Protect Their Privacy
🌐
Humans Need to Rethink Trust in the Wake of Generative AI
🌐
5 Strategies to Protect Your Software Development Teams from Software Supply Chain Attacks
πŸŽ™οΈ
Cyber Security Today, Week in Review for the week ending Friday, Oct. 27, 2023
πŸ“‘
How Kopeechka, an Automated Social Media Accounts Creation Service, Can Facilitate Cybercrime
πŸ“‘
Nigerian Police Dismantle Major Cybercrime Hub
πŸ“‘
Cranium Announces $25 Million in Series A Funding to Secure AI
πŸ“‘
New Project Analyzes and Catalogs Vendor Support for Secure PLC Coding
πŸ“‘
Security Leaders Have Good Reasons to Fear AI-Generated Attacks
πŸ“‘
Report: Security Not a Priority For a Third of SMBs
πŸ“‘
In-Home Hospitality App Hello Alfred Exposes User Data
πŸ“‘
Crypto King Tells Judge He Acted On Legal Advice
πŸ“‘
iPhones Have Been Exposing Your Unique MAC Despite Apple's Promises Elsewise
πŸ“‘
Hackers Earn $350k On Second Day Of Pwn2Own Toronto 2023
πŸ“‘
Microsoft Unveils Shady Shenanigans Of Octo Tempest
πŸ“‘
Windows 11 KB5031455 preview update enables Moment 4 features by default
πŸ“‘
Internet access in Gaza is collapsing as ISPs fall offline
πŸ“‘
Microsoft 365 users get workaround for β€˜Something Went Wrong’ errors
πŸ“‘
SAS 2023: Key Research | Kaspersky official blog
πŸ“‘
The Federal Partnership for Interoperable Communications (FPIC) Releases the Transition to Advanced Encryption Standard White Paper