161Articles
8Categories
2023-12-12Date
πŸ›
New Critical RCE Vulnerability Discovered in Apache Struts 2 - Patch Now
πŸ›
50K WordPress Sites Exposed to RCE Attacks by Critical Bug in Backup Plugin
πŸ›
Sophos backports RCE fix after attacks on unsupported firewalls
πŸ›
Hardening cellular basebands in Android
πŸ›
CVE-2023-36696 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2023-36391 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
πŸ›
CVE-2023-36020 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
πŸ›
CVE-2023-36009 Microsoft Word Information Disclosure Vulnerability
πŸ›
CVE-2023-36011 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2023-20588 AMD: CVE-2023-20588 AMD Speculative Leaks Security Notice
πŸ›
CVE-2023-35625 Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability
πŸ›
CVE-2023-21740 Windows Media Remote Code Execution Vulnerability
πŸ›
CVE-2023-36019 Microsoft Power Platform Connector Spoofing Vulnerability
πŸ›
CVE-2023-36010 Microsoft Defender Denial of Service Vulnerability
πŸ›
CVE-2023-36012 DHCP Server Service Information Disclosure Vulnerability
πŸ›
CVE-2023-36003 XAML Diagnostics Elevation of Privilege Vulnerability
πŸ›
CVE-2023-36004 Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
πŸ›
CVE-2023-36005 Windows Telephony Server Elevation of Privilege Vulnerability
πŸ›
CVE-2023-36006 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2023-35638 DHCP Server Service Denial of Service Vulnerability
πŸ›
CVE-2023-35639 Microsoft ODBC Driver Remote Code Execution Vulnerability
πŸ›
CVE-2023-35641 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
πŸ›
CVE-2023-35642 Internet Connection Sharing (ICS) Denial of Service Vulnerability
πŸ›
CVE-2023-35643 DHCP Server Service Information Disclosure Vulnerability
πŸ›
CVE-2023-35644 Windows Sysmain Service Elevation of Privilege
πŸ›
CVE-2023-35628 Windows MSHTML Platform Remote Code Execution Vulnerability
πŸ›
CVE-2023-35629 Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability
πŸ›
CVE-2023-35630 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
πŸ›
CVE-2023-35631 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2023-35632 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2023-35633 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2023-35634 Windows Bluetooth Driver Remote Code Execution Vulnerability
πŸ›
CVE-2023-35635 Windows Kernel Denial of Service Vulnerability
πŸ›
CVE-2023-35636 Microsoft Outlook Information Disclosure Vulnerability
πŸ›
CVE-2023-35619 Microsoft Outlook for Mac Spoofing Vulnerability
πŸ›
CVE-2023-35621 Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
πŸ›
CVE-2023-35622 Windows DNS Spoofing Vulnerability
πŸ›
CVE-2023-35624 Azure Connected Machine Agent Elevation of Privilege Vulnerability
πŸ›
Atlassian patches critical remote code execution vulnerabilities in multiple products
KEV
πŸ›
The Apache Software Foundation Updates Struts 2
πŸ›
Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally
⚠️
Lazarus Group Using Log4j Exploits to Deploy Remote Access Trojans - RedPacket Security
⚠️
World's First CISO Dies as SEC Turns Up Enforcement on Cybersecurity - BSW #331
⚠️
The Impact of the New SEC Regulations on Cybersecurity - BSW #331
⚠️
Apple Releases Security Updates to Patch Critical iOS and macOS Security Flaws
⚠️
Kubescape Open-Source Project Adds Vulnerability Exploitability eXchange (VEX) Support
⚠️
Apple Releases Security Updates to Patch Critical iOS and macOS Security Flaws
⚠️
WordPress Plugin Flaw Exposes 90K+ Websites to Hack Attack
⚠️
SyzGPT: When the fuzzer meets the LLM
⚠️
The SEC action against SolarWinds highlights how tough it can get for CISOs
KEV
⚠️
DEF CON 23 (2015) - Chris Domas - Repsych: Psychological Warfare in Reverse Engineering
⚠️
The Art of Code by Dylan Beattie (2022)
⚠️
Snyk unveils new ASPM offering to help DevSecOps manage cloud application risks
⚠️
Gamers Warned of Potential CS2 Exploit That can Reveal IP Addresses
⚠️
ICS Patch Tuesday: Electromagnetic Fault Injection, Critical Redis Vulnerability
⚠️
Air Force Disciplines 15 as IG Finds That Security Failures Led to Massive Classified Documents Leak
⚠️
CISA Releases SCuBA Google Workspace Secure Configuration Baselines for Public Comment
⚠️
Flaws in Backup Migration and Elementor WordPress Plugins Allow Remote Code Execution
⚠️
Over 1,450 pfSense servers exposed to RCE attacks via bug chain
⚠️
Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign
⚠️
Over 1,450 pfSense Servers Exposed to RCE Attacks via Bug Chain
⚠️
CISA Releases Two Industrial Control Systems Advisories
⚠️
Russia Weaponizes Israel-Hamas Conflict in Targeted Phishing Attack
⚠️
Ukraine’s intelligence claims cyberattack on Russia’s state tax service
⚠️
The ABCs of RFCs - Heather Flanagan - ASW #266
⚠️
Apple Releases Security Updates for Multiple Products
⚠️
Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
⚠️
SAP Patches Critical Vulnerability in Business Technology Platform
⚠️
Microsoft Patch Tuesday December 2023, (Tue, Dec 12th)
⚠️
Microsoft Patch Tuesday: Critical Spoofing and Remote Code Execution Flaws
⚠️
FCC reminds mobile phone carriers they must do more to prevent SIM swaps
⚠️
Microsoft Patch Tuesday, December 2023 Edition
⚠️
Adobe Releases Security Updates for Multiple Products
⚠️
Microsoft Releases Security Updates for Multiple Products
⚠️
Lazarus Exploits Log4Shell to Deploy Telegram-Based Malware
⚠️
A Vulnerability in the Backup Migration Plugin for WordPress Could Allow for Remote Code Execution
⚠️
Critical Patches Issued for Microsoft Products, December 12, 2023
⚠️
Multiple Vulnerabilities in Atlassian Products Could Allow for Remote Code Execution
πŸ“‹
Adobe Patches 207 Security Bugs in Mega Patch Tuesday Bundle
πŸ“‹
From Microsoft to you, 33 packages
πŸ“’
A Note on progress…NIST’s Digital Identity Guidelines.
πŸ“’
CISA Seeks Public Comment on Newly Developed Secure Configuration Baselines for Google Workspace
πŸ“’
Why Financial Institutions Are Adopting the CRI Profile
πŸ“’
Rumble Fights Off Unprecedented Cyberattack, Likely An Attempt To Censor Creators, CEO Says
πŸ“’
HPE security advisory (AV23-755)
πŸ“’
SAP security advisory – December 2023 monthly rollup (AV23-756)
πŸ“’
Findings and Updates from CISA’s Ongoing Collaboration with Education Technology Vendors to Address K-12 Cybersecurity Challenges
πŸ“’
Fortinet security advisory (AV23-757)
πŸ“’
[Control systems] Schneider Electric security advisory (AV23-754)
πŸ“’
Microsoft security advisory – December 2023 monthly rollup (AV23-758)
πŸ“’
Addressing Privacy and Data-Sharing Hurdles in Healthcare AI
πŸ“’
[Control systems] Siemens security advisory (AV23-760)
πŸ“’
Adobe security advisory (AV23-759)
πŸ“’
Strengthening identity protection in the face of highly sophisticated attacks
πŸ”₯
InflateVids - 13,405 breached accounts
πŸ”₯
A Gigantic New ICBM Will Take US Nuclear Missiles Out of the Cold War-Era but Add 21st-Century Risks
πŸ”₯
LockBit Ransomware Group Alleges LivaNova PLC Data Breach
πŸ”₯
HHS Agrees to $480,000 Settlement With Louisiana Medical Group Over Data Breach
πŸ”₯
Greece Plans National Cybersecurity Authority to Combat Rising Hacker Threats
πŸ”₯
Update: Henry Schein Says 29K People Affected in September Cyberattack
πŸ”₯
White House Wants to Set Minimum Cyber Standards for Hospitals, Healthcare
πŸ”₯
TV Service in UAE Hacked to Show Alleged Atrocities in Palestine
πŸ”₯
Toyota Germany Confirms Personal Information Stolen in Ransomware Attack
πŸ”₯
FBI Issues Guidance for Delaying SEC-Required Data Breach Disclosure
πŸ”₯
Toyota Financial Services Discloses Data Breach Affecting German Customers
πŸ”₯
Nearly 130,000 Affected by Ransomware Attack on Cold Storage Company Americold
πŸ”₯
Non-Human Access is the Path of Least Resistance: A 2023 Recap
πŸ”₯
Toyota Ransomware Attack Exposes Customers Personal Data
πŸ”₯
North Ireland Cops Count Human Cost Of August Data Breach
πŸ”₯
Toyota Germany Says Customer Data Stolen In Ransomware Attack
πŸ”₯
Ukraine's largest mobile carrier Kyivstar down following cyberattack
πŸ”₯
Ukraine’s largest mobile operator Kyivstar downed by β€˜powerful’ cyberattack
πŸ”₯
Bitcoin ATM company Coin Cloud got hacked. Even its new owners don’t know how
πŸ”₯
Top Ukrainian Mobile Operator Kyivstar Hit by Cyberattack
πŸ”₯
Northern Ireland's Police Service to Revamp Cybersecurity
πŸ”₯
Ukrainian military says it hacked Russia's federal tax agency
πŸ”₯
Cyberattack Cripples Ukraine’s Largest Telcom Operator
πŸ”₯
UK Downplays Ransomware Threat at Its Peril, Says Committee
πŸ•΅οΈ
ISC Stormcast For Tuesday, December 12th, 2023 https://isc.sans.edu/podcastdetail/8774, (Tue, Dec 12th)
πŸ•΅οΈ
What is CloudSecOps? – A Complete Security Operations Guide – 2024
πŸ•΅οΈ
Shaping our children's education in computing" by Simon Peyton Jones (2018)
πŸ•΅οΈ
Bret Victor The Future of Programming (2013)
πŸ•΅οΈ
New Windows/Linux Firmware Attack
πŸ•΅οΈ
James Powell: So you want to be a Python expert? | PyData Seattle 2017
πŸ•΅οΈ
New malware is using direct emails to hunt the head-hunters
πŸ•΅οΈ
Sandman Cyberespionage Group Linked to China
πŸ•΅οΈ
CyberheistNews Vol 13 #50 [Heads Up] Don't Be Fooled by This Sneaky Disney+ Phishing Scam
πŸ•΅οΈ
Is there really an Information Security Jobs Crisis? - Ben Rothke - CSP #152
πŸ•΅οΈ
Threat Actor TA4557 Targets Recruiters With Malware
πŸ•΅οΈ
Cybertruck, Viagra, Struts, Atlassian, Log4Shell, Pharmacies, Jason Wood, and More – SWN #348
πŸ•΅οΈ
Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign
πŸ•΅οΈ
Apple Sets Trap to Catch iMessage Impersonators
πŸ•΅οΈ
Who's Calling? Spam, Scams and Wasted Time
πŸ•΅οΈ
Unwrapping the Threat: AI-Powered Phishing Attacks Take Center Stage in 2023 Holidays
πŸ•΅οΈ
News alert: Detectify’s EASM research reveals top overlooked vulnerabilities from 2023
πŸ•΅οΈ
Cybertruck, Viagra, Struts, Atlassian, Log4Shell, Pharmacies, Jason Wood, and More - SWN #348
πŸ•΅οΈ
Prompt Injection Scanners, Better AI Jailbreaks, Purple Llama, Linux Kernel Security - ASW #266
πŸ•΅οΈ
Microsoft: OAuth apps used to automate BEC and cryptomining attacks
πŸ•΅οΈ
Threat actors misuse OAuth applications to automate financially driven attacks
🌐
New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam
🌐
Kelvin Security cybercrime gang suspect seized by Spanish police
🌐
Unveiling the Cyber Threats to Healthcare: Beyond the Myths
πŸ“‘
Amazon Sues REKK Fraud Gang That Stole Millions in Illicit Refunds
πŸ“‘
UK Police Return $10 Million in Bitcoin Stolen by Chronically-Ill Bed-Bound Thief
πŸ“‘
Leader of Russian Hacktivist Group Killnet β€˜Retires,’ Appoints New Head
πŸ“‘
Cybercriminals Continue Targeting Open Remote Access Products
πŸ“‘
Security Automation Gains Traction, Prompting a β€œShift Everywhere” Philosophy
πŸ“‘
Long-Running Clearview AI Class Action Biometric Privacy Case Settles
πŸ“‘
Fake LinkedIn Profiles Target Saudi Workers for Information Leakage and Financial Fraud
πŸ“‘
Apple Ships iOS 7.2 With Urgent Security Patches
πŸ“‘
Atlassian Warns Of Four New Critical Vulnerabilities
πŸ“‘
Cybercriminals Are Using Wyoming Shell Companies For Global Hacks
πŸ“‘
Cloud engineer gets 2 years for wiping ex-employer’s code repos
πŸ“‘
Practitioner guidance for securing Microsoft Active Directory services in your organization - ITSP.60.100
πŸ“‘
How criminals disguise URLs | Kaspersky official blog
πŸ“‘
Windows 10 KB5033372 update released with Copilot for everyone, 20 changes
πŸ“‘
Windows 11 update KB5033375 released with upgraded Copilot AI-assistant
πŸ“‘
How the EU Cyber Resilience Act Impacts Manufacturers
πŸ“‘
Windows 11 KB5033375 update released with upgraded Copilot AI-assistant
πŸ“‘
Avira antivirus causes Windows computers to freeze after boot
πŸ“‘
A pernicious potpourri of Python packages in PyPI