113Articles
8Categories
2023-12-19Date
🐛
8220 Gang Exploiting Oracle WebLogic Server Vulnerability to Spread Malware
🐛
Researchers Disclose Zero-Click Exploit for Microsoft Outlook
🐛
Hackers Actively Exploiting ActiveMQ Vulnerability to Install Malware
🐛
36 million people affected by data breach at Xfinity
🐛
Hackers steal data from millions of Xfinity customers via Citrix Bleed vulnerability
⚠️
How cybersecurity roles are changing and what to look for when hiring
⚠️
xorbot: A Stealthy Botnet Family That Defies Detection
⚠️
US Regulators Warn of AI Risk to Financial Systems
⚠️
Pro-Israel hacktivist group brings down 70% of gas stations in Iran
⚠️
Insights from the CISA Healthcare and Public Health Sector Risk and Vulnerability Assessment
⚠️
Microsoft Windows 10 security support extension no excuse to put off patching, asset review
⚠️
New SMTP Smuggling Attack Lets Hackers Send Spoofed Emails
⚠️
Xfinity Customer Data Compromised in Attack Exploiting CitrixBleed Vulnerability
⚠️
Comcast says hackers stole data of close to 36 million Xfinity customers
⚠️
US Agencies Release Security Guidance on Managing SBOMs and Open Source Software
⚠️
Authorities claim seizure of notorious ALPHV ransomware gang’s dark web leak site
⚠️
Novel SMTP Smuggling Technique Slips Past DMARC, Email Protections
⚠️
CyberheistNews Vol 13 #51 Phishing Is Still the No. 1 Attack Vector, With Huge 144% Malicious URL Spike
⚠️
Xfinity Discloses Massive Data Breach Affecting Over 35 Million People
KEV
⚠️
Xfinity Customer Data Compromised In Attack Exploiting CitrixBleed Vulnerability
⚠️
The lion’s share of CIOs cyber budgets must go to cloud security platforms
⚠️
FBI Takes Down BlackCat Ransomware, Releases Free Decryption Tool
⚠️
CISA Releases Seven Industrial Control Systems Advisories
⚠️
FBI warrant reveals ‘confidential source’ helped AlphV/Blackcat ransomware takedown
⚠️
Hacktivists say they shut down Iran's gasoline pumps
⚠️
Microsoft Discovers Critical RCE Flaw in Perforce Helix Core Server
⚠️
Making Service Meshes Work for People - Idit Levine - ASW #267
⚠️
Mr Cooper now says 15M people's data exposed in cyberattack
⚠️
Qakbot returns: FBI-led takedown lasts just 3 months
⚠️
Ledger JS library poisoned to steal $650K+ from wallets
⚠️
How the FBI seized BlackCat (ALPHV) ransomware’s servers
⚠️
#StopRansomware: ALPHV Blackcat
⚠️
Interpol operation arrests 3,500 cybercriminals, seizes $300 million
⚠️
Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE
⚠️
BlackCat Ransomware Raises Ante After FBI Disruption
⚠️
Report Says CISA is Failing to Identify High-Risk Exploits
KEV
📢
Double-Extortion Play Ransomware Strikes 300 Organizations Worldwide
📢
CISA Urges Manufacturers to Eliminate Default Passwords to Thwart Cyber Threats
📢
Tech Device Manufacturers Urged by CISA to Remove Default Passwords
📢
Cisco security advisory (AV23-774)
📢
Red Hat security advisory (AV23-773)
📢
Ransomware Attack on Westpole Disrupted Digital Services for Italian Public Administration
📢
FBI, CISA, and ACSC Release Joint Advisory on Play Ransomware
📢
Cyber Risk Management Starts with Risk Quantification - Padraic O'Reilly - BSW #332
📢
CISA and FBI Release Advisory on ALPHV Blackcat Affiliates
📢
Mozilla security advisory (AV23-776)
📢
Microsoft Edge security advisory (AV23-775)
📢
HPE security advisory (AV23-777)
📢
[Control systems] EFACEC security advisory (AV23-779)
📢
[Control systems] Subnet Solutions security advisory (AV23-778)
📢
[Control systems] Open Design Alliance security advisory (AV23-780)
📢
[Control systems] EuroTel security advisory (AV23-781)
📢
Apple security advisory (AV23-782)
🔥
Update: October Cyberattack Leaked Data of 14.7 Million People, Mortgage Giant Mr. Cooper Says
🔥
Alleged LockBit Operator to Face New Cybercrime Charges in Canada
🔥
What the SEC Weighed in Finalizing the Cyber Disclosure Rules
🔥
Apparel Giant VF Corporation Reports Cyberattack on First Day of SEC Disclosure Rule
🔥
Mr. Cooper Data Breach Impacts 14.7 Million Individuals
🔥
Governments Issue Warning After Play Ransomware Hits Hundreds of Organizations
🔥
Iran Hit by Major Cyberattack Targeting Nation's Fuel Supply
🔥
2022 Election Not Impacted by Chinese, Russian Cyber Activity: DOJ, DHS
🔥
Hackers Abusing GitHub to Evade Detection and Control Compromised Hosts
🔥
Anti-ransomware startup Halcyon lands fresh $40M tranche
🔥
Web injections are back on the rise: 40+ banks affected by new malware campaign
🔥
FBI disrupts Blackcat ransomware operation, creates decryption tool
🔥
Halcyon Raises $40 Million for Anti-Ransomware Platform
🔥
Mr. Cooper Breach Affects 14.6 Million Customers
🔥
Brazil's First Lady To Sue Musk's X Over Hacked Account
🔥
Behind the Scenes of Matveev's Ransomware Empire: Tactics and Team
🔥
Holiday Scams Include Thousands of Impersonation Phishing Domains per Brand
🔥
FBI Seizes BlackCat Infrastructure; Group Has New Domain
🔥
US Gov Disrupts BlackCat Ransomware Operation; FBI Releases Decryption Tool
🔥
FBI: ALPHV ransomware raked in $300 million from over 1,000 victims
🔥
Iowa Medical Center Latest Victim of Transcription Firm Hack
🔥
BlackCat Ransomware 'Unseizing' a Dark Web Stunt
🕵️
ISC Stormcast For Tuesday, December 19th, 2023 https://isc.sans.edu/podcastdetail/8784, (Tue, Dec 19th)
🕵️
QakBot Malware Emerges with New Tactics, Attacking Hospitality Industry
🕵️
New Malvertising Campaign Distributing PikaBot Disguised as Popular Software
🕵️
OpenAI Is Not Training on Your Dropbox Documents—Today
🕵️
Iranian Hackers Using MuddyC2Go in Telecom Espionage Attacks Across Africa
🕵️
Every “Thing” Everywhere All at Once
🕵️
How Microsoft might have lured unsuspecting end-users into the hands of criminals
🕵️
The Rise in Attacks Requires Specialized Expertise – Breakaway 1=5
🕵️
Sidewinder Hacker Group Using Weaponized Documents to Deliver Malware
🕵️
Turngate Raises $5 Million to Shed Light on User Activity
🕵️
Four Pieces of Transitional Advice: Incoming CISOs - Sean Zadig - CSP #153
🕵️
New Remote “Job” Scam Tells Victims They'll Get Paid For Liking YouTube Videos
🕵️
Effective Security Strategy, Overlooked Leadership Attributes, and Fun Icebreakers - BSW #332
🕵️
Nagios and Abandoned Projects, Hacking Trains (to Fix Them), OAuth Threats, 5Ghoul - ASW #267
🕵️
Understanding The Workings of Russian Hacker “Wazawaka”
🕵️
Looking Ahead: Mobile Driver's Licenses for ID Verification
🕵️
Santa, SEC, Google, Qakbot, VMWARE, AI, Turing, Voight-Kampff, Jason Wood, and more - SWN #350
🕵️
How Strata Identity and Microsoft Entra ID solve identity challenges in mergers and acquisitions
🕵️
Okta to Acquire Spera Security
🕵️
What are You Working on Wednesday
🕵️
OpenAI Formulates Framework to Mitigate 'Catastrophic Risks'
🕵️
Azure Serial Console Attack and Defense - Part 2
🌐
“Inhospitality” malspam campaign targets hotel industry
🌐
New Web injections campaign steals banking data from 50,000 people
🌐
ESET Threat Report H2 2023
🎙️
Sharing stories on the CyberTuesday podcast
📡
Microsoft is Working on a More Secure Print System for Windows
📡
A Season of Giving at Sophos
📡
Are We Ready to Give Up on Security Awareness Training?
📡
SimSpace raises $45M to simulate tech stacks for cyber training
📡
What are they looking for? Scans for OpenID Connect Configuration, (Tue, Dec 19th)
📡
New QakBot Phishing Campaign Appears After FBI Takedown
📡
Hacktivists Shut Down Iran's Gas Pumps
📡
New Scam Involving Remote Jobs on Social Media Platforms
📡
Terrapin attacks can downgrade security of OpenSSH connections
📡
Microsoft confirms Windows 11 Wi-Fi issues, asks for user feedback
📡
Sensor Intel Series: Top CVEs in November 2023
📡
Sensor Intel Series: Top CVEs in November 2023