162Articles
9Categories
2024-01-09Date
🚨
CISA Warns of Apache Superset Vulnerability ExploitationCISA has added a critical-severity Apache Superset flaw (CVE-2023-27524) to its Known Exploited Vulnerabilities catalog. The post CISA Warns of Apache Superset Vulnerability Exploitation appeared first on SecurityWeek .
KEV
🚨
CISA warns agencies of fourth flaw used in Triangulation spyware attacksThe U.S. Cybersecurity and Infrastructure Security Agency has added to its to the Known Exploited Vulnerabilities catalog six vulnerabilities that impact products from Adobe, Apache, D-Link, and Joomla. [...]
KEV
πŸ›
Enterprises with Kyocera printers open to path traversal attacks
πŸ›
Cacti Blind, SQL Injection Flaw, Enables Remote Code Execution
πŸ›
Apache OFBiz 0-day sees thousands of daily exploit attempts
πŸ›
CVE-2024-20666 BitLocker Security Feature Bypass Vulnerability
πŸ›
CVE-2024-20674 Windows Kerberos Security Feature Bypass Vulnerability
πŸ›
CVE-2024-20677 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2024-20676 Azure Storage Mover Remote Code Execution Vulnerability
πŸ›
CVE-2024-20654 Microsoft ODBC Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-20657 Windows Group Policy Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20658 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20680 Windows Message Queuing Client (MSMQC) Information Disclosure
πŸ›
CVE-2024-20682 Windows Cryptographic Services Remote Code Execution Vulnerability
πŸ›
CVE-2024-20683 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20690 Windows Nearby Sharing Spoofing Vulnerability
πŸ›
CVE-2024-20691 Windows Themes Information Disclosure Vulnerability
πŸ›
CVE-2024-20694 Windows CoreMessaging Information Disclosure Vulnerability
πŸ›
CVE-2022-35737 MITRE: CVE-2022-35737 SQLite allows an array-bounds overflow
πŸ›
CVE-2024-20696 Windows Libarchive Remote Code Execution Vulnerability
πŸ›
CVE-2024-20697 Windows Libarchive Remote Code Execution Vulnerability
πŸ›
CVE-2024-20698 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20699 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2024-20700 Windows Hyper-V Remote Code Execution Vulnerability
πŸ›
CVE-2024-21305 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
πŸ›
CVE-2024-21307 Remote Desktop Client Remote Code Execution Vulnerability
πŸ›
CVE-2024-21313 Windows TCP/IP Information Disclosure Vulnerability
πŸ›
CVE-2024-21325 Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability
πŸ›
CVE-2024-20672 .NET Core and Visual Studio Denial of Service Vulnerability
πŸ›
CVE-2024-0056 Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
πŸ›
CVE-2024-0057 NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
πŸ›
CVE-2024-20652 Windows HTML Platforms Security Feature Bypass Vulnerability
πŸ›
CVE-2024-20653 Microsoft Common Log File System Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20655 Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability
πŸ›
CVE-2024-20656 Visual Studio Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20660 Microsoft Message Queuing Information Disclosure Vulnerability
πŸ›
CVE-2024-20661 Microsoft Message Queuing Denial of Service Vulnerability
πŸ›
CVE-2024-20662 Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
πŸ›
CVE-2024-20663 Windows Message Queuing Client (MSMQC) Information Disclosure
πŸ›
CVE-2024-20664 Microsoft Message Queuing Information Disclosure Vulnerability
πŸ›
CVE-2024-21316 Windows Server Key Distribution Service Security Feature Bypass
πŸ›
CVE-2024-20681 Windows Subsystem for Linux Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20686 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20687 Microsoft AllJoyn API Denial of Service Vulnerability
πŸ›
CVE-2024-20692 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
πŸ›
CVE-2024-21306 Microsoft Bluetooth Driver Spoofing Vulnerability
πŸ›
CVE-2024-21309 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21310 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21311 Windows Cryptographic Services Information Disclosure Vulnerability
πŸ›
CVE-2024-21312 .NET Framework Denial of Service Vulnerability
πŸ›
CVE-2024-21314 Microsoft Message Queuing Information Disclosure Vulnerability
πŸ›
CVE-2024-21318 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21319 Microsoft Identity Denial of service vulnerability
πŸ›
CVE-2024-21320 Windows Themes Spoofing Vulnerability
⚠️
Vulnerability Assessments
⚠️
Security Control Frameworks
⚠️
Surge in Open Source Malware Stealing Login Credentials & Sensitive Data
⚠️
Incorporating Mobile Threat Defense into Your Device Management Ecosystem
⚠️
Protecting Windows networks: Get back to basics for the new year
⚠️
Alert: New Vulnerabilities Discovered in QNAP and Kyocera Device Manager
⚠️
Researchers Disclose New Lumma Stealer Campaign Distributed via YouTube
⚠️
Sensitive Files of Swiss Air Force Stolen in the Hack of Ultra Intelligence & Communications
⚠️
PIN-Stealing Android Malware
⚠️
Update: Apache OFBiz Zero-Day Sees Thousands of Daily Exploit Attempts
⚠️
Saudi Ministry of Industry and Mineral Resources Exposed Sensitive Data for 15 Months
⚠️
LoanDepot Takes Systems Offline Following Ransomware Attack
⚠️
Turkish Hackers Exploiting Poorly Secured MS SQL Servers Across the Globe
⚠️
Months long AsyncRAT campaign targeted key US infrastructure employees
⚠️
Shadow APIs are opening organizations to attacks: Report
⚠️
Online Services Down for German Craft Associations Following β€˜Security Incident’
⚠️
High-Severity Vulnerabilities Patched in QNAP QTS, Video Station, QuMagie, Netatalk Products
KEV
⚠️
CISA Releases One Industrial Control Systems Advisory
⚠️
Apache OFBiz Zero Day Pummeled By Exploit Attempts After Disclosure
⚠️
Criminal IP and Tenable Partner for Swift Vulnerability Detection
⚠️
Turkish Hackers Exploiting Poorly Secured MS SQL Servers Across the Globe
⚠️
Hackers disrupt Beirut airport with anti-Hezbollah message
⚠️
Bangladesh official alleges cyberattack β€˜from Ukraine and Germany’ targeted election
⚠️
Wiper malware found in analysis of Iran-linked attacks on Albanian institutions
⚠️
Pro-Ukraine hackers claim breach of Russian internet provider
⚠️
New decryptor for Babuk Tortilla ransomware variant released
⚠️
Jenkins Brute Force Scans, (Tue, Jan 9th)
⚠️
Microsoft Ships Urgent Fixes for Critical Flaws in Windows Kerberos, Hyper-V
⚠️
Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
⚠️
Critical Patches Issued for Microsoft Products, January 09, 2024
⚠️
Kyocera Printers Open to Path Traversal Attacks
⚠️
Fortinet Releases Security Updates for FortiOS and FortiProxy
⚠️
Microsoft Releases Security Updates for Multiple Products
πŸ“‹
Adobe Patches Code Execution Flaws in Substance 3D Stager
πŸ“‹
Siemens, Schneider Electric Release First ICS Patch Tuesday Advisories of 2024
πŸ“‹
2024’s first Patch Tuesday steps lightly
πŸ“’
Reimagining Risk in the Emerging Cloud: A GRC Perspective - Solomon Ugah - CSP #156
πŸ“’
Jobs, QNAP, NIST, Spectral Blur, Stuxnet, Swatting, Volkswagen, Jason Wood – SWN #352
πŸ“’
Jobs, QNAP, NIST, Spectral Blur, Stuxnet, Swatting, Volkswagen, Jason Wood - SWN #352
πŸ“’
[Control systems] Schneider Electric security advisory (AV24-012)
πŸ“’
SAP security advisory – January 2024 monthly rollup (AV24-014)
πŸ“’
[Control systems] Siemens security advisory (AV24-013)
πŸ“’
Microsoft security advisory – January 2024 monthly rollup (AV24-018)
πŸ“’
Fortinet security advisory (AV24-017)
πŸ“’
HPE security advisory (AV24-016)
πŸ“’
Google Chrome security advisory (AV24-015)
πŸ”₯
Bangladesh Official Alleges Cyberattack β€˜From Ukraine and Germany’ Targeted Election
πŸ”₯
Ransomware Attack on Toronto Zoo Had No Impact on Animal Wellbeing
πŸ”₯
Netgear, Hyundai Latest X Accounts Hacked To Push Crypto Drainers
πŸ”₯
Update: LockBit Claims November Attack on New Jersey Hospital That Disrupted Patient Care
πŸ”₯
Midwives clinic takes nine months to deliver news of data breach
πŸ”₯
Rhysida Ransomware Gang Takes Credit for Christmas Attack on Global Lutheran Organization
πŸ”₯
New York Clinic Must Pay $450K Fine, Spend $1.2M on Security
πŸ”₯
Bosch Nutrunner Vulnerabilities Could Aid Hacker Attacks Against Automotive Production Lines
πŸ”₯
Ransomware Gang Claims Attack on Capital Health
πŸ”₯
Continuity in Chaos: Applying Time-Tested Incident Response to Modern Cybersecurity
πŸ”₯
New Decryptor for Babuk Tortilla Ransomware Variant Released
πŸ”₯
Hackers Can Infect Network-Connected Wrenches To Install Ransomware
πŸ”₯
LoanDepot Systems Offline Following Ransomware Attack
πŸ”₯
Paraguay warns of Black Hunt ransomware attacks after Tigo Business breach
πŸ”₯
Turkish Hackers Target Microsoft SQL Servers in Americas, Europe
πŸ”₯
Decryptor for Babuk ransomware variant released after hacker arrested
πŸ”₯
AI aides nation-state hackers but also helps US spies to find them, says NSA cyber director
πŸ”₯
Hackers target Microsoft SQL servers in Mimic ransomware attacks
πŸ”₯
Ransomware victims targeted by fake hack-back offers
πŸ”₯
Fidelity National Financial says hackers stole data on 1.3 million customers
πŸ”₯
Fallout Mounting From Recent Major Health Data Hacks
πŸ”₯
US SEC’s X account hacked to announce fake Bitcoin ETF approval
πŸ”₯
Cyber insurance requirements: What’s in store for 2024
πŸ•΅οΈ
Browser Certificate Stores and QWACs
πŸ•΅οΈ
ISC Stormcast For Tuesday, January 9th, 2024 https://isc.sans.edu/podcastdetail/8802, (Tue, Jan 9th)
πŸ•΅οΈ
Accenture Buys 6point6 to Expand Cyber Portfolio
πŸ•΅οΈ
Beware! YouTube Videos Promoting Cracked Software Distribute Lumma Stealer
πŸ•΅οΈ
Multiple QNAP High-Severity Flaws Let Attackers Execute Remote Code
πŸ•΅οΈ
Cybersecurity Funding Dropped 40% in 2023: Analysis
πŸ•΅οΈ
Best Practices for Moving Sensitive Data into the Cloud | Leadership & Communications - BSW #333
πŸ•΅οΈ
Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them
πŸ•΅οΈ
Cybersecurity trends: IBM’s predictions for 2024
πŸ•΅οΈ
CyberheistNews Vol 14 #02 AI Breaks Free: New Insights Into The Latest Chatbot Jailbreak Hack
πŸ•΅οΈ
Countering Online Fraud With Gen AI Safeguards
πŸ•΅οΈ
Alert: Water Curupira Hackers Actively Distributing PikaBot Loader Malware
πŸ•΅οΈ
What's in Store for 2024? - ASW #268
πŸ•΅οΈ
23andMe Blames Users, Abusing Google's OAuth2, Rustls Performance, AI Goes OSINT - ASW #268
πŸ•΅οΈ
DevOps Configuration Management Tier Discussion
πŸ•΅οΈ
Using honeytokens to detect (AiTM) phishing attacks on your Microsoft 365 tenant
πŸ•΅οΈ
Organizations Undercount APIs by One-Third, Experts Warn
πŸ•΅οΈ
Delinea Acquires Authomize to Tackle Identity-Based Threats
πŸ•΅οΈ
Cybercriminals Celebrate the Holidays with Dark Web Data Dumps, DubbedΒ  β€œLeaksmas”
πŸ•΅οΈ
Red Flags for Phishing: Verizon Outlines Common Scams to Watch Out For
πŸ•΅οΈ
GUEST ESSAY: The case for using augmented reality (AR) and virtual reality (VR) to boost training
πŸ•΅οΈ
PAM Provider Delinea Acquires Israeli Startup Authomize
πŸ•΅οΈ
OpenAI: Gen AI 'Impossible' Without Copyrighted Material
🌐
Deceptive Cracked Software Spreads Lumma Variant on YouTube
πŸ“‘
Why Public Links Expose Your SaaS Attack Surface
πŸ“‘
Google Search bug shows blank page in Firefox for Android
πŸ“‘
Nigerian Gets Ten Years for Laundering Scam Funds
πŸ“‘
US DHS Solicits Synthetic Data Expertise for AI Training
πŸ“‘
Turkish Hackers Target Microsoft SQL Servers In Americas, Europe
πŸ“‘
FTC bans X-Mode from selling phone location data, and orders firm to delete collected data
πŸ“‘
Windows 11 KB5034123 update released with security and Wi-Fi fixes
πŸ“‘
Windows 10 KB5034122 update released with fix for shut down bug
πŸ“‘
FTC bans data broker from selling Americans’ location data
πŸ“‘
China claims it cracked Apple's AirDrop to find numbers, email addresses
πŸ“‘
Everything you need to know about VPNs
πŸ“‘
Nigerian gets 10 years for laundering millions stolen from elderly
πŸ“‘
Love is in the AI: Finding love online takes on a whole new meaning
πŸ“‘
Securing Application Staging & Production Environments
πŸ“‘
Black Basta-Affiliated Water Curupira’s Pikabot Spam Campaign