95Articles
10Categories
2024-01-11Date
🚨
CISA Urges Patching of Exploited SharePoint Server VulnerabilityCISA has added a critical Microsoft SharePoint Server flaw (CVE-2023-29357) to its Known Exploited Vulnerabilities catalog. The post CISA Urges Patching of Exploited SharePoint Server Vulnerability appeared first on SecurityWeek .
KEV
πŸ›
Cisco Fixes High-Risk Vulnerability Impacting Unity Connection Software
πŸ›
Actively Exploited Zero-Days in Ivanti VPN are Letting Hackers Backdoor Networks
KEV
πŸ›
Chinese hackers exploit Ivanti VPN zero days for RCE attacks
KEV
πŸ›
New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems
πŸ›
State-backed hackers are exploiting new Ivanti VPN zero-days β€” but no patches yet
πŸ›
Juniper Networks Releases Security Bulletin for Junos OS and Junos OS Evolved
πŸ›
Cisco Releases Security Advisory for Cisco Unity Connection
πŸ›
Attackers deploy rootkits on misconfigured Apache Hadoop and Flink servers
πŸ›
Microsoft shares script to update Windows 10 WinRE with BitLocker fixes
πŸ›
Chromium: CVE-2024-0333 Insufficient data validation in Extensions
πŸ›
CVE-2024-20675 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
πŸ›
CVE-2023-48631 Adobe Systems Incorporated: CVE-2023-Improper Input Validation Denial of Service Vulnerability
πŸ›
CVE-2024-20709 Adobe Systems Incorporated: CVE-2024-20709 Javascript Implementation PDF Vulnerability
πŸ›
CVE-2024-21337 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
πŸ›
MiraclePtr: protecting users from use-after-free vulnerabilities on more platforms
⚠️
Chinese Hackers Exploit Zero-Day Flaws in Ivanti Connect Secure and Policy Secure
⚠️
Mandiant's X Account Was Hacked Using Brute-Force Attack
⚠️
Cisco Says Critical Unity Connection Bug Lets Attackers Get Root
⚠️
Security firm Mandiant says it didn’t have 2FA enabled on its hacked Twitter account
⚠️
Thousands of WordPress Sites with Popup Builder Plugin Compromised by Balada Injector
⚠️
Pharmacies Giving Patient Records to Police without Warrants
⚠️
Cisco Patches Critical Vulnerability in Unity Connection Product
⚠️
Mandiant Details How Its X Account Was Hacked
⚠️
Mirai-Based NoaBot Launches a DDoS Attack on Linux Devices
⚠️
Microsoft Fixes 48 Bugs In January Patch Tuesday, None Of Them Zero Days
⚠️
Actively Exploited 0-Days In Ivanti VPN Are Letting Hackers Backdoor Networks
KEV
⚠️
A Vulnerability in Cisco Unity Connection Could Allow for Arbitrary Code Execution
⚠️
Ivanti Connect Secure and Ivanti Policy Secure gateways zero-day vulnerabilities
⚠️
CISA Releases Nine Industrial Control Systems Advisories
⚠️
We're Old Now - PSW #812
⚠️
Journey into the Immersive Frontier: Preliminary NIST Research on Cybersecurity and Privacy Standards for Immersive Technologies
⚠️
Bitwarden adds passkey support to log into web password vaults
⚠️
Suspected Chinese Hackers Exploit 2 Ivanti Zero-Days
⚠️
Predicting GenAI Threats & Concerns + Pros & Cons of Building a Security Business Around Open Source
⚠️
Breach Roundup: FTC Bans Data Broker From Sharing Locations
⚠️
Framework discloses data breach after accountant gets phished
⚠️
The Pros and Cons of Building a Security Business Around Open Source - Ev Kontsevoy - ESW #345
⚠️
Turkish Hackers Exploit MS SQL Servers to Deliver Ransomware
⚠️
A peek behind the curtain: How are sock puppet accounts used in OSINT?
πŸ“‹
Intel, AMD, Zoom, Splunk Release Patch Tuesday Security Advisories
πŸ“’
UK: NCSC Publishes Practical Security Guidance for SMBs
πŸ“’
Finland warns of Akira ransomware wiping NAS and tape backup devices
πŸ“’
Finland Warns of Akira Ransomware Wiping NAS and Tape Backup Devices
πŸ“’
Apple security advisory (AV24-022)
πŸ“’
[Control systems] Horner Automation security advisory (AV24-023)
πŸ“’
[Control systems] Rapid Software security advisory (AV24-024)
πŸ”₯
Twitter says, It’s not our fault the SEC’s account got hacked
πŸ”₯
There is a Ransomware Armageddon Coming for Us All
πŸ”₯
HMG Healthcare Discloses Data Breach Affecting 40 Affiliated Nursing Facilities
πŸ”₯
Mandiant Details How Its X Account Was Hacked
πŸ”₯
Threat Actors Increasingly Abusing GitHub for Malicious Purposes
πŸ”₯
Halara probes breach after hacker leaks data for 950,000 people
πŸ•΅οΈ
ISC Stormcast For Thursday, January 11th, 2024 https://isc.sans.edu/podcastdetail/8806, (Thu, Jan 11th)
πŸ•΅οΈ
The Evolution of Purple Teaming - Jared Atkinson - PSW #812
πŸ•΅οΈ
Beware of Phishing Scams Disguised as Annual HR Tasks
πŸ•΅οΈ
New NoaBot Botnet Spreads an Illicit Cryptominer on Linux Systems
πŸ•΅οΈ
Atomic Stealer Gets an Upgrade - Targeting Mac Users with Encrypted Payload
πŸ•΅οΈ
KnowBe4 Named a Leader in the Winter 2024 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR)
πŸ•΅οΈ
AI-Powered Misinformation is the World’s Biggest Short-Term Threat, Davos Report Says
πŸ•΅οΈ
Coming Soon to a Network Near You: More Shadow IoT
πŸ•΅οΈ
China-Linked Volt Typhoon Hackers Possibly Targeting Australian, UK Governments
πŸ•΅οΈ
Vulnerabilities on Bosch Rexroth Nutrunners May Be Abused to Stop Production Lines, Tamper with Safety-Critical Tightenings
πŸ•΅οΈ
Atomic Stealer Delivered Through Malicious Ads Via Google Search
πŸ•΅οΈ
Cryptohack Roundup: It's Raining Phishing Scams on X
πŸ•΅οΈ
Microsoft Lets Cloud Users Keep Personal Data Within Europe to Ease Privacy Fears
πŸ•΅οΈ
Beware of "Get to Know Me" Surveys
πŸ•΅οΈ
Microsoft Takes the Lead in Q4 2023 for Alarming Phishing Attempts
πŸ•΅οΈ
FTC Issues Warning About the Dangers of QR Code-Based Scams
πŸ•΅οΈ
Attackers' GitHub Abuse Poses Growing Risk, Researchers Warn
πŸ•΅οΈ
Researchers Flag FBot Hacking Tool Hijacking Cloud, Payment Services
πŸ•΅οΈ
[New Phishing Template]Β Formula 1 Exclusive: Gene Haas on Guenther Steiner's Departure
πŸ•΅οΈ
Predicting GenAI Threats and Concerns in 2024 - Greg Notch - ESW #345
🌐
Atomic Stealer Rings in the New Year With Updated Version
🌐
Black Basta-Affiliate Spreads Pikabot
🌐
Trend Micro Defends FIFA World Cup from Cyber Threats
πŸŽ™οΈ
Smashing Security podcast #354: Chuck Norris and the fake CEO, artificial KYC, and an Airbnb scam
πŸŽ™οΈ
New YouTube Video Series: Hacker Tools Origin Stories, (Thu, Jan 11th)
πŸŽ™οΈ
Transatlantic Cable podcast episode 329 looks news around Stuxnet, how journalists and creative artists are suing OpenAI and much more! | Kaspersky official blog
πŸ“‘
Why you should start the year with a digital cleanup | Kaspersky official blog
πŸ“‘
Top LLM Vulnerabilities and How to Mitigate the Associated Risk
πŸ“‘
ExtraHop Raises $100M in Growth Capital
πŸ“‘
French Hacker From β€˜ShinyHunters’ Group Sentenced to Three Years in US Prison
πŸ“‘
Fidelity National Now Says 1.3M Customers Had Their Data Stolen
πŸ“‘
New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms
πŸ“‘
Chertoff Group Affiliate Completes Trustwave Acquisition
πŸ“‘
New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms
πŸ“‘
A geofence warrant typo cast a location dragnet spanning two miles over San Francisco
πŸ“‘
Top Takeaways From the Hijacking of Mandiant's X Account
πŸ“‘
Build Cyber Resilience with Distributed Energy Systems
πŸ“‘
New Balada Injector campaign infects 6,700 WordPress sites
πŸ“‘
Microsoft testing Windows 11 USB 80Gbps support, Copilot on login
πŸ“‘
Over 150k WordPress sites at takeover risk via vulnerable plugin
πŸ“‘
How the Merck Case Shapes the Future of Cyber Insurance
πŸ“‘
Major T-Mobile outage takes down account access, mobile app