81Articles
9Categories
2024-01-12Date
🚨
CISA adds patched MS SharePoint server vulnerability to KEV catalogA patched privilege escalation vulnerability impacting Microsoft SharePoint servers has been added to the known exploited vulnerabilities (KEV) catalog of the US Cybersecurity and Infrastructure Security Agency (CISA). Citing evidence of active exploitation, CISA has tagged the c…
KEV
🚨
Known Indicators of Compromise Associated with Androxgh0st MalwareSUMMARY The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) to disseminate known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated w…
KEV
🐛
Hackers Actively Exploited 2 Ivanti Zero-Day to Execute Arbitrary Commands
KEV
🐛
Act Now: CISA Flags Active Exploitation of Microsoft SharePoint Vulnerability
KEV
🐛
CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign
🐛
Urgent: GitLab Releases Patch for Critical Vulnerabilities - Update ASAP
🐛
CISA Flags Active Exploitation of Microsoft SharePoint Vulnerability
🐛
DreamBus Unleashes Metabase Mayhem With New Exploit Module
🐛
CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign
🐛
GitLab Releases Patch for Critical Vulnerabilities
⚠️
Android’s January 2024 Security Update Patches 58 Vulnerabilities
⚠️
Cryptominers Targeting Misconfigured Apache Hadoop and Flink with Rootkit in New Attacks
⚠️
Malware Takedowns Show Progress, But Fight Against Cybercrime Not Over
⚠️
Over 150k WordPress Sites at Takeover Risk via Vulnerable Plugin
⚠️
Update: New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems
⚠️
Cryptominers Targeting Misconfigured Apache Hadoop and Flink with Rootkit in New Attacks
⚠️
Apple Patches Keystroke Injection Vulnerability in Magic Keyboard
⚠️
Malware Used in Ivanti Zero-Day Attacks Shows Hackers Preparing for Patch Rollout
⚠️
On IoT Devices and Software Liability
⚠️
Further Analysis of Denmark Attacks Leads to Warning About Unpatched Network Gear
⚠️
WordPress Plugin Flaw Exposes 300,000+ to Hack Attacks
⚠️
Nation-State Actors Weaponize Ivanti VPN Zero-Days, Deploying 5 Malware Families
⚠️
Apple Patches Keystroke Injection Vulnerability In Magic Keyboard
⚠️
Recovery From Cyberattack ‘On the Horizon,’ Kansas Supreme Court Chief Justice Says
⚠️
Ivanti Connect Secure zero-days exploited to deploy custom malware
⚠️
Brad Arkin is New Chief Trust Officer at Salesforce
⚠️
Juniper warns of critical RCE bug in its firewalls and switches
⚠️
CISA: Critical Microsoft SharePoint bug now actively exploited
KEV
⚠️
GitLab warns of critical zero-click account hijacking vulnerability
⚠️
Researchers demo new CI/CD attack techniques in PyTorch supply-chain
⚠️
Fertility Test Lab Will Pay $1.25M to Settle Breach Lawsuit
⚠️
Chinese Nation-State Hacker Is Exploiting Cisco Routers
⚠️
Amazon Appeals Privacy Fine of 746 Million Euros
⚠️
Medusa group steps up ransomware activities
📢
AgentTesla Malware Attacking Windows Machine to Steal Sensitive Data
📢
EU Enhances Cybersecurity Requirements for Agencies
📢
GitLab security advisory (AV24-025)
📢
Microsoft Edge security advisory (AV24-026)
📢
US CISA Must Improve Water Sector Assistance, Says Watchdog
🔥
Cyber Security Today, Jan. 12, 2024 - A Chinese hacking group's reach may be bigger than we thought
🔥
Hathway - 4,670,080 breached accounts
🔥
Framework Computer Discloses Data Breach After Accountant Gets Phished
🔥
How the Merck Case Shapes the Future of Cyber Insurance
🔥
Halara Probes Breach After Hacker Leaks Data for 950,000 People
🔥
Medusa Ransomware on the Rise: From Data Leaks to Multi-Extortion
🔥
Team Liquid ’s E-Sports Platform Exposes 118,000 Users' Personal Information
🔥
Laptop Maker Framework Says Customer Data Stolen in Third-Party Breach
🔥
Ransomware Trends: Medusa and Akira Rage; Tortilla Disrupted
🔥
Medusa Ransomware Turning Your Files into Stone
🔥
The Week in Ransomware - January 12th 2024 - Targeting homeowners' data
🕵️
Funding, acquisitions, AI, CES, and dumpster fires kick off security for 2024! - ESW #345
🕵️
ISC Stormcast For Friday, January 12th, 2024 https://isc.sans.edu/podcastdetail/8808, (Fri, Jan 12th)
🕵️
One File, Two Payloads, (Fri, Jan 12th)
🕵️
Threat Actors Increasingly Abusing GitHub for Malicious Purposes
🕵️
Qbot Malware Via FakeUpdates Leads the Race of Malware Attacks
🕵️
New Class of CI/CD Attacks Could Have Led to PyTorch Supply Chain Compromise
🕵️
Russian Hackers Likely Not Involved in Attacks on Denmark’s Critical Infrastructure
🕵️
Splunk Patched Critical Vulnerabilities in Enterprise Security
🕵️
In Other News: WEF’s Unsurprising Cybersecurity Findings, KyberSlash Cryptography Flaw
🕵️
Framework says hackers accessed customer data after phishing attack on accounting partner
🕵️
News alert: Trimarc launches Active Directory security posture tool for enterprise, M&A
🕵️
Palo Alto Networks Recognized as a Leader in the 2023 Gartner Magic Quadrant for Endpoint Protection Platforms (EPP)
🕵️
Smart Cars, Microsoft, Layoffs, PyTorch, Mandiant, SEC, Aaran Leyland, and More News - SWN #353
🕵️
ISMG Editors: Will We Ever Get a Handle on API Security?
🕵️
Friday Squid Blogging: Giant Squid from Newfoundland in the 1800s
🕵️
Microsoft is named a Leader in the 2023 Gartner® Magic Quadrant™ for Endpoint Protection Platforms
🌐
Cyber Insecurity and Misinformation Top WEF Global Risk List
🌐
New Class Of CI/CD Attacks Could Have Led To PyTorch Supply Chain Compromise
🌐
eBay Pays $3M Penalty For Cyber-Stalking Newsletter Critics
🎙️
Cyber Security Today, Week in Review for the week ending Friday, Jan. 12, 2024
📡
Hyundai Motor India fixes bug that exposed customers’ personal data
📡
EMEA Panel Discussion featuring Forrester Analyst | A CISO Guide to Calculating the ROI of Prisma Cloud Based on the Commissioned TEI Study
📡
Researchers Develop Technique to Prevent Software Bugs
📡
Applying the Tyson Principle to Cybersecurity: Why Attack Simulation is Key to Avoiding a KO
📡
Fake Recruiters Defraud Facebook Users via Remote Work Offers
📡
Bitwarden Adds Passkey Support to Log Into Web Password Vaults
📡
Prolific ShinyHunters Hacker Jailed, Ordered To Repay $5 Million
📡
UAE Faces Fresh Plague of Phishing Scams, Poisoned Searches
📡
What is the principle of least privilege? | Kaspersky official blog
📡
Sophos named a Leader in 2023 Gartner®️ Magic Quadrant™️ for Endpoint Protection Platforms
📡
Lessons from SEC's X account hack – Week in security with Tony Anscombe