108Articles
9Categories
2024-01-17Date
🚨
CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2023-6549 Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability CVE-2023-6548 Citrix NetScaler ADC and NetScaler Gateway Code…
KEV
🐛
Zero-Day Alert: Update Chrome Now to Fix New Actively Exploited Vulnerability
KEV
🐛
Citrix, VMware, and Atlassian Hit with Critical Flaws — Patch ASAP!
KEV
🐛
Magic Keyboard vulnerability allows takeover of iOS, Android, Linux, and MacOS devices
🐛
Windows SmartScreen Bug Abused to Deploy Phemedrone Stealer
🐛
GitHub Rotates Keys After High-Severity Vulnerability Exposes Credentials
🐛
Citrix Warns NetScaler ADC Customers of New Zero-Day Exploitation
🐛
VMware Fixed a Critical Flaw in Aria Automation
🐛
Citrix NetScaler devices face active zero-day exploitations
🐛
Citrix Warns Admins to Immediately Patch NetScaler for Actively Exploited Zero-Days
KEV
🐛
VMware Releases Security Advisory for Aria Operations
🐛
Chromium: CVE-2024-0517 Out of bounds write in V8
🐛
Chromium: CVE-2024-0518 Type Confusion in V8
🐛
Chromium: CVE-2024-0519 Out of bounds memory access in V8
🐛
Over 178,000 SonicWall firewalls still vulnerable to old flaws
⚠️
GitHub Rotates Keys After High-Severity Vulnerability Exposes Credentials
⚠️
Ivanti Spots ‘Sharp Increase’ in Targeting of VPN as Analysts Find 1,700 Devices Exploited
⚠️
Atlassian Fixed Critical RCE Flaw in Older Confluence Versions
⚠️
Badge privacy-preserving authentication tool launches with Okta integration
⚠️
Google Issues Chrome Update to Fix Actively Exploited Zero-Day Vulnerability
KEV
⚠️
FBI warns against cloud credential-stealing Androxgh0st botnet
⚠️
Google Chrome Browser Zero-Day Vulnerability Exploited in Wild – Emergency Patch!
KEV
⚠️
No digital transformation without cybersecurity
⚠️
Feds Warn of AndroxGh0st Botnet Targeting AWS, Azure, and Office 365 Credentials
⚠️
Webinar: The Art of Privilege Escalation - How Hackers Become Admins
⚠️
Adalanche: Open-Source Active Directory ACL Visualizer, Explorer
⚠️
GitHub Rotates Credentials in Response to Vulnerability
⚠️
Apple Actively Exploited Telegram Channel
KEV
⚠️
SoftwareProjects exposes substantial customer and affiliate data
⚠️
Attacks On Ivanti 0-Days Scale To 1,700 VPNs
⚠️
Google Warns Of Chrome Browser Zero Day Being Exploited
⚠️
GitHub Rotates Credentials In Response To Vulnerability
⚠️
Naz.API - 70,840,771 breached accounts
⚠️
A tougher balancing act in 2024, the year of the CISO
⚠️
Wazuh: Building robust cybersecurity architecture with open source tools
⚠️
Atlassian Warns of Critical RCE Vulnerability in Outdated Confluence Instances
⚠️
AMD, Apple, Qualcomm GPUs leak AI data in LeftoverLocals attacks
⚠️
Cyber Startup Vicarius Raises $30 Million Series B for Vulnerability Remediation Platform
⚠️
Detained Russian Student Allegedly Helped Ukrainian Hackers With Cyberattacks
⚠️
Vulnerabilities Discovered in Android-based POS Terminals From PAX Technology
⚠️
CISA pushes federal agencies to patch Citrix RCE within a week
KEV
⚠️
Chrome Patches First Zero-Day of 2024 Exploited in the Wild
KEV
⚠️
Vulnerability Management Firm Vicarius Raises $30 Million
⚠️
Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website
⚠️
NetScaler, Atlassian, VMWare Disclose Critical Flaws
KEV
⚠️
A Vulnerability in Atlassian Confluence Data Center and Server Could Allow for Remote Code Execution
📋
Cyber Security Today, Jan. 17, 2024 - Security updates issued for Atlassian, Citrix, VMware and Chrome products
📢
PixieFail Vulnerabilities Impact PXE Network Boot in Enterprise Systems
📢
As hacks worsen, SEC turns up the heat on CISOs
📢
US Gov Issues Warning for Androxgh0st Malware Attacks
📢
CISA Releases 2023 Year in Review Showcasing Efforts to Protect Critical Infrastructure
📢
SonicWall security advisory (AV24-036)
📢
London internet attack highlights confusing hacktivism movement
📢
Chinese Drones Pose Threat to US Infrastructure, CISA Warns
🔥
Number Usage in Passwords, (Wed, Jan 17th)
🔥
Three Ransomware Group Newcomers to Watch in 2024
🔥
Crypto Heists Surge in 2023, $16.93m Already Stolen in 2024
🔥
New iShutdown Method Exposes Hidden Spyware Like Pegasus on Your iPhone
🔥
Ransomware Gang Demands $11 Million After Attacking Spanish City Council in Majorca
🔥
Inside the Massive Naz.API Credential Stuffing List
🔥
Progress Software’s MOVEit Meltdown: Uncovering the Fallout
🔥
Did Uber's Delivery Service Drizly Die Due to Data Breach?
🔥
iShutdown scripts can help detect iOS spyware on your iPhone
🔥
Swiss Govt Websites Hit by Pro-Russia Hackers After Zelensky Visit
🔥
How a Novel Legal Maneuver Got a Hospital's Stolen Data Back
🔥
Have I Been Pwned adds 71 million emails from Naz.API stolen account list
🔥
New Microsoft Incident Response guides help security teams analyze suspicious activity
🕵️
Current account recovery best practices?
🕵️
ISC Stormcast For Wednesday, January 17th, 2024 https://isc.sans.edu/podcastdetail/8812, (Wed, Jan 17th)
🕵️
PentestGPT – A ChatGPT Powered Automated Penetration Testing Tool
🕵️
Remcos RAT Spreading Through Adult Games in New Attack Wave
🕵️
Here’s How ChatGPT Maker OpenAI Plans to Deter Election Misinformation in 2024
🕵️
Oracle Patches 200 Vulnerabilities With January 2024 CPU
🕵️
Code Written with AI Assistants Is Less Secure
🕵️
macOS Infostealers That Actively Involve in Attacks Evade XProtect Detection
🕵️
AI Data Exposed to ‘LeftoverLocals’ Attack via Vulnerable AMD, Apple, Qualcomm GPUs
🕵️
Achieving “Frictionless Defense” in the Age of Hybrid Networks
🕵️
What are You Working on Wednesday
🕵️
AI in Security — Ready for Prime Time
🕵️
PAX PoS Terminal Flaw Could Allow Attackers to Tamper with Transactions
🕵️
News alert: Incogni study reveals overwhelming majority of spam calls originate locally
🕵️
Microsoft: Iranian APT Impersonating Prominent Journalist in Clever Spear-Phishing Attacks
🕵️
Microsoft: Iranian hackers target researchers with new MediaPl malware
🕵️
How 'sleeper agent' AI assistants can sabotage code
🕵️
OpenAI Combats Election Misinformation Amid Growing Concerns
🕵️
New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs
🕵️
K-12 Cybersecurity with Brian Stephens, Director, Stakeholder Engagement at Funds For Learning
🕵️
US Judge Again Says Meta Pixel Privacy Case Dismissal Unlikely
🌐
Cyber Tops Business Risk for Enterprises Worldwide, Report Finds
🌐
US Agencies Warn of Androxgh0st Malware Botnet Stealing AWS, Microsoft credentials
🌐
MacOS Info-Stealers Quickly Evolve to Evade XProtect Detection
🌐
Release Cybersecurity Guidance on Chinese-Manufactured UAS for Critical Infrastructure Owners and Operators
🌐
Bigpanzi botnet infects 170,000 Android TV boxes with malware
📡
What cybersecurity threats to kids parents should be aware of in 2024? | Kaspersky official blog
📡
Southeast Asian Casino Industry Supercharging Cyber Fraud, UN Says
📡
Report: 94% of Firms Hit by Phishing Attacks in 2023
📡
PSA: Anyone can tell if you are using WhatsApp on your computer
📡
New UEFI Vulnerabilities Send Firmware Devs Across An Entire Ecosystem Scrambling
📡
SonicWall API Opens 178k Firewalls To Attack
📡
Crypto Trading Firm Closes Shop After $8 Million NY State Fine Over Security Issues
📡
Combating IP Leaks into AI Applications with Free Discovery and Risk Reduction Automation
📡
Snyk Acquires Helios for Runtime Visibility
📡
Cheap .cloud Domains and Shark Tank Impersonation Fuels Unhealthy Scams
📡
E-Crime Rapper ‘Punchmade Dev’ Debuts Card Shop
📡
The threat from large language model text generators
📡
Embracing a risk-based cybersecurity approach with ASRM
📡
Is Temu safe? What to know before you ‘shop like a billionaire’
📡
Modernize Federal Cybersecurity Strategy with FedRAMP