106Articles
8Categories
2024-01-23Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-23222 Apple Multiple Products Type Confusion Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actor…
KEV
🐛
Apple Issues Patch for Critical Zero-Day in iPhones, Macs - Update Now
🐛
~40,000 Attacks in 3 Days: Critical Confluence RCE Under Active Exploitation
🐛
Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing (CVE-2023-45866)
🐛
Apple Issues Patch for Critical Zero-Day in iPhones, Macs - Update Now
🐛
Chinese cyberspies exploited critical VMware vCenter flaw undetected for 1.5 years
⚠️
Update: Hackers Start Exploiting Critical Atlassian Confluence RCE Flaw
⚠️
News alert: Sternum and ChargePoint collaborate to enhance ChargePoint Home Flex Security
⚠️
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
⚠️
Kasseika Ransomware Deploys BYOVD Attacks, Abuses PsExec and Exploits Martini Driver
⚠️
10 top cyber recovery providers
⚠️
MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned Libraries
⚠️
Trezor Support Site Breach Exposes Personal Data of 66,000 Customers
⚠️
Sequoia backs Coana to help companies prioritise vulnerabilities using ‘code aware’ software analysi
⚠️
Israel, Czech Republic Reinforce Cyber Partnership Amid Hamas War
⚠️
Silverfort now valued at $1B after raising $116M for its holistic approach to identity security
⚠️
High-Severity Vulnerability Patched in Splunk Enterprise
⚠️
Fortra warns of new critical GoAnywhere MFT auth bypass, patch now
⚠️
Apple Releases Security Updates for Multiple Products
⚠️
Hackers Are Hitting A Critical Atlassian Confluence Vulnerability
⚠️
High Severity Vulnerability Patched In Splunk Enterprise
⚠️
Dealing with the Burden of Bad Bots - Sandy Carielli - ASW #270
⚠️
CISA Releases Six Industrial Control Systems Advisories
⚠️
Update on Atlassian Exploit Activity , (Tue, Jan 23rd)
⚠️
Vulnerabilities in Lamassu Bitcoin ATMs Can Allow Hackers to Drain Wallets
⚠️
Water services giant Veolia North America hit by ransomware attack
⚠️
CISA Joins ACSC-led Guidance on How to Use AI Systems Securely
⚠️
Exploit released for Fortra GoAnywhere MFT auth bypass bug
📢
Australian government names and issues sanctions on individual linked to Medibank data breach
📢
BreachForums Founder Sentenced to 20 Years of Supervised Release, No Jail Time
📢
Lack of Understanding, Underfunding Threaten Data Privacy & Compliance
📢
Apple security advisory (AV24-044)
📢
HPE security advisory (AV24-045)
📢
Mozilla security advisory (AV24-046)
📢
Windows 10 KB5034203 preview update adds EU DMA compliance
📢
Fortra security advisory (AV24-047)
📢
Google Chrome security advisory (AV24-048)
📢
CISA's Jen Easterly Confirms 'Harrowing' Swatting Attack
🔥
Australia Sanctions Russian it Says Hacked Health Insurer
🔥
Hackers Abusing LSASS Process Memory to Exfiltrate Login Credentials
🔥
Finland: Prosecutors Add to Evidence Against Alleged Vastaamo Hacker
🔥
NS-STEALER Uses Discord Bots to Exfiltrate Your Secrets from Popular Browsers
🔥
SEC X Account was Hacked Using SIM Swapping Method
🔥
SEC Says X Account Hacked via SIM Swapping
🔥
Russian Hackers Suspected of Sweden Cyberattack
🔥
Subway Sandwich Chain Investigating Ransomware Group’s Claims
🔥
Historic Data Leak Reveals 26 Billion Records From Tencent, Weibo, Twitter, Adobe, and Others
🔥
North Korean ScarCruft Attackers Gear Up to Target Cybersecurity Professionals
🔥
Australia sanctions REvil hacker behind Medibank data breach
🔥
Aircraft Lessor AerCap Confirms Ransomware Attack
🔥
Cato Networks launches new SASE-powered XDR offering
🔥
Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub
🔥
CyberheistNews Vol 14 #04 'Swatting' Becomes the Latest Extortion Tactic in Ransomware Attacks
🔥
Update: LoanDepot Says 16.6 Million Customers had ‘Sensitive Personal’ Information Stolen in Cyberattack
🔥
Threat Assessment of BianLian Ransomware
🔥
Aviation Leasing Giant AerCap Hit By Ransomware Attack
🔥
Jason’s Deli says customer data exposed in credential stuffing attack
🔥
Slug Ransomware Attacked AerCap, Claims to Have Stolen 1TB Data
🔥
US sanctions Russian citizen accused of playing key role in Medibank ransomware attack
🔥
Black Basta Gang Claims the Hack of the UK Water Utility Southern Water
🔥
Hackers Used SIM Swapping to Breach US SEC X Account
🔥
Kasseika ransomware uses antivirus driver to kill other antiviruses
🔥
Unprecedented Cybersecurity Alert: 26 Billion Records Exposed in Mega Data Breach
🔥
Australia, US, UK Sanction Russian Over 2022 Medibank Breach
🔥
US, UK, Australia sanction REvil hacker behind Medibank data breach
🔥
UK Intelligence Agency Warns of Mounting AI Cyberthreat
🕵️
15M Trello accounts have been leaked
🕵️
ISC Stormcast For Tuesday, January 23rd, 2024 https://isc.sans.edu/podcastdetail/8820, (Tue, Jan 23rd)
🕵️
SSH3 – Faster & Rich Secure Shell Using HTTP/3
🕵️
F5 Names Samir Sherif as New CISO
🕵️
A Sanction Has Been Imposed on a Hacker Who Released Australian Health Insurer Client Data
🕵️
Side Channels Are Common
🕵️
The Secure Developer Podcast - Generative AI, Security, And Predictions For 2024 - 1:06 hours
🕵️
Identity Security Firm Silverfort Lands $116 Million Investment
🕵️
Doppel Secures $14M for AI-Powered Brand Protection Technology
🕵️
New Malware Hidden In PyPI Packages Attacking Windows & Linux Machines
🕵️
North Korean Hackers Attacking Cybersecurity Professionals to Steal Threat Research Reports
🕵️
Silverfort Plans Platform Expansion With $116M Funding Round
🕵️
VexTrio: The Uber of Cybercrime - Brokering Malware for 60+ Affiliates
🕵️
Cloud Security Staffing in a Hybrid World – It Can Be Done! - Larry Lidz - CSP #158
🕵️
AI Testing Startup RagaAI Emerges From Stealth With $4.7M in Seed Funding
🕵️
Security in Wrenches, Vulns in Atlassian and GitLab, 2023's Top Web Hacking Tricks - ASW #270
🕵️
News alert: NCA’s Data Privacy Week webinars highlight data protection for consumers, businesses
🕵️
RoboJoe, Apple, VMWARE, AI, Confluence, Scarcruft, Microsoft, Jason Wood, and More - SWN #356
🕵️
Malicious Traffic Distribution System Spotted by Researchers
🕵️
Cybercrime’s Silent Operator: The Unraveling of VexTrio’s Malicious Network Empire
🕵️
AI Automation Won't Steal All Jobs, for Now
🕵️
Medical Lab Database Exposed 1.3M Records, COVID Test Info
🌐
New Chae$ 4.1 Malware Hides in Driver Downloads
🌐
From Megabits to Terabits: Gcore Radar Warns of a New Era of DDoS Attacks
🌐
"Activator" Alert: MacOS Malware Hides in Cracked Apps, Targeting Crypto Wallets
📡
A Universal Prompt Injection Attack In The GPT Store
📡
Bulletproof Hosting: A Critical Cybercriminal Service
📡
Thai Court Blocks 9near.org to Avoid Exposure of 55M Citizens
📡
Info Stealing Packages Hidden in PyPI
📡
SEC Says X Account Hack was Due to SIM Swapping
📡
Kaspersky Standard wins Product of the Year award from AV-Comparatives | Kaspersky official blog
📡
New Method To Safeguard Against Mobile Account Takeovers
📡
‘De-Googled’ smartphone company Murena launches own-brand mobile network
📡
iPhone users should turn on Apple’s stolen device protection feature
📡
Clerk, the authentication startup, lands $30M and inks a strategic deal with Stripe
📡
SEC Blames SIM Swap Hack For Twitter Account Hijack
📡
Important Sophos Firewall product news
📡
X adds passkeys support for iOS users in the United States
📡
Trello API abused to link email addresses to 15 million accounts
📡
Break the fake: The race is on to stop AI voice cloning scams