102Articles
9Categories
2024-01-24Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2023-22527 Atlassian Confluence Data Center and Server Template Injection Vulnerability These types of vulnerabilities are frequent attack vectors f…
KEV
πŸ›
Patch Your GoAnywhere MFT Immediately - Critical Flaw Lets Anyone Be Admin
πŸ›
CVE-2024-0204: Fortra GoAnywhere MFT Authentication Bypass Deep-Dive
πŸ›
Over 5,300 GitLab servers exposed to zero-click account takeover attacks
⚠️
Civilian cyber reserves gaining steam at the US federal and state levels
⚠️
The Unknown Risks of The Software Supply Chain: A Deep-Dive
⚠️
The Mass Exploitation of Ivanti Connect Secure
⚠️
Hackers Deploy Malicious npm Packages on GitHub to Steal SSH Keys
⚠️
Poisoning AI Models
⚠️
Go St*lk Yourself: Privacy Through OSINT w/ Mishaal Khan | 1-Hour
⚠️
Tesla hacked, 24 zero-days demoed at Pwn2Own Automotive 2024
⚠️
How Bad User Interfaces Make Security Tools Harmful, (Wed, Jan 24th)
⚠️
Gen AI fuelled 2023 cyberattacks, evolution pushed remediation costs: report
⚠️
PoC Code Published for Just-Disclosed Fortra GoAnywhere Vulnerability
⚠️
Google Kubernetes Misconfig Lets Any Gmail Account Control Your Clusters
⚠️
Apple Patches iOS, macOS 0-Day That May Have Been Exploited
⚠️
Pwn2Own Automotive: Hackers Earn Over $700k for Tesla, EV Charger, Infotainment Exploits
⚠️
Mozilla Releases Security Updates for Thunderbird and Firefox
⚠️
Group permission misconfiguration exposes Google Kubernetes Engine clusters
⚠️
How the Sys:All Loophole Allowed Us To Penetrate GKE Clusters in Production
⚠️
We Must Consider Software Developers a Key Part of the Cybersecurity Workforce
⚠️
Fortra GoAnywhere MFT Flaw Grants Admin Access to Anyone
⚠️
HPE: Russian hackers breached its security team’s email accounts
⚠️
SBOMs and Supply Chains - Allan Friedman - BTS #22
⚠️
UK Mulls Rollout of New Software Vulnerability Rules
⚠️
HPE Fingers Russian State Hackers for Email Hack
πŸ“’
GoAnywhere MFT Critical Flaw Lets Anyone Be Admin
πŸ“’
BHIS Webcast: New Wave of Ransomware Attacks: How did this happen?
πŸ“’
Venafi’s new offering to block unauthorized code across user environments
πŸ“’
UK says AI will empower ransomware over the next two years
πŸ“’
Cisco security advisory (AV24-049)
πŸ“’
Privacy Attacks in Federated Learning
πŸ“’
HHS Details New Cyber Performance Goals for Health Sector
πŸ“’
What Smart CISOs and Mature Orgs Get That Others Don’t About Cyber Compliance with Matt Coose.
πŸ“’
The near-term impact of AI on the cyber threat
πŸ”₯
Parrot TDS Injecting Malicious Redirect Scripts on Hacked Sites
πŸ”₯
Top 12 Best Penetration Testing Companies & Services – 2024
πŸ”₯
MavenGate Supply Chain Attack Let Attackers Hijack Java & Android Apps
πŸ”₯
U.S., U.K., Australia Sanction Russian REvil Hacker Behind Medibank Breach
πŸ”₯
Cyber Security Today, Jan. 24, 2024 - The latest ransomware news and a controversy over alleged viruses in HP printer cartridges
πŸ”₯
US, UK, Australia Sanction Russian Man Over Ransomware Attack on Healthcare Insurer
πŸ”₯
VexTrio a hub of Cyber attacks With Massive Criminal Affiliate Chain
πŸ”₯
Trello API Abused to Link Email Addresses to 15 Million Accounts
πŸ”₯
Major US, UK Water Companies Hit by Ransomware
πŸ”₯
Kasseika Ransomware Operators Launch BYOVD Attacks
πŸ”₯
Kasseika Ransomware Using BYOVD Trick to Disarms Security Pre-Encryption
πŸ”₯
Hackers Use SYSTEMBC Tool to Maintain Access to Compromised Network
πŸ”₯
Jason’s Deli Says Customer Data Exposed in Credential Stuffing Attack
πŸ”₯
Beware of rogue chatbot hacking incidents
πŸ”₯
GitGot: GitHub Leveraged by Cybercriminals to Store Stolen Data
πŸ”₯
What Microsoft's Latest Email Breach Says About This IT Security Heavyweight
πŸ”₯
Major US, UK Water Companies Hit By Ransomware
πŸ”₯
AI Rise Will Lead To Increase In Cyberattacks, GCHQ Warns
πŸ”₯
Water Services Giant Veolia North America Hit by Ransomware Attack
πŸ”₯
Ransomware on Tap as Major Water Providers Fall Victim
πŸ”₯
Global fintech firm EquiLend offline after recent cyberattack
πŸ”₯
37C3: how ethical hackers broke DRM on trains | Kaspersky official blog
πŸ”₯
Watching the Watchdog: Learning from HHS' Grant Payment Mess
πŸ”₯
North Korean Hackers Using AI in Advanced Cyberattacks
πŸ•΅οΈ
Windows - Data Protection API - A journey into various DPAPI potential abuses from an offensive security perspective
πŸ•΅οΈ
ISC Stormcast For Wednesday, January 24th, 2024 https://isc.sans.edu/podcastdetail/8822, (Wed, Jan 24th)
πŸ•΅οΈ
Amazon’s French Warehouses Fined Over Employee Surveillance
πŸ•΅οΈ
Chrome 121 Patches 17 Vulnerabilities
πŸ•΅οΈ
Cybersecurity Market Forecasts: AI, API, Adaptive Security, Insurance Expected to Soar
πŸ•΅οΈ
Gen AI Expected to Bring Big Changes to Banking Sector
πŸ•΅οΈ
Use of Generative AI Apps Jumps 400% in 2023, Signaling the Potential for More AI-Themed Attacks
πŸ•΅οΈ
North Korean Threat Actor Targeting Cybersecurity Researchers With Spear Phishing Attacks
πŸ•΅οΈ
Beyond the Hype β€” Where AI Can Shine in Security
πŸ•΅οΈ
340,000 Jason’s Deli Customers Potentially Impacted by Credential Stuffing Attack
πŸ•΅οΈ
Methodology: How we discovered over 18,000 API secret tokens
πŸ•΅οΈ
CISO Conversations: The Legal Sector With Alyssa Miller at Epiq and Mark Walmsley at Freshfields
πŸ•΅οΈ
Orca Flags Dangerous Google Kubernetes Engine Misconfiguration
πŸ•΅οΈ
Israeli Startup Gets $5M Seed Capital to Tackle AI Security
πŸ•΅οΈ
What are You Working on Wednesday
πŸ•΅οΈ
Beware of Weaponized Office Documents that Deliver VenomRAT
πŸ•΅οΈ
Roblox Game 'Hack-A-Cat' Now Part of the Free KnowBe4 Children’s Interactive Cybersecurity Activity Kit
πŸ•΅οΈ
How Datawiza uses Microsoft Entra ID to help universities simplify access
πŸ•΅οΈ
GSA Sparks Security Fears After Buying Risky Chinese Cameras
πŸ•΅οΈ
NSPX30: A sophisticated AitM-enabled implant evolving since 2005
πŸ•΅οΈ
NSPX30: A sophisticated AitM-enabled implant evolving since 2005
🌐
VexTrio: The Uber of Cybercrime - Brokering Malware for 60+ Affiliates
πŸ“°
Sensor Intel Series: Top CVEs in December 2023
πŸ“°
Sensor Intel Series: Top CVEs in December 2023
πŸ“‘
Microsoft: Recent updates cause Sysprep Windows validation errors
πŸ“‘
What is Nudge Security and How Does it Work?
πŸ“‘
Splunk fixed high-severity flaw impacting Windows versions
πŸ“‘
Organizations Invest More in Data Protection But Recover Less
πŸ“‘
Windows 11 KB5034204 update fixes Bluetooth audio issues, 24 bugs
πŸ“‘
Google Pixel phones unusable after January 2024 system update
πŸ“‘
How to secure AD passwords without sacrificing end-user experience
πŸ“‘
Prompt Security wants to make GenAI safe for the enterprise
πŸ“‘
Chrome 121 Patches 17 Vulnerabilities
πŸ“‘
COVID-19 Testing Lab Accused Of Exposing 1.3 Million Records
πŸ“‘
340,000 Jason's Deli Customers Hit By Credential Stuffing Attack
πŸ“‘
Colorado Pastor Accused Of Multimillion Dollar Crypto Scheme
πŸ“‘
Meta Has Not Done Enough To Safeguard Children, Whistleblower Says
πŸ“‘
ACSC Engaging with Artificial Intelligence – Summary for Cyber Centre Website
πŸ“‘
Engaging with Artificial Intelligence
πŸ“‘
Windows 11 KB5034204 Update Fixes Bluetooth Audio Issues, 24 bugs
πŸ“‘
Global Retailer BuyGoods.com Leaks User PII, KYC data
πŸ“‘
SEC Twitter hack blamed on SIM swap attack
πŸ“‘
VexTrio TDS: Inside a massive 70,000-domain cybercrime operation