122Articles
10Categories
2024-02-01Date
🚨
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical InfrastructureSUMMARY The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) assess that People’s Republic of China (PRC) state-sponsored cyber actors are seeking to pre-position themselves on IT networks for disru…
KEV
🐛
RunC Flaws Enable Container Escapes, Granting Attackers Host Access
🐛
CISA Warns of Active Exploitation of Critical Vulnerability in iOS, iPadOS, and macOS
KEV
🐛
Glibc library vulnerability published | Kaspersky official blog
🐛
Exploit Released for Android Local Elevation Flaw Impacting Seven OEMs
🐛
Moby and Open Container Initiative Release Critical Updates for Multiple Vulnerabilities Affecting Docker-related Components
⚠️
Mercedes-Benz Source Code Leaked via mishandled GitHub token
⚠️
Warning: New Malware Emerges in Attacks Exploiting Ivanti VPN Vulnerabilities
⚠️
CISA Warns of Active Exploitation of Critical Flaws in Apple iOS and macOS
⚠️
Ransomware Incidents Hit Record High, But Law Enforcement Takedowns Slow Growth
⚠️
Two New Ivanti Bugs Discovered as CISA Warns of Hackers Bypassing Mitigations
⚠️
MOVEit Liabilities Mount for Progress Software
⚠️
Apple Patches Vision Pro Vulnerability as CISA Warns of iOS Flaw Exploitation
⚠️
Audio-jacking: Using generative AI to distort live audio transactions
⚠️
Why the Right Metrics Matter When it Comes to Vulnerability Management
⚠️
HeadCrab 2.0 Goes Fileless, Targeting Redis Servers for Crypto Mining
⚠️
Feds Say Anti-Robocall Efforts Appear to be Working Against Foreign Sources
⚠️
Facebook’s Extensive Surveillance Network
⚠️
U.S. Feds Shut Down China-Linked "KV-Botnet" Targeting SOHO Routers
⚠️
Protect AI adds LLM support with open source acquisition
⚠️
Faction: Open-Source Pentesting Report Generation and Collaboration Framework
⚠️
CISA orders federal agencies to disconnect Ivanti VPN appliances by Saturday
KEV
⚠️
Okta lays off 400 employees — almost exactly a year after last staff cuts
⚠️
Wray's Stunning Warning Points To A New Age Of US Vulnerability
⚠️
New Windows Event Log zero-day flaw gets unofficial patches
⚠️
FritzFrog Returns with Log4Shell and PwnKit, Spreading Malware Inside Your Network
⚠️
CVE, CVSS, EPSS Falls Short - PSW #815
⚠️
CISA Releases Two Industrial Control Systems Advisories
⚠️
Zero-Day Vulnerability can Blind Defenses Relying on Windows Event Logs
⚠️
US gives federal agencies 48 hours to disconnect flawed Ivanti VPN tech
⚠️
Microsoft Teams: The New Phishing Battlefront - How Attackers Are Exploiting Trusted Platforms
⚠️
Does CVSS 4.0 Solve the Exploitability Problem?
⚠️
UN Cybercrime Treaty Could Endanger Web Security
⚠️
Okta Lays Off 400 Employees in Second Round of Dismissals
⚠️
Protect AI Acquires Laiyer AI to Better Secure AI Models
⚠️
Bazel PoC attack highlights transitive vulnerability risk in custom GitHub Actions
⚠️
UK: City Cyber Task Force Launches to Secure Corporate Finance
⚠️
Cloudflare hacked using auth tokens stolen in Okta attack
⚠️
The Elephant in the Pipeline: Securing the Wild, Untamed Software Supply Chain - Pete ... - ESW #348
📋
Mastodon security update: every version prior to today's is vulnerable to remote user impersonation and takeover
📋
The Elephant in the Pipeline: Securing the Wild, Untamed Software Supply Chain – Pete Morgan
📢
US IaaS Providers Face 'Know Your Customer' Regulation
📢
US security agencies terminate China-backed hacking attempt
📢
Hackers Obtain Confidential Information on Romanian Officials After Cyberattack at Parliament
📢
Global Affairs Canada Hit by Cyberattack, Shuts Down Computer Systems to Fix
📢
CISA Sets 48-hour Deadline for Removal of Insecure Ivanti Products
📢
Juniper Networks security advisory (AV24-059)
📢
How is IR sniping and AI changing the game in today’s ever-evolving threat situation?
📢
CISA Hosts Second Cyber Resilient 911 Symposium
📢
Apple security advisory (AV24-060)
🔥
Phobos Ransomware Expands with New FAUST Variant
🔥
Nitrogen Shelling Malware From Hacked Sites
🔥
Hackers Started using Python for Developing New Ransomware
🔥
Cybercriminals Embrace Smarter Strategies, Less Effort
🔥
Cybercriminals Stole Around $112 Million Worth of XRP From Ripple’s Co-Founder
🔥
Johnson Controls Ransomware Attack: Data Theft Confirmed, Cost Exceeds $27 Million
🔥
Football Australia Data Leak Exposes Players’ Contracts, Fans’ Personal Details
🔥
New York Sues Citibank Over Poor Data Security
🔥
At Least 30 Journalists, Lawyers and Activists Hacked With Pegasus in Jordan, Forensic Probe Finds
🔥
Update: Johnson Controls Reports $27M Hit From Ransomware Attack
🔥
The Rise of Python-Scripted Ransomware
🔥
LockBit Shows No Remorse For Ransomware Attack On Children's Hospital
🔥
Pentagon Investigating Theft of Sensitive Files by Ransomware Group
🔥
Identifying Bad By Defining Good - Danny Jenkins - PSW #815
🔥
Cryptohack Roundup: 2024's Biggest Heist - So Far
🔥
Europcar Denies Data Breach of 50 Million Users, Says Data is Fake
🔥
Transatlantic Cable podcast episode 332 | Kaspersky official blog
🔥
FTC orders Blackbaud to boost security after massive data breach
🔥
How 2023 Broke Long-Running Records for Health Data Breaches
🔥
The Internet of Shit, AI Funding, Market Struggles, The Cyber Why, and when to Quit - ESW #348
🔥
Breach Roundup: CIA Hacking Tool Leaker Gets 40 Years
🔥
FTC Blasts Blackbaud's 'Shoddy' Practices in Ransomware Hack
🕵️
Leaky Vessels: Docker and runc Container Breakout Vulnerabilities - January 2024
🕵️
US Says it Disrupted a China Cyber Threat, but Warns Hackers Could Still Wreak Havoc for Americans
🕵️
ISC Stormcast For Thursday, February 1st, 2024 https://isc.sans.edu/podcastdetail/8834, (Thu, Feb 1st)
🕵️
‘Tis the Season for Tax Hax
🕵️
Why Are Cybersecurity Automation Projects Failing?
🕵️
Pawn Storm APT Launch Hash Relay Attacks on Government Departments
🕵️
Grandoreiro Banking Malware Infrastructure Seized by Authorities
🕵️
[Live Demo] Ridiculously Easy Security Awareness Training and Phishing
🕵️
Short, Mid and Long-Term Impacts of AI in Cybersecurity
🕵️
Man Sentenced to Prison for Stealing Millions in Cryptocurrency via SIM Swapping
🕵️
Feds Untether Hundreds Of Routers From Volt Typhoon Botnet
🕵️
‘Leaky Vessels’ Container Escape Vulnerabilities Impact Docker, Others
🕵️
Watch: Top Cyber Officials Testify on China’s Cyber Threat to US Critical Infrastructure
🕵️
How Long Will FBI's 'Volt Tycoon' Router Interdiction Stick?
🕵️
Associated Press: "Grave peril of digital conspiracy theories."
🕵️
81% of Underwriters Expect Cyber Insurance Premiums to Increase as Risk is Expected to Soar
🕵️
ANY.RUN Sandbox Now Let SOC & DFIR Teams Analyze Sophisticated Linux Malware
🕵️
Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal
🕵️
Your Security Program Is Shit
🕵️
Uber Fined 10 Million Euros by Dutch Data Regulator
🕵️
Palo Alto Told to Pay Centripetal $150M for Patent Theft
🕵️
VajraSpy: A Patchwork of espionage apps
🕵️
Connect with Microsoft at these cybersecurity events in 2024
🕵️
3 new ways the Microsoft Intune Suite offers security, simplification, and savings
🕵️
The Economic Ripple Effects of Automated Counter-Drone Solutions
🌐
EMEA Live Panel | Defending Against Today's Threat Landscape with MDR
🌐
AI-Generated Code Leads to Security Issues for Most Businesses: Report
🌐
Brazilian Police Make Arrests in Grandoreiro Banking Malware Case
🌐
PurpleFox malware infected thousands of systems in Ukraine
🌐
More Android apps riddled with malware spotted on Google Play
🌐
PurpleFox malware infects thousands of computers in Ukraine
🎙️
Smashing Security podcast #357: Interview with an iPhone thief, anti-AI, and have we gone too far?
📡
Nigerian 'Yahoo Boys' Behind Social Media Sextortion Surge in the US
📡
New York AG Sues Citibank for Poor Phishing Protections
📡
'Leaky Vessels' Cloud Bugs Allow Container Escapes Globally
📡
HeadCrab 2.0 Goes Fileless, Targeting Redis Servers for Crypto Mining
📡
Exposed Docker APIs Under Attack in 'Commando Cat' Cryptojacking Campaign
📡
What is a "Top Level Domain"?, (Thu, Feb 1st)
📡
Italian Data Protection Watchdog Accuses ChatGPT of Privacy Violations
📡
Meta Boss Mark Zuckerberg Apologizes To Families In Fiery Senate Hearing
📡
Man Sentenced To Prison For Cryptocurrency Theft Via SIM Swapping
📡
New York Sues Citibank Over Poor Data Security
📡
Google shares fix for Pixel phones hit by bad system update
📡
US Charges Two More Suspects With DraftKings Account Hacks
📡
Safeguarding UK Energy: A Deep Dive into Cybersecurity Strategies
📡
Aim Security Raises $10M for its GenAI Security Platform
📡
Here is Apple’s official ‘jailbroken’ iPhone for security researchers
📡
Incognia Raises $31M in Series B Funding
📡
Arrests in $400M SIM-Swap Tied to Heist at FTX?
📡
Microsoft fixes connection issue affecting Outlook email apps