102Articles
8Categories
2024-02-08Date
🚨
CISA Adds Google Chromium V8 Type Confusion Bug to its Known Exploited Vulnerabilities CatalogThe vulnerability, tracked as CVE-2023-4762, can allow a remote attacker to execute arbitrary code via a crafted HTML page, and has been exploited by threat actors to install spyware on both Apple and Android devices.
KEV
πŸ›
Critical Patches Released for New Flaws in Cisco, Fortinet, VMware Products
πŸ›
Google Fixed an Android Critical Remote Code Execution Flaw
πŸ›
Researchers say attackers are mass-exploiting new Ivanti VPN flaw
πŸ›
Chromium: CVE-2024-1283 Heap buffer overflow in Skia
πŸ›
Chromium: CVE-2024-1284 Use after free in Mojo
πŸ›
Fortinet: APTs Exploiting FortiOS Vulnerabilities in Critical Infrastructure Attacks
⚠️
Google Cybersecurity Action Team Threat Horizons Report #9 Is Out!
⚠️
Google starts blocking users from sideloading certain apps in Singapore
⚠️
Is your cloud security strategy ready for LLMs?
⚠️
China-backed β€˜Volt Typhoon’ preparing wave of attacks
⚠️
BSides London 2023
⚠️
Introducing Smart Answers, a genAI tool for CSO readers
⚠️
CISA Releases Two Industrial Control Systems Advisories
⚠️
Cisco Releases Security Advisory for Vulnerabilities in Cisco Expressway Series
⚠️
Chinese State-Sponsored Actors Compromised and Maintained Persistent Access to U.S. Critical Infrastructure for Five Years
⚠️
Linux Distros Hit by RCE Vulnerability in Shim Bootloader
⚠️
24 on 2024: Asia-Pacific’s cybersecurity thought leaders share their predictions and aspirations
⚠️
CISA Partners With OpenSSF Securing Software Repositories Working Group to Release Principles for Package Repository Security
⚠️
Watch Out For Valentine’s Day Romance Scams
⚠️
Phishing attack uses compromised SendGrid accounts to target additional users
⚠️
Ivanti: Patch new Connect Secure auth bypass bug immediately
⚠️
You Can’t Defend What You Can’t Define - Sergey Bratus - PSW #816
⚠️
Zero-Trust is Meaningless if Your Cryptography is Flakey with Vincent Berk – ESW #349
⚠️
Breach Roundup: US Bans AI Robocalls
⚠️
Zero-Trust is Meaningless if Your Cryptography is Flakey - Vincent Berk - ESW #349
⚠️
New Fortinet RCE flaw in SSL VPN likely exploited in attacks
⚠️
Cisco Patches Critical Vulnerabilities in Enterprise Communication Devices
πŸ“’
Biden Administration Names a Director of the New AI Safety Institute
πŸ“’
SonicWall security advisory (AV24-073)
πŸ“’
NIST’s International Cybersecurity and Privacy Engagement Update – International Dialogues, Workshops, and Translations
πŸ“’
Suspected EncroChat Admin Extradited to France
πŸ“’
White House Targets Software Provider Accountability
πŸ“’
Federal Cybersecurity Agency Launches Program to Boost Support for State, Local Election Offices
πŸ”₯
Smashing Security podcast #358: Hong Kong hijinks, pig butchers, and poor ransomware gangs
πŸ”₯
Record-Breaking Ransomware Profits Surpassed $1B in 2023
πŸ”₯
Group-IB bets on AI to improve threat intelligence and incident response
πŸ”₯
Unprecedented Rise of Malvertising as a Precursor to Ransomware
πŸ”₯
US Says China's Volt Typhoon Hackers Pre-Positioning For Cyberattacks Against Critical Infrastructure
πŸ”₯
Funerals Reportedly Canceled Due to Ransomware Attack on Austrian Town
πŸ”₯
Data breaches at Viamedis and Almerys impact 33 million in France
πŸ”₯
US insurance firms sound alarm after 66,000 individuals impacted by SIM swap attack
πŸ”₯
Device Authority Raises $7M in Series A Funding
πŸ”₯
US offers $10 million for tips on Hive ransomware leadership
πŸ”₯
Cybersecurity Resiliency and Your Board of Directors
πŸ”₯
Hyundai Motor Europe hit by Black Basta ransomware attack
πŸ”₯
Feds Warn Health Sector About Akira Again, Amid New Attacks
πŸ”₯
Fake IDs threaten ID verification services, PANW hits $100B valuation, and other news - ESW #349
πŸ”₯
Cyber Security Today, Feb. 9, 2024 - A record US$1 billion paid to ransomware gangs last year
πŸ”₯
The buck stops here: Why the stakes are high for CISOs
πŸ”₯
Ransomware Payments Surpassed $1 Billion in 2023: Analysis
πŸ”₯
Iran Ramps Up Cyberattacks on Israel Amid Hamas Conflict: Microsoft
πŸ”₯
Microsoft Copilot for Security provides immediate impact for the Microsoft Defender Experts team
πŸ•΅οΈ
ShmooCon 2024 Videos are up!
πŸ•΅οΈ
ISC Stormcast For Thursday, February 8th, 2024 https://isc.sans.edu/podcastdetail/8844, (Thu, Feb 8th)
πŸ•΅οΈ
Beware of Facebook Ads That Deliver Password-Stealing Malware
πŸ•΅οΈ
A Python MP3 Player with Builtin Keylogger Capability, (Thu, Feb 8th)
πŸ•΅οΈ
Kimsuky's New Golang Stealer 'Troll' and 'GoBear' Backdoor Target South Korea
πŸ•΅οΈ
Chinese Hackers Fail to Rebuild Botnet After FBI Takedown
πŸ•΅οΈ
Recommended AppSec conferences in Europe?
πŸ•΅οΈ
On Software Liabilities
πŸ•΅οΈ
81% of Organizations Cite Phishing as the Top Security Risk
πŸ•΅οΈ
Shellcode evasion using Wasm/Wat and Rust
πŸ•΅οΈ
Critical Cisco Expressway Flaw Let Remote Execute Arbitrary Code
πŸ•΅οΈ
Kimsuky APT Disguises as a Korean Company to Distribute Troll Stealer
πŸ•΅οΈ
Cryptohack Roundup: FTX Hacker Was a SIM Swapper
πŸ•΅οΈ
Getting More Out of Investments in Network-Centric Solutions
πŸ•΅οΈ
EMEA Live Panel | Continuous Monitoring + Real-Time Detection = Proactive Threat Intelligence with Rapid Response
πŸ•΅οΈ
Chinese Hackers Operate Undetected in U.S. Critical Infrastructure for Half a Decade
πŸ•΅οΈ
HijackLoader Evolves: Researchers Decode the Latest Evasion Methods
πŸ•΅οΈ
Number of Attacks Against Critical Infrastructure Is Growing
πŸ•΅οΈ
Cohesity Is Set to Acquire Veritas' Data Protection Business
πŸ•΅οΈ
LimaCharlie Lands $10.2 Million Series A Funding
πŸ•΅οΈ
Google Announces Enhanced Fraud Protection for Android
πŸ•΅οΈ
How to Predict Your Patching Priorities
πŸ•΅οΈ
Were 3 Million Toothbrushes Really Used for a DDoS Attack?
πŸ•΅οΈ
News alert: Diversified, GroCyber form partnership to deliver media-centric cybersecurity solutions
🌐
Tooth be told: Toothbrush DDoS attack claim was lost in translation, says Fortinet
🌐
Surge in deepfake β€œFace Swap” attacks puts remote identity verification at risk
🌐
Round 3 in the toothbrush DDoS debacle!
🌐
Android XLoader malware can now auto-execute after installation
πŸ“‘
Critical Cisco Bug Exposes Expressway Gateways to CSRF Attacks
πŸ“‘
Denmark Orders Schools to Stop Sending Student Data to Google
πŸ“‘
NinjaOne Raises $231.5M in Series C Funding
πŸ“‘
Facebook Fatal Accident Scam Still Rages On
πŸ“‘
Google teases a new modern look for sign-in pages, including Gmail
πŸ“‘
One-time passwords and 2FA codes β€” what to do if you receive one without requesting it | Kaspersky official blog
πŸ“‘
Closinglock, now with $12M, wants to prevent the 1 in 10 real estate transactions targeted for fraud
πŸ“‘
Deepfake Face Swap Attacks On ID Verification Systems Up By 704% In 2023
πŸ“‘
Iran-Backed Hackers Interrupt UAE TV With Deepfake News
πŸ“‘
Were 3 Million Toothbrushes Really Used For A DDoS Attack?
πŸ“‘
Raspberry Pi Pico Cracks BitLocker In Under A Minute
πŸ“‘
Security flaw in a popular smart helmet allowed silent location tracking
πŸ“‘
HijackLoader Expands Techniques to Improve Defense Evasion
πŸ“‘
What Generative AI Means for Cybersecurity in 2024
πŸ“‘
What Generative AI Means for Cybersecurity in 2024
πŸ“‘
Fake LastPass password manager spotted on Apple’s App Store
πŸ“‘
Google saves your conversations with Gemini for years by default
πŸ“‘
Microsoft unveils new 'Sudo for Windows' feature in Windows 11
πŸ“‘
Microsoft fixes Copilot issue blocking Windows 11 upgrades
πŸ“‘
Unified Identity – look for the meaning behind the hype!
πŸ“‘
Google Starts Blocking Sideloading of Potentially Dangerous Android Apps in Singapore