161Articles
9Categories
2024-02-13Date
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-21412 Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability CVE-2024-21351 Microsoft Windows SmartScreen Security F…
KEV
πŸ›
Ivanti Vulnerability Exploited to Install 'DSLog' Backdoor on 670+ IT Infrastructures
πŸ›
Alert: CISA Warns of Active 'Roundcube' Email Attacks - Patch Now
KEV
πŸ›
ISC Releases Security Advisories for BIND 9
πŸ›
CVE-2024-20667 Azure DevOps Server Remote Code Execution Vulnerability
πŸ›
CVE-2023-50387 MITRE: CVE-2023-50387 DNSSEC verification complexity can be exploited to exhaust CPU resources and stall DNS resolvers
πŸ›
CVE-2024-21327 Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
πŸ›
CVE-2024-21329 Azure Connected Machine Agent Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21338 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21340 Windows Kernel Information Disclosure Vulnerability
πŸ›
CVE-2024-21349 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
πŸ›
CVE-2024-21350 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21351 Windows SmartScreen Security Feature Bypass Vulnerability
πŸ›
CVE-2024-21352 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21354 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21357 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
πŸ›
CVE-2024-21358 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21360 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21361 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21366 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21369 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21371 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21372 Windows OLE Remote Code Execution Vulnerability
πŸ›
CVE-2024-21375 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21379 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2024-21381 Microsoft Azure Active Directory B2C Spoofing Vulnerability
πŸ›
CVE-2024-21386 .NET Denial of Service Vulnerability
πŸ›
CVE-2024-21389 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
πŸ›
CVE-2024-21393 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
πŸ›
CVE-2024-21394 Dynamics 365 Field Service Spoofing Vulnerability
πŸ›
CVE-2024-21396 Dynamics 365 Sales Spoofing Vulnerability
πŸ›
CVE-2024-21401 Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21402 Microsoft Outlook Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21404 .NET Denial of Service Vulnerability
πŸ›
CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
πŸ›
CVE-2024-21420 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-20673 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2024-20679 Azure Stack Hub Spoofing Vulnerability
πŸ›
CVE-2024-21304 Trusted Compute Base Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21315 Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20695 Skype for Business Information Disclosure Vulnerability
πŸ›
CVE-2024-21328 Dynamics 365 Sales Spoofing Vulnerability
πŸ›
CVE-2024-20684 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2024-21339 Windows USB Generic Parent Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-21341 Windows Kernel Remote Code Execution Vulnerability
πŸ›
CVE-2024-21342 Windows DNS Client Denial of Service Vulnerability
πŸ›
CVE-2024-21343 Windows Network Address Translation (NAT) Denial of Service Vulnerability
πŸ›
CVE-2024-21344 Windows Network Address Translation (NAT) Denial of Service Vulnerability
πŸ›
CVE-2024-21345 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21346 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21347 Microsoft ODBC Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-21348 Internet Connection Sharing (ICS) Denial of Service Vulnerability
πŸ›
CVE-2024-21353 Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-21355 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21356 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
πŸ›
CVE-2024-21359 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21362 Windows Kernel Security Feature Bypass Vulnerability
πŸ›
CVE-2024-21363 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
πŸ›
CVE-2024-21364 Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21365 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21367 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21368 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21370 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21374 Microsoft Teams for Android Information Disclosure
πŸ›
CVE-2024-21376 Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
πŸ›
CVE-2024-21377 Windows DNS Information Disclosure Vulnerability
πŸ›
CVE-2024-21378 Microsoft Outlook Remote Code Execution Vulnerability
πŸ›
CVE-2024-21380 Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
πŸ›
CVE-2024-21384 Microsoft Office OneNote Remote Code Execution Vulnerability
πŸ›
CVE-2024-21391 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-21395 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
πŸ›
CVE-2024-21397 Microsoft Azure File Sync Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21403 Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21405 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21406 Windows Printing Service Spoofing Vulnerability
πŸ›
CVE-2024-21410 Microsoft Exchange Server Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21412 Internet Shortcut Files Security Feature Bypass Vulnerability
πŸ›
SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
πŸ›
CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
πŸ›
Attackers target new Ivanti XXE vulnerability days after patch
KEV
⚠️
Blueprint for Threat Intel to Detection Flow (Part 7)
⚠️
Critical Patches Issued for Microsoft Products, February 13, 2024
⚠️
Prudential Financial breached in data theft cyberattack
⚠️
Hackers used new Windows Defender zero-day to drop DarkMe malware
KEV
⚠️
Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
KEV
⚠️
SiCat: Open-Source Exploit Finder
⚠️
Hackers Exploit Ivanti SSRF Flaw to Deploy New DSLog Backdoor
⚠️
Microsoft Confirms Windows Exploits Bypassing Security Features
⚠️
Ivanti Vulnerability Exploited to Deliver New β€˜DSLog’ Backdoor
⚠️
Fat Patch Tuesday, February 2024 Edition
⚠️
Microsoft February 2024 Patch Tuesday, (Tue, Feb 13th)
⚠️
Microsoft Releases Security Updates for Multiple Products
⚠️
CISA Releases One Industrial Control Systems Advisory
⚠️
Adobe Releases Security Updates for Multiple Products
⚠️
Seal Security wants to make open source vulnerability remediation easy
⚠️
Ivanti Vuln Exploited To Deliver New DSLog Backdoor
⚠️
Infosys Subsidiary Named As Source Of Bank of America Data Leak
⚠️
AI adoption in security taking off amid budget, trust, and skill-based issues
⚠️
How to strengthen your Kubernetes defenses
⚠️
A changing world requires CISOs to rethink cyber preparedness
⚠️
High-profile incidents put spotlight on non-production system security
⚠️
Proactive Compliance, Improving Cybersecurity Culture, and Hiring The Right Skills - BSW #338
⚠️
Creating Code Security Through Better Visibility - Christien Rioux - ASW #273
⚠️
The Ultimate OSINT Collection
⚠️
CISA, FBI warn of China-linked hackers pre-positioning for β€˜destructive cyberattacks against US critical infrastructure’
⚠️
Free Rhysida ransomware recovery tool published
πŸ“‹
Patch Tuesday: Adobe Warns of Critical Flaws in Widely Deployed Software
πŸ“‹
ICS Patch Tuesday: Siemens Addresses 270 Vulnerabilities
πŸ“’
News alert: Kiteworks named as a founding member of NIST’s new AI safety consortium – β€˜AISIC’
πŸ“’
Data residency: What is it and why it is important?
πŸ“’
Raspberry Pi Pico cracks BitLocker in under a minute
πŸ”₯
Integris Health says data breach impacts 2.4 million patients
πŸ”₯
Jet Engine Dealer to Major Airlines Discloses β€˜Unauthorized Activity’
πŸ”₯
Bank of America Warns Customers of Data Breach After Vendor Hack
πŸ”₯
French Healthcare Payments Processor Breaches Affect Half of Population
πŸ”₯
Willis Lease Finance Corp Discloses Cyberattack
πŸ”₯
Bank of America Customer Data Stolen in Data Breach
πŸ”₯
Midnight Blizzard and Cloudflare-Atlassian Cybersecurity Incidents: What to Know
πŸ”₯
DarkGate Malware opens RaaS For Financially Motivated Hackers
πŸ”₯
DNA Testing: What Happens If Your Genetic Data Is Hacked?
πŸ”₯
Korean Eggheads Crack Rhysida Ransomware And Release Free Decryptor Tool
πŸ”₯
Tool sprawl is hurting application security, US CSOs say
πŸ”₯
Cyber Attacks Spike Suddenly Prior to Taiwan’s Election
πŸ”₯
Decrypted: Rhysida Ransomware - "we are now publicly releasing our decryptor for download to all victims of the Rhysida ransomware"
πŸ•΅οΈ
A Hacker’s Mind is Out in Paperback
πŸ•΅οΈ
Molly White Reviews Blockchain Book
πŸ•΅οΈ
200,000 Facebook Marketplace user records leaked on hacking forum
πŸ•΅οΈ
5 Steps to Improve Your Security Posture in Microsoft Teams
πŸ•΅οΈ
JFK Airport Taxi Hackers Sentenced to Prison
πŸ•΅οΈ
PikaBot Resurfaces with Streamlined Code and Deceptive Tactics
πŸ•΅οΈ
ISC Stormcast For Tuesday, February 13th, 2024 https://isc.sans.edu/podcastdetail/8850, (Tue, Feb 13th)
πŸ•΅οΈ
CyberheistNews Vol 14 #07 Social Engineering Masterstroke: How Deepfake CFO Duped a Firm out of $25 Million
πŸ•΅οΈ
Fileless Revenge RAT Abuses Legitimate Tools to Hide Malicious Activity
πŸ•΅οΈ
New Azure Hacking Campaign Steals Senior Executive Accounts
πŸ•΅οΈ
Turk Hack Team Attacked the World’s Largest Cooperative Finance
πŸ•΅οΈ
What Is Volt Typhoon And Why Is It The Defining Threat Of Our Generation?
πŸ•΅οΈ
LLMs & Security Tools, Shim Vuln, AI Threat Models, Configuration as Code with Pkl - ASW #273
πŸ•΅οΈ
Angry mobs, Azure, Avanti, Rhysida, Warzone, Flipper Zero, Josh Marpet, and More - SWN #362
πŸ•΅οΈ
Angry mobs, Azure, Avanti, Rhysida, Warzone, Flipper Zero, Josh Marpet, and More – SWN #362
πŸ•΅οΈ
The Business Side of AI - Edward Contreras - CSP #161
πŸ•΅οΈ
83% of Indian cybersecurity, IT workers impacted by burnout, fatigue: Report - Social News XYZ
πŸ•΅οΈ
ChatGPT Account Takeover via Wildcard Web Cache Deception
πŸ•΅οΈ
PAPERWALL: Chinese Websites Posing as Local News Outlets Target Global Audiences with Pro-Beijing Content
🌐
Bumblebee malware attacks are back after 4-month break
🌐
Diving Into Glupteba's UEFI Bootkit
🌐
Notorious Bumblebee Malware Re-emerges with New Attack Methods
🌐
Glupteba Botnet Evades Detection with Undocumented UEFI Bootkit
πŸ“‘
Sophos Wins Top Employer Awards in British Columbia, Canada
πŸ“‘
Windows 10 KB5034763 update released with new fixes, changes
πŸ“‘
Windows 11 KB5034765 update released with Start Menu fixes
πŸ“‘
Hackers steal $290 million in crypto from PlayDapp gaming platform
πŸ“‘
Fertility tracker Glow fixes bug that exposed users’ personal data
πŸ“‘
Azure Account Takeover Campaign Targets Senior Execs
πŸ“‘
JFK Airport Taxi Hackers Sentenced To Prison
πŸ“‘
Your Mac Is Not Virus Proof. It Never Has Been.
πŸ“‘
Global Cybersecurity Trends: AI, Geopolitical Risks, and Zero Trust
πŸ“‘
Global Cybersecurity Trends: AI, Geopolitical Risks, and Zero Trust
πŸ“‘
Cyberthreats to marketing | Kaspersky official blog
πŸ“‘
PHP deserialization attacks and a new gadget chain in Laravel
πŸ“‘
Deepfakes in the global election year of 2024: A weapon of mass deception?
πŸ“‘
Hackers mint 1.79 billion crypto tokens from PlayDapp gaming platform