100Articles
8Categories
2024-03-05Date
๐Ÿšจ
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2023-21237 Android Pixel Information Disclosure Vulnerability CVE-2021-36380 Sunhillo SureLine OS Command Injection Vulnerablity These typesโ€ฆ
KEV
๐Ÿ›
Critical JetBrains TeamCity On-Premises Flaws Could Lead to Server Takeovers
๐Ÿ›
Exploit Available for New Critical JetBrains TeamCity Authentication Bypass Bug, Patch Now
๐Ÿ›
TeamCity hit by critical software supply chain bugs
๐Ÿ›
Apple Releases iOS/iPadOS Updates with Zero Day Fixes., (Tue, Mar 5th)
โš ๏ธ
How the Application โ€˜XHelperโ€™ Is Powering the Indian Money-Laundering Gig Economy
โš ๏ธ
143: Jim Hates Scams
โš ๏ธ
How GenAI helps entry-level SOC analysts improve their skills
โš ๏ธ
CACTUS Hackers Exploiting Software Bug to Attack Corporate Networks
โš ๏ธ
TA577 Exploits NTLM Authentication Vulnerability
โš ๏ธ
Securing Software Repositories Leads to Better OSS Security
โš ๏ธ
ScreenConnect Flaws Exploited to Drop New ToddleShark Malware
โš ๏ธ
Open Source IDS - Security Onion 2.4
โš ๏ธ
Critical Vulnerability Exposes TeamCity Servers to Takeover
โš ๏ธ
Zeek Security Tool Vulnerabilities Allow ICS Network Hacking
โš ๏ธ
Self-Propagating Worm Created to Target Generative AI Systems
โš ๏ธ
ALPHV BlackCat New Leak Site Seized by Authorities
โš ๏ธ
Nepali Hacker Tops Hall of Fame by Reporting Facebook's Zero-Click Flaw
โš ๏ธ
An Air Force Employee Shared Highly Classified Data Via Dating App
โš ๏ธ
Hackers Exploited Windows 0-Day For 6 Months After Microsoft Knew About It
โš ๏ธ
CISA Releases Three Industrial Control Systems Advisories
โš ๏ธ
Hackers abuse QEMU to covertly tunnel network traffic in cyberattacks
โš ๏ธ
Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware
โš ๏ธ
Why Your Firewall Will Kill You, (Tue, Mar 5th)
โš ๏ธ
Cyberattack Forces Canadaโ€™s Financial Intelligence Agency to Take Systems Offline
โš ๏ธ
JetBrains' TeamCity Bugs Could Lead to Server Takeover
โš ๏ธ
The Simple Mistakes and Complex Seeds of a Vulnerability Management Program - Emily Fox - ASW #275
โš ๏ธ
Apple Blunts Zero-Day Attacks With iOS 17.4 Update
โš ๏ธ
Apple fixes two new iOS zero-days exploited in attacks on iPhones
โš ๏ธ
CrowdStrike to Buy Israeli Data Defense Vendor Flow Security
โš ๏ธ
Germany Rules Out Russian Hack in Military Data Leak
โš ๏ธ
Multiple Vulnerabilities in Apple Products Could Allow for Privilege Escalation.
๐Ÿ“ข
Ukraine Claims it Hacked Russian Ministry of Defense Servers
๐Ÿ“ข
SolarWinds security advisory (AV24-120)
๐Ÿ“ข
A Printout on Secure by Design When Utilizing 3rd Parties - Bryan Willett - CSP #164
๐Ÿ“ข
VMware security advisory (AV24-122)
๐Ÿ“ข
JetBrains security advisory (AV24-121)
๐Ÿ“ข
โ€‹โ€‹Secure SaaS applications with Valence Security and Microsoft Securityโ€‹โ€‹
๐Ÿ”ฅ
Iowa Electric, Water Utility Says Information of Nearly 37,000 Leaked in January Ransomware Attack
๐Ÿ”ฅ
Over 225,000 Compromised ChatGPT Credentials Up for Sale on Dark Web Markets
๐Ÿ”ฅ
Amex Customer Data Exposed in Third-Party Breach
๐Ÿ”ฅ
RA World Ransomware Attack Windows Using Hacked Domain Control & Anti-AV Tactics
๐Ÿ”ฅ
American Express Discloses Data Breach
๐Ÿ”ฅ
Update: BlackCat Ransomware Turns off Servers Amid Claim They Stole $22 Million Ransom
๐Ÿ”ฅ
American Express Data Breach Exposed Customer Data
๐Ÿ”ฅ
BlackCat ransomware shuts down in exit scam, blames the "feds"
๐Ÿ”ฅ
GhostLocker 2.0 Haunts Businesses Across Middle East, Africa, and Asia
๐Ÿ”ฅ
Sophos Guidance on CIRCIA
๐Ÿ”ฅ
Mr. Green Gaming Suffers Data Breach, Exposing Personal Information of 27,000 Users
๐Ÿ”ฅ
How to Improve Health Data Breach Response Planning
๐Ÿ”ฅ
A New Self-Spreading, Zero-Click Gen AI Worm Has Arrived!
๐Ÿ•ต๏ธ
ISC Stormcast For Tuesday, March 5th, 2024 https://isc.sans.edu/podcastdetail/8880, (Tue, Mar 5th)
๐Ÿ•ต๏ธ
GTPDOOR โ€“ Previously Unknown Linux Malware Attack Telecom Networks
๐Ÿ•ต๏ธ
Discord military leaker pleads guilty, gets 16 years
๐Ÿ•ต๏ธ
Warning: Thread Hijacking Attack Targets IT Networks, Stealing NTLM Hashes
๐Ÿ•ต๏ธ
Accelerate Your Cybersecurity Transformation at Ignite On Tour
๐Ÿ•ต๏ธ
Cybercriminals Using Novel DNS Hijacking Technique for Investment Scams
๐Ÿ•ต๏ธ
South Korea Says Semiconductor Industry Targeted by Cyber-Spies From North Korea
๐Ÿ•ต๏ธ
Phishers Abusing Legitimate but Neglected Domains To Pass DMARC Checks
๐Ÿ•ต๏ธ
Phishing Kit Targets the FCC and Crypto Exchanges
๐Ÿ•ต๏ธ
The Insecurity of Video Doorbells
๐Ÿ•ต๏ธ
Hacktivist Collective NoName057(16) Strikes European Targets
๐Ÿ•ต๏ธ
Axonius Raises $200M, Aims to Guard More Asset Types Via M&A
๐Ÿ•ต๏ธ
CyberheistNews Vol 14 #10 [SCARY] You Knew About OSINT, But Did You Know About ADINT?
๐Ÿ•ต๏ธ
From federation to fabric: IAMโ€™s evolution
๐Ÿ•ต๏ธ
Axonius Banks $200 Million in Late-Stage Funding
๐Ÿ•ต๏ธ
Investment Firm Team8 Raises Additional $500 Million
๐Ÿ•ต๏ธ
Cybersecurity M&A Roundup: 27 Deals Announced in February 2024
๐Ÿ•ต๏ธ
Microsoft and OpenAI Team Up to Block Threat Actor Access to AI
๐Ÿ•ต๏ธ
Dtex Systems Snags $50M from Alphabetโ€™s CapitalG
๐Ÿ•ต๏ธ
Cloudflare Introduces AI Security Solutions
๐Ÿ•ต๏ธ
How to Create a Sandbox Environment For Malware Analysis โ€“ A Complete Guide
๐Ÿ•ต๏ธ
VMware Patches Critical ESXi Sandbox Escape Flaws
๐Ÿ•ต๏ธ
TA577 Now Focusing on NT LAN Manager Authentication Theft
๐Ÿ•ต๏ธ
SAML & Secrets, Serializing AI Models, OWASP ISTG, More Memory Safety - ASW #275
๐Ÿ•ต๏ธ
US Sanctions Spyware Company and Executives Who Targeted American Journalists, Government Officials
๐Ÿ•ต๏ธ
ToddleShark, Zeek, Stuxnet revisited, ICS, AMEX, Apple, Change, Josh Marpet, and More - SWN #366
๐Ÿ•ต๏ธ
Hornetsecurity Buys Vade to Fuel Strength in France, Germany
๐ŸŒ
Report: 95% Believe LLMs Making Phishing Detection More Challenging
๐ŸŒ
Self-Propagating Worm Created to Target Generative AI Systems
๐ŸŒ
Zeek Security Tool Vulns Allow ICS Network Hacking
๐ŸŒ
US sanctions founder of spyware maker Intellexa for targeting Americans
๐ŸŒ
New CHAVECLOAK Banking Trojan Targets Brazilians via Malicious PDFs
๐ŸŒ
U.S. sanctions Predator spyware operators for spying on Americans
๐ŸŒ
New WogRAT malware abuses online notepad service to store malware
๐Ÿ“ก
GitHub Push Protection Now on by Default for Public Repositories
๐Ÿ“ก
The Impact of Organizational Structure on Cybersecurity Outcomes
๐Ÿ“ก
Update: Optum Offering Financial Aid to Some Providers Hit by Outage
๐Ÿ“ก
What is Exposure Management and How Does it Differ from ASM?
๐Ÿ“ก
Axonius, a specialist in cyber asset managment, secures $200M at a flat $2.6B valuation
๐Ÿ“ก
Protecting surveillance cameras and smart doorbells from intruders | Kaspersky official blog
๐Ÿ“ก
Discord Leaker Jack Teixeira Pleads Guilty, Seeks Light 11-Year Sentence
๐Ÿ“ก
JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities
๐Ÿ“ก
Passwords are Costing Your Organization Money - How to Minimize Those Costs
๐Ÿ“ก
Facebook and Instagram outage logs out users, passwords not working
๐Ÿ“ก
Microsoft is killing off the Android apps in Windows 11 feature
๐Ÿ“ก
Security tips for organizations with remote workers - ITSAP.10.016
๐Ÿ“ก
How NOT to Lead
๐Ÿ“ก
NSA shares zero-trust guidance to limit adversaries on the network
๐Ÿ“ก
Irresistible: Hooks, habits and why you canโ€™t put down your phone