113Articles
8Categories
2024-03-22Date
🐛
TeamCity Vulnerability Exploits Leads to Surge in Ransomware Attacks
🐛
Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect | Mandiant
🐛
Critical Vulnerabilities fixed in Firefox 124.0.1
🐛
Exploit available for critical flaw in FortiClient Server
KEV
🐛
CVE-2024-26247 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
🐛
CVE-2024-29057 Microsoft Edge (Chromium-based) Spoofing Vulnerability
🐛
Chromium: CVE-2024-2625 Object lifecycle issue in V8
🐛
Chromium: CVE-2024-2626 Out of bounds read in Swiftshader
🐛
Chromium: CVE-2024-2627 Use after free in Canvas
🐛
Chromium: CVE-2024-2628 Inappropriate implementation in Downloads
🐛
Chromium: CVE-2024-2629 Incorrect security UI in iOS
🐛
Chromium: CVE-2024-2630 Inappropriate implementation in iOS
🐛
Chromium: CVE-2024-2631 Inappropriate implementation in iOS
🐛
CVE-2024-29059 .NET Framework Information Disclosure Vulnerability
⚠️
Lots Of Funding News, Airbus Says No, and Cato Networks Going IPO? - ESW #354
⚠️
Top 5 Myths About API Security and What to Do Instead - Robert Dickinson - ESW #354
⚠️
_Half of North Korea's foreign currency income comes from cyberattacks
⚠️
Hackers earn $1,132,500 for 29 zero-days at Pwn2Own Vancouver
⚠️
Researchers Propose An Invisible Backdoor Attack Dubbed DEBA
⚠️
Unsaflok Vulnerability Lets Hackers Open 3M+ Hotel Doors in Seconds
⚠️
FlowFixation Account Takeover Vulnerability Impacts AWS Managed Apache Airflow Service
⚠️
TinyTurla Evolved TTPs To Stealthly Attack Enterprise Organizations
⚠️
Cyber Security Today, March 22, 2024 - Mac CPUs are vulnerable to encrypted key theft, white hat hackers win a second Tesla, and more
⚠️
Windows 11, Tesla, and Ubuntu Linux Hacked at Pwn2Own Vancouver
⚠️
API Environments Becoming Hotspots for Exploitation
⚠️
DHCP Hacked to Escalate Privileges in Windows Domains
⚠️
Tesla, OS, Software Exploits Earn Hackers $1.1 Million at Pwn2Own 2024
⚠️
One-Click AWS Vulnerability Let Attackers Takeover User’s Web Management Panel
⚠️
Exploit Released For Critical Fortinet RCE Flaw: Patch Soon!
⚠️
Chinese Government Hacker Exploiting Screenconnect, F5 Bugs To Attack Defense and Government Entities
⚠️
Google Pays $10M in Bug Bounties in 2023
⚠️
Implementing Zero Trust Controls for Compliance
⚠️
Understanding and Responding to Distributed Denial-Of-Service Attacks | CISA
⚠️
Saflok Lock Vulnerability Can Be Exploited to Open Millions of Doors
⚠️
GitHub’s New AI-Powered Tool Auto-Fixes Vulnerabilities in Your Code
⚠️
FBI and CISA warn government systems against increased DDoS attacks
⚠️
AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session Hijacking
⚠️
WebCopilot: Open-Source Automation Tool Enumerates Subdomains, Detects Bugs
⚠️
Luxury Yacht Dealer Attack Claimed by Rhysida Gang
⚠️
Apple M-Series Chip Vulnerability Puts Encryption Keys at Risk
⚠️
Mozilla fixes two Firefox zero-day bugs exploited at Pwn2Own
⚠️
Mozilla Drops Onerep After CEO Admits to Running People-Search Networks
⚠️
Likely Chinese Hacking Contractor Is Quick to Exploit N-Days
📋
Microsoft releases emergency fix for Windows Server crashes
📢
US Government Issues New DDoS Mitigation Guidance
📢
US cyber investors pledge spyware is off limits — with a catch
📢
Mozilla security advisory (AV24-155)
📢
CISA, DC HSEMA and Regional Partners Conduct Exercise to Ensure National Capital Region Water Service Resilience
🔥
MediaWorks - 162,710 breached accounts
🔥
Change Healthcare Cyberattack Could Damage Credit at Small Providers: Fitch
🔥
RaaS Groups Increasing Efforts to Recruit Affiliates
🔥
IAG Warns Air Europa’s Consumers of Personal Data Leak
🔥
Jacksonville Beach Report Data Breach Following Cyberattacks
🔥
Philips Respironics Notifies the HHS-OCR of Data Breach Affecting 457,152 Individuals | JD Supra
🔥
China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws
🔥
Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects
🔥
NDSS Symposium 2023
🔥
Fake Data Breaches: Countering the Damage
🔥
South China Athletic Association Suffers Cyberattack Potentially Compromising 70,000 Members’ Data
🔥
Ransomware Group Takes Credit for Attack on Boat Dealer MarineMax
🔥
Report: Malware Stands Out as the Fastest-Growing Threat of 2024
🔥
New Details on TinyTurla’s Post-Compromise Activity Reveal Full Kill Chain
🔥
Cyber Security Today, Week in Review for week ending Friday, March 22, 2024
🔥
Nursing Home Declares Bankruptcy, Blames Recent Cyberattacks
🔥
Russian APT Releases More Deadly Variant of AcidRain Wiper Malware
🕵️
GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent Prefetchers
🕵️
ISC Stormcast For Friday, March 22nd, 2024 https://isc.sans.edu/podcastdetail/8906, (Fri, Mar 22nd)
🕵️
Russian Hackers Target Ukrainian Telecoms with Upgraded 'AcidPour' Malware
🕵️
Attackers are targeting financial departments with SmokeLoader malware - Help Net Security
🕵️
BlueFlag Security Emerges From Stealth With $11.5M in Funding
🕵️
New ‘GoFetch’ Apple CPU Attack Exposes Crypto Keys
🕵️
Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign | Proofpoint US
🕵️
Microsoft Warns of New Tax Returns Phishing Scams Targeting You
🕵️
39,000 Websites Infected in ‘Sign1’ Malware Campaign
🕵️
Munich Cyber Security Conferencec 2024 - 18 talks
🕵️
Truck-to-truck worm could infect entire US fleet
🕵️
‘Brain Weasels’: Impostor Syndrome in Cybersecurity
🕵️
In Other News: Google’s PQC Threat Model, Keyboard Sounds Expose Data, AI Roadmap
🕵️
Russian APT29 Hackers Caught Targeting German Political Parties
🕵️
UN Adopts Resolution Backing Efforts to Ensure Artificial Intelligence is Safe
🕵️
Why You Need a Battle-Tested PAM Solution
🕵️
Solving SandboxAQ's Post-Quantum Crypto CTF
🕵️
Thousands of WordPress sites impacted by Sign1 malware campaign
🕵️
Russian APT29 Hackers Caught Targeting German Political Parties
🕵️
ISMG Editors: How Will the Quantum Era Reshape Cybersecurity?
🕵️
Identity Security Clinic
🕵️
Russian hackers target German political parties with WineLoader malware
🕵️
Robots, UDP, GoFetch, DCs, Pwn2Own, Verner Vinge, Reddit, Aaran Leyland, and More - SWN #371
🕵️
Detecting a tracker pixel/image in email
🕵️
Biden's Economic Team Warns of AI Risks and Job Displacement
🕵️
Friday Squid Blogging: New Species of Squid Discovered
🕵️
Russian Nation-State Hacker Targets German Political Parties
🕵️
GitLab Acquires Oxeye to Bolster SAST in DevSecOps Workflow
🕵️
Security expert Chris Krebs on TikTok, AI and the key to survival (part 2)
🌐
New Sysrv Botnet Variant Makes Use of Google Subdomain to Spread XMRig Miner
🌐
AceCryptor attacks surge in Europe – Week in security with Tony Anscombe
📡
DOJ calls Apple’s privacy justifications an ‘elastic shield’ for financial gains
📡
U.S. Justice Department Sues Apple Over Monopoly and Messaging Security
📡
Red Teaming in the AI Era
📡
Nemesis Darknet Marketplace Raided in Germany-Led Operation
📡
US Airlines’ Privacy Protection Practices to Get DOT Review
📡
New GoFetch attack on Apple Silicon CPUs can steal crypto keys
📡
Email Bomb Attacks: Filling Up Inboxes and Servers Near You
📡
New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S.
📡
Large-Scale StrelaStealer Campaign in Early 2024
📡
Darknet marketplace Nemesis Market seized by German police
📡
Ways to detect and curb Living off the Land (LotL) attacks | Kaspersky official blog
📡
Hackers Can Unlock Over 3 Millions Hotel Doors In Seconds
📡
Apple Lawsuit: US Says iPhone Monopoly Undermines Security
📡
China Relaxes Some Security Review Rules For Data Exports
📡
GoFetch - Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent Prefetchers
📡
AT&T won’t say how its customers’ data spilled online
📡
CISOs: Make Sure Your Team Members Fit Your Company Culture