208Articles
8Categories
2024-04-09Date
πŸ›
Critical Flaws Leave 92,000 D-Link NAS Devices Vulnerable to Malware Attacks
πŸ›
HTTP/2 Vulnerability Let Hackers Launch DOS Attacks on Web Servers
πŸ›
D-Link RCE Vulnerability That Affects 92,000 Devices Exploited in Wild
KEV
πŸ›
Exploitation Attempts Target Unpatched Flaw Affecting Many D-Link NAS Devices
KEV
πŸ›
Patches for CVE-2024-1086 for CloudLinux 6h, 7 Users on KernelCare Live
πŸ›
Sysdig digs up a ransomware gang in stealth for over a decade
πŸ›
Thousands Of Internet-Exposed Ivanti VPN Appliances Vulnerable To RCE Attacks
πŸ›
Lessons That The XZ Utils Backdoor Spells Out - Farshad Abasi - ASW #280
πŸ›
Microsoft patches actively exploited security feature bypass vulnerability (CVE-2024-29988) - Help Net Security
KEV
πŸ›
CVE-2024-26193 Azure Migrate Remote Code Execution Vulnerability
πŸ›
CVE-2024-20688 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-20693 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20669 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-20665 BitLocker Security Feature Bypass Vulnerability
πŸ›
CVE-2024-20678 Remote Procedure Call Runtime Remote Code Execution Vulnerability
πŸ›
CVE-2024-21424 Azure Compute Gallery Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21447 Windows Authentication Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26250 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26252 Windows rndismp6.sys Remote Code Execution Vulnerability
πŸ›
CVE-2024-26253 Windows rndismp6.sys Remote Code Execution Vulnerability
πŸ›
CVE-2024-26254 Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability
πŸ›
CVE-2024-26255 Windows Remote Access Connection Manager Information Disclosure Vulnerability
πŸ›
CVE-2024-26256 libarchive Remote Code Execution Vulnerability
πŸ›
CVE-2024-26172 Windows DWM Core Library Information Disclosure Vulnerability
πŸ›
CVE-2024-26179 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-26200 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-26205 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-26158 Microsoft Install Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26232 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
πŸ›
CVE-2024-28920 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28922 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28921 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28919 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28923 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28896 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28898 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28901 Windows Remote Access Connection Manager Information Disclosure Vulnerability
πŸ›
CVE-2024-28902 Windows Remote Access Connection Manager Information Disclosure Vulnerability
πŸ›
CVE-2024-28903 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28905 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2024-29050 Windows Cryptographic Services Remote Code Execution Vulnerability
πŸ›
CVE-2024-29063 Azure AI Search Information Disclosure Vulnerability
πŸ›
CVE-2024-29064 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2024-29066 Windows Distributed File System (DFS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-20685 Azure Private 5G Core Denial of Service Vulnerability
πŸ›
CVE-2024-23593 Lenovo: CVE-2024-23593 Zero Out Boot Manager and drop to UEFI Shell
πŸ›
CVE-2024-23594 Lenovo: CVE-2024-23594 Stack buffer overflow in Lenovo system recovery boot manager
πŸ›
CVE-2024-29988 SmartScreen Prompt Security Feature Bypass Vulnerability
πŸ›
CVE-2024-29990 Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
πŸ›
CVE-2024-20689 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26168 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26171 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26175 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26180 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26183 Windows Kerberos Denial of Service Vulnerability
πŸ›
CVE-2024-26189 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26194 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26195 DHCP Server Service Remote Code Execution Vulnerability
πŸ›
CVE-2024-26202 DHCP Server Service Remote Code Execution Vulnerability
πŸ›
CVE-2024-26209 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
πŸ›
CVE-2024-26218 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26219 HTTP.sys Denial of Service Vulnerability
πŸ›
CVE-2024-26220 Windows Mobile Hotspot Information Disclosure Vulnerability
πŸ›
CVE-2024-26221 Windows DNS Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-26222 Windows DNS Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-26223 Windows DNS Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-26224 Windows DNS Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-26227 Windows DNS Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-26231 Windows DNS Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-26233 Windows DNS Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-26241 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26243 Windows USB Print Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26248 Windows Kerberos Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26210 Microsoft WDAC OLE DB Provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-26229 Windows CSC Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26235 Windows Update Stack Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26236 Windows Update Stack Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26237 Windows Defender Credential Guard Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26242 Windows Telephony Server Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26244 Microsoft WDAC OLE DB Provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-26245 Windows SMB Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26207 Windows Remote Access Connection Manager Information Disclosure Vulnerability
πŸ›
CVE-2024-26208 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
πŸ›
CVE-2024-26211 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26212 DHCP Server Service Denial of Service Vulnerability
πŸ›
CVE-2024-26213 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26214 Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-26215 DHCP Server Service Denial of Service Vulnerability
πŸ›
CVE-2024-26216 Windows File Server Resource Management Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26217 Windows Remote Access Connection Manager Information Disclosure Vulnerability
πŸ›
CVE-2024-26226 Windows Distributed File System (DFS) Information Disclosure Vulnerability
πŸ›
CVE-2024-26228 Windows Cryptographic Services Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26230 Windows Telephony Server Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26239 Windows Telephony Server Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26240 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-26251 Microsoft SharePoint Server Spoofing Vulnerability
πŸ›
CVE-2024-28924 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28925 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28897 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-28900 Windows Remote Access Connection Manager Information Disclosure Vulnerability
πŸ›
CVE-2024-28904 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2024-28907 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2024-28917 Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
πŸ›
CVE-2024-29052 Windows Storage Elevation of Privilege Vulnerability
πŸ›
CVE-2024-29056 Windows Authentication Elevation of Privilege Vulnerability
πŸ›
CVE-2024-29061 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-29062 Secure Boot Security Feature Bypass Vulnerability
πŸ›
CVE-2024-20670 Outlook for Windows Spoofing Vulnerability
πŸ›
CVE-2024-29989 Azure Monitor Agent Elevation of Privilege Vulnerability
πŸ›
CVE-2024-29992 Azure Identity Library for .NET Information Disclosure Vulnerability
πŸ›
CVE-2024-29993 Azure CycleCloud Elevation of Privilege Vulnerability
⚠️
5 groups that support diversity in cybersecurity
⚠️
Google Rolls Out β€œFind My Device” Network for Android Users
⚠️
Notepad++ Wants Your Help to Take Down the Parasite Website
⚠️
Malware-Initiated Vulnerability Scanning is on the Rise
⚠️
Top Israeli Spy Chief Identity Exposed In A Privacy Mistake
⚠️
CISO Conversations: Nick McKenzie (Bugcrowd) and Chris Evans (HackerOne)
⚠️
Google Adds V8 Sandbox To Chrome To Fight Against Browser Attacks
⚠️
Researchers Discover LG Smart TV Vulnerabilities Allowing Root Access
⚠️
Hackers Using ScrubCrypt β€˜AV Evasion Tool’ To Exploit Oracle WebLogic Servers
⚠️
Critical Takeover Vulns In 92,000 D-Link Devices Under Active Exploitation
⚠️
RUBYCARP hackers linked to 10-year-old cryptomining botnet
⚠️
Implementing container security best practices using Wazuh
⚠️
CISA Releases One Industrial Control Systems Advisory
⚠️
Asia-Focused Dark Web Threat Intelligence Startup StealthMole Raises $7 Million
⚠️
Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
⚠️
Patch Tuesday: Code Execution Flaws in Multiple Adobe Software Products
⚠️
Aged D-Link NAS Devices Are Being Exploited by Hackers
⚠️
GHC-SCW: Ransomware gang stole health data of 533,000 people
⚠️
Automattic buys Beeper for $125MM, launches closed-source "privacy" app
KEV
⚠️
Dronepocalypse, Microsoft, DLINK, Home Depot, Phishing, NIST, VenomRat, Josh Marpet - SWN #376
⚠️
Microsoft Releases April 2024 Security Updates
⚠️
Adobe Releases Security Updates for Multiple Products
⚠️
Critical Rust flaw enables Windows command injection attacks
⚠️
April 2024 Microsoft Patch Tuesday Summary, (Tue, Apr 9th)
⚠️
Researchers uncover evasion data exfiltration techniques that can be exploited in SharePoint
⚠️
Microsoft fixes two Windows zero-days exploited in malware attacks
KEV
⚠️
Critical Patches Issued for Microsoft Products, April 09, 2024
πŸ“‹
ICS Patch Tuesday: Siemens Addresses Palo Alto Networks Product Vulnerabilities
πŸ“‹
Cohesity partners with Intel to solve insider threat challenges
πŸ“‹
Microsoft Plugs Gaping Hole in Azure Kubernetes Service Confidential Containers
πŸ“‹
April’s Patch Tuesday Brings Record Number of Fixes
πŸ“’
Sprinto raises $20M to bring automation to security compliance management
πŸ“’
US Cyber Safety Review Board on the 2023 Microsoft Exchange Hack
πŸ“’
[Control systems] Siemens security advisory (AV24-187)
πŸ“’
[Control systems] Schneider Electric security advisory (AV24-186)
πŸ“’
HPE security advisory (AV24-188)
πŸ“’
SAP security advisory – April 2024 monthly rollup (AV24-189)
πŸ“’
Fortinet security advisory (AV24-190)
πŸ“’
Adobe security advisory (AV24-191)
πŸ”₯
Kaspersky Club - 55,971 breached accounts
πŸ”₯
Hackers Deploy Crypto Drainers on Thousands of WordPress Sites
πŸ”₯
Cyber Attack on Consulting Firm Exposes DOJ Data of 341,000 People
πŸ”₯
Targus Hacked: Attackers Gain Access to File Servers
πŸ”₯
Sophos Named Best MSP Solution by SE Labs
πŸ”₯
CVS Group Restoring Systems Impacted by Cyberattack
πŸ”₯
DOJ-Collected Information Exposed in Data Breach Affecting 340,000
πŸ”₯
Second Ransomware Group Extorting Change Healthcare
πŸ”₯
CL0P's Ransomware Rampage - Security Measures for 2024
πŸ”₯
Ransomware gang’s new extortion trick? Calling the front desk
πŸ”₯
OWASP Breach, Types of Prompt Injection, Device-Bound Sessions, ASVS & APIs - ASW #280
πŸ”₯
Microsoft Two-Step Phishing Campaign Targets LinkedIn Users
πŸ”₯
Tips for a Successful Cyber Resilience Program - Olusegun Opeyemi-Ajayi - CSP #169
πŸ”₯
Home Depot Confirms Data Breach Via Third Party Vendor
πŸ”₯
Firm Says Medicare Info Obtained From DOJ Breached in Attack
πŸ•΅οΈ
ISC Stormcast For Tuesday, April 9th, 2024 https://isc.sans.edu/podcastdetail/8930, (Tue, Apr 9th)
πŸ•΅οΈ
Exploring How Penetration Tests Are Classified – Pentesting Aspirant Guide 2024
πŸ•΅οΈ
StrikeReady Raises $12M to Build AI-Powered Security Command Center
πŸ•΅οΈ
All The Ways the Internet is Surveilling You
πŸ•΅οΈ
CyberheistNews Vol 14 #15 [Heads Up] Your Apple Users Are Now Targeted With New MFA Attacks
πŸ•΅οΈ
Entering the Next Chapter of SASE at InterSECt 2024
πŸ•΅οΈ
SAP’s April 2024 Updates Patch High-Severity Vulnerabilities
πŸ•΅οΈ
Ahoi Attacks – New Attack Breaking VMs With Malicious Interrupts
πŸ•΅οΈ
Hackers Targeting Human Rights Activists in Morocco and Western Sahara
πŸ•΅οΈ
Data Security Firm Cyera Raises $300 Million at $1.4 Billion Valuation
πŸ•΅οΈ
Streamline Threat Hunting: Shortemall Automates Short URL Analysis with a Click
πŸ•΅οΈ
What Cisco's Purchase of Splunk Means for Cybersecurity, AI
πŸ•΅οΈ
How to Use Cyber Threat Intelligence ? 4 TI Categories to Learn SOC/DIFR Team
πŸ•΅οΈ
Critical Improvements To The Seven Most Common Pieces of Cybersecurity Advice
πŸ•΅οΈ
New Phishing-as-a-Service (PhaaS) platform, 'Tycoon 2FA', TargetsΒ Microsoft 365 and Gmail Accounts
πŸ•΅οΈ
Ukrainian security service’s cyber chief suspended following media investigation
πŸ•΅οΈ
US Bipartisan Privacy Bill Contains Cybersecurity Mandates
πŸ•΅οΈ
Cyera Gets $300M at $1.4B Valuation to Fuel Safe AI Adoption
πŸ•΅οΈ
Why security orchestration, automation and response (SOAR) is fundamental to a security platform
🌐
Attackers Using Obfuscation Tools to Deliver Multi-Stage Malware via Invoice Phishing
🌐
ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins
🌐
US Health Deptarment Warns Hospitals of Hackers Targeting IT Help Desks
🌐
10-Year-Old 'RUBYCARP' Romanian Hacker Group Surfaces with Botnet
🌐
Smoke and (screen) mirrors: A strange signed backdoor
πŸ“‘
Automating Pikabot’s String Deobfuscation
πŸ“‘
Cybercriminal Adoption of Browser Fingerprinting
πŸ“‘
AI data security startup Cyera confirms $300M raise at a $1.4B valuation
πŸ“‘
Google injects generative AI into its cloud security tools
πŸ“‘
Chrome Enterprise goes Premium with new security and management features
πŸ“‘
Phishing Deception - Suspended Domains Reveal Malicious Payload for Latin American Region
πŸ“‘
X adds support for passkeys globally on iOS
πŸ“‘
CISO Conversations: Nick McKenzie (Bugcrowd) And Chris Evans (HackerOne)
πŸ“‘
US Insurers Use Drone Photos To Deny Home Insurance Policies
πŸ“‘
How to verify the authenticity and origin of photos and videos | Kaspersky official blog
πŸ“‘
Over 90,000 LG Smart TVs may be exposed to remote attacks
πŸ“‘
New SharePoint flaws help hackers evade detection when stealing files
πŸ“‘
Evolving Threats Facing Robotic and Other Medical Gear
KEV
πŸ“‘
Windows 11 KB5036893 update released with 29 changes, Moment 5 features
πŸ“‘
Microsoft employees exposed internal passwords in security lapse
πŸ“‘
Windows 10 KB5036892 update released with 23 new fixes, changes
πŸ“‘
Employees Are 'Quiet Quitting' - What Can Employers Do?
πŸ“‘
Why Claroty Is Considering Going Public at a $3.5B Valuation
πŸ“‘
Webinar | Enhancing Security for Government Agencies & Educational Institutions with Advanced MDR Strategies