122Articles
9Categories
2024-04-11Date
🚨
OWASP Top 10 OSS Risks: A guide to better open source securityCalls for a critical look at how open-source software (OSS) is secured and used have been increasing after a number of recent scares exposed vulnerabilities and risks, in particular the XZ Utils incident that revealed a backdoor inserted into a widely used OSS for compression and…
KEV
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-3272 D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability CVE-2024-3273 D-Link Multiple NAS Devices Command Injectio…
KEV
πŸ›
Fortinet Rolls Out Critical Security Patches for FortiClientLinux Vulnerability
πŸ›
Fortinet Fixed a Critical RCE Bug in FortiClientLinux
πŸ›
Rust Addresses Critical Vulnerability on Windows
πŸ›
Rust addresses critical vulnerability on Windows
πŸ›
CVE-2022-0001 Intel: CVE-2022-0001 Branch History Injection
πŸ›
CVE-2024-21322 Microsoft Defender for IoT Remote Code Execution Vulnerability
πŸ›
CVE-2024-21323 Microsoft Defender for IoT Remote Code Execution Vulnerability
πŸ›
CVE-2024-21324 Microsoft Defender for IoT Elevation of Privilege Vulnerability
πŸ›
CVE-2024-26234 Proxy Driver Spoofing Vulnerability
πŸ›
CVE-2024-29053 Microsoft Defender for IoT Remote Code Execution Vulnerability
πŸ›
CVE-2024-29055 Microsoft Defender for IoT Elevation of Privilege Vulnerability
πŸ›
CVE-2024-29054 Microsoft Defender for IoT Elevation of Privilege Vulnerability
⚠️
Apple alerts users in 92 nations to mercenary attacks in new warning
⚠️
Apple Expands Spyware Alert System to Warn Users of Mercenary Attacks
⚠️
Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
⚠️
Fortra For Windows Vulnerability Let Attackers Escalate Privilege
⚠️
Hackers Manipulate GitHub Search To Deliver Clipboard-Hijacking Malware
⚠️
Client-Side Exploitation: Poisoning WebDAV+URL+LNK to Deliver Malicious Payloads
⚠️
Backdoor in XZ Utils That Almost Happened
⚠️
New Technique Detected in an Open Source Supply Chain Attack
⚠️
Cagey Phishing Attack Drops Multiple RATs to Steal Data
⚠️
US Cyber Force Assisted Foreign Governments 22 Times in 2023
⚠️
Fortinet Patches FortiClientLinux Critical RCE Vulnerability
⚠️
New Spectre v2 Attack Impacts Linux Systems Running on Intel CPUs
⚠️
Apple: Mercenary spyware attacks target iPhone users in 92 countries
⚠️
Cryptohack Roundup: Google Sues Alleged Crypto App Crooks
⚠️
Data Access Platform PVML Launches With $8 Million in Funding
⚠️
CISA Releases Nine Industrial Control Systems Advisories
⚠️
DragonForce ransomware – what you need to know
⚠️
Intel and Lenovo servers impacted by 6-year-old BMC flaw
⚠️
Our Security of AI Papers and Blogs Explained
⚠️
Customers of Sisense data analytics service urged to change credentials
⚠️
Understanding KillNet and Recent Waves of DDoS Attacks - Michael Smith - ESW #357
⚠️
Technical Controls
⚠️
The AI-est news segment ever, now with even more AI! - ESW #357
πŸ“‹
Breach Roundup: Sisense Supply Chain Attack
πŸ“’
CISA Opens Its Internal Malware Analysis Tool for Public Use
πŸ“’
Water Facilities Compromised By Iranian Threat Actors
πŸ“’
Compromise of Sisense Customer Data
πŸ“’
Citrix security advisory (AV24-195)
πŸ“’
CISA investigates critical infrastructure breach after Sisense hack
πŸ“’
CISA says Sisense hack impacts critical infrastructure orgs
πŸ“’
Attack on data analytics company Sisense prompts alert from CISA
πŸ“’
Sisense Data Breach Triggers CISA Alert and Urgent Calls for Credential Resets
πŸ“’
CISA Issues Emergency Directive 24-02: Mitigating the Significant Risk from Nation-State Compromise of Microsoft Corporate Email System
πŸ“’
CISA Directs Federal Agencies to Immediately Mitigate Significant Risk From Russian State-Sponsored Cyber Threat
πŸ“’
CISA orders agencies impacted by Microsoft hack to mitigate risks
πŸ“’
Mitel security advisory (AV24-196)
πŸ“’
CISA Warns Russian Microsoft Hackers Targeted Federal Emails
πŸ“’
[Control systems] B&R security advisory (AV24-197)
πŸ“’
US says Russian hackers stole federal government emails during Microsoft cyberattack
πŸ“’
Why CISA is Warning CISOs About a Breach at Sisense
πŸ“’
Implementing Least-Privilege Administrative Models
πŸ“’
CISA makes its "Malware Next-Gen" analysis system publicly available
πŸ”₯
Cyber Espionage: Turla APT Hackers Attack European Organization With Backdoor
πŸ”₯
Wiz Buys Startup Gem Security for $350M to Spot Cloud Issues
πŸ”₯
IMF: Financial Firms Lost $12 Billion to Cyberattacks in Two Decades
πŸ”₯
NSA Updates Zero-Trust Advice to Reduce Attack Surfaces
πŸ”₯
Ransomware payouts hit all-time high, but that’s not the whole story
πŸ”₯
UK's Attitude to Security Spotlit by Government Figures
πŸ”₯
Ukrainian Hackers Launch Cyberattacks On Moscow Sewage System
πŸ”₯
TA547 Hackers Launching AI-Powered Cyber Attacks Targeting Organizations
πŸ”₯
Taxi Software Vendor Data Leak: 300K Passengers Data Exposed
πŸ”₯
East Central University suffers BlackSuit ransomware attack
πŸ”₯
When a breach goes from 25 documents to 1.3 terabytes…
πŸ”₯
How Red Team Exercises Increases Your Cyber Health
πŸ”₯
Optics giant Hoya hit with $10 million ransomware demand
πŸ”₯
Change Healthcare Attack 'Devastating' to Doc Practices
πŸ”₯
FBI Calls for Increased Funding to Counter Cyber Threats
πŸ”₯
Raspberry Robin Morphs, Now Spreads via Windows Script Files
πŸ•΅οΈ
ISC Stormcast For Thursday, April 11th, 2024 https://isc.sans.edu/podcastdetail/8934, (Thu, Apr 11th)
πŸ•΅οΈ
History of RSA Conference. Bruce Schneier. The First β€˜Exhibitor’ in 1994.
πŸ•΅οΈ
Evolution of Artificial Intelligence Systems and Ensuring Trustworthiness, (Thu, Apr 11th)
πŸ•΅οΈ
Cyberespionage Group Earth Hundun's Continuous Refinement of Waterbear and Deuterbear
πŸ•΅οΈ
Palo Alto Networks Patches Vulnerabilities Allowing Firewall Disruption
πŸ•΅οΈ
Google Cloud Unveils New AI-Powered Security Capabilities
πŸ•΅οΈ
Alethea Raises $20 Million for Disinformation Detection and Mitigation Solution
πŸ•΅οΈ
TA547 Phishing Attack Hits German Firms with Rhadamanthys Stealer
πŸ•΅οΈ
Conservative Revolt in the House Blocks Effort to Reauthorize a Key US Spy Tool
πŸ•΅οΈ
Google Pays Out $41,000 for Three Serious Chrome Vulnerabilities
πŸ•΅οΈ
Top Tax Scams of 2024 Your Organization Should Watch Out For
πŸ•΅οΈ
Malvertising Campaigns Surged in 2023
πŸ•΅οΈ
Rhadamanthys Malware Deployed By TA547 Against German Targets
πŸ•΅οΈ
Why Intelligence Sharing Is Vital to Building a Robust Collective Cyber Defense Program
πŸ•΅οΈ
News alert: Simbian launches with $10M to build autonomous, GenAI-powered security platform
πŸ•΅οΈ
Simbian Emerges From Stealth With $10 Million to Build Autonomous AI-Based Security Platform
πŸ•΅οΈ
Inside AWS’s Crusade Against IP Spoofing and DDoS Attacks
πŸ•΅οΈ
Knostic Emerges From Stealth With Enterprise Gen-AI Access Controls
πŸ•΅οΈ
Google Cloud and Palo Alto Networks Deliver Cloud-Native NGFW Service
πŸ•΅οΈ
Zscaler to Acquire Network Segmentation Tech Startup Airgap Networks
πŸ•΅οΈ
News alert: NTT all photonics network connects data centers in U.S., U.K. at very low latency
πŸ•΅οΈ
Digging Into Supply Chain Security - James McMurry - PSW #824
πŸ•΅οΈ
Yesterday, in DC, I was given theΒ Holland on the Hill Freddy Heineken Award
πŸ•΅οΈ
US Government on High Alert as Russian Hackers Steal Critical Correspondence From Microsoft
πŸ•΅οΈ
Why Is Your TV & NAS On The Internet? - PSW #824
πŸ•΅οΈ
How Microsoft discovers and mitigates evolving attacks against AI guardrails
πŸ•΅οΈ
Zscaler Buys Airgap Networks to Fuel Segmentation in IoT, OT
πŸ•΅οΈ
LastPass: Hackers targeted employee in failed deepfake CEO call
🌐
US government urges Sisense customers to reset credentials after hack
🌐
Rhadamanthys Malware Deployed By TA547 Against German Targets
🌐
Live Webinar | What’s Missing in Your Identity First Security Strategy: Lessons from an ISMG Survey
πŸ“‘
Analyzing CryptoJS Encrypted Phishing Attempt
πŸ“‘
Raspberry Robin Now Spreading Through Windows Script Files
πŸ“‘
AI Data Security Startup Cyera Confirms $300M Raise at a $1.4B Valuation
πŸ“‘
New Google Workspace Feature Prevents Sensitive Security Changes if Two Admins Don’t Approve Them
πŸ“‘
Python's PyPI Reveals Its Secrets
πŸ“‘
Simbian brings AI to existing security tools
πŸ“‘
DuckDuckGo launches a premium Privacy Pro VPN service
πŸ“‘
CISO Role Shows Significant Gains Amid Corporate Recognition of Cyber Risk
πŸ“‘
Meta will auto-blur nudity in Instagram DMs in latest teen safety step
πŸ“‘
Cyber Resilient 911 Symposium Blog Post
πŸ“‘
Google Cloud Unveils New AI-Powered Security Capabilities
πŸ“‘
Global Taxi Software Vendor Exposes Details Of Nearly 300K Across UK And Ireland
πŸ“‘
Apple Drops Term State-Sponsored Attacks From Its Threat Notification Policy
πŸ“‘
How to automate up to 90% of IT offboarding tasks
πŸ“‘
Python's PyPI Reveals Its Secrets
πŸ“‘
X Fixes URL Blunder That Could Enable Social Media Phishing
πŸ“‘
OpenTable is adding your first name to previously anonymous reviews
πŸ“‘
Fileless Attacks Prompt Intel’s Next-Gen Security
πŸ“‘
Beyond fun and games: Exploring privacy risks in children’s apps