111Articles
8Categories
2024-04-12Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-3400 Palo Alto Networks PAN-OS Command Injection Vulnerability These types of vulnerabilities are frequent attack vectors for malicious c…
KEV
🚨
Palo Alto Networks Releases Guidance for Vulnerability in PAN-OS, CVE-2024-3400Palo Alto Networks has released workaround guidance for a command injection vulnerability (CVE-2024-3400) affecting PAN-OS versions 10.2, 11.0, and 11.1. Palo Alto Networks has reported active exploitation of this vulnerability in the wild.  CISA encourages users and adminis…
KEV
🚨
Attackers exploit critical zero-day flaw in Palo Alto Networks firewallsNetwork security vendor Palo Alto Networks released mitigation instructions for an actively exploited vulnerability in PAN-OS, the software that powers its next-generation firewall (NGFW) products. The company is still working on developing software patches. The vulnerability, tr…
KEV
🐛
Zero-Day Alert: Critical Palo Alto Networks PAN-OS Flaw Under Active Attack
KEV
🐛
Palo Alto Networks Fixed Multiple DoS Bugs in its Firewalls
🐛
Exploitation of Unpatched D-Link NAS Device Vulnerabilities Soars
🐛
Microsoft Fixed Two Zero-Day Flaws Exploited in Malware Attacks
🐛
Citrix Releases Security Updates for XenServer and Citrix Hypervisor
🐛
Alert! Palo Alto RCE Zero-day Vulnerability Actively Exploited in the Wild
KEV
🐛
CVE 10.0 vulnerability in PAN-OS
🐛
Palo Alto Networks warns of zero-day in VPN product
KEV
🐛
Tool finds new ways to exploit Spectre holes in Intel CPUs
🐛
CVE-2024-3400 exploited: Unit 42, Volexity share more details about the attacks - Help Net Security
🐛
Chromium: CVE-2024-3157 Out of bounds write in Compositing
🐛
Chromium: CVE-2024-3515 Use after free in Dawn
🐛
Chromium: CVE-2024-3516 Heap buffer overflow in ANGLE
⚠️
ISC2 study pegs average US cybersecurity salary at $147K, up from $119K in 2021
⚠️
How Exposure Management Elevates Cyber Resilience
⚠️
New Technique Detected in an Open Source Supply Chain Attack
⚠️
Apple Warns of 'Mercenary Attack' on iPhones. What You Should Know
⚠️
Palo Alto Networks Warns of Exploited Firewall Vulnerability
⚠️
‘BatBadBut’ Command Injection Vulnerability Affects Multiple Programming Languages
⚠️
Palo Alto Networks warns of PAN-OS firewall zero-day used in attacks
KEV
⚠️
6-year-old Lighttpd Flaw Impacts Intel And Lenovo Servers
⚠️
Apple Boosts Spyware Alerts For Mercenary Attacks
⚠️
CISA opens its malware analysis and threat hunting tool for public use
⚠️
Lessons from XZ Utils: Achieving a More Sustainable Open Source Ecosystem
⚠️
In Other News: Moscow Sewage Hack, Women in Cybersecurity Report, Dam Security Concerns
⚠️
Juniper Releases Security Bulletin for Multiple Juniper Products
⚠️
How Ukraine’s cyber police fights back against Russia’s hackers
⚠️
Palo Alto Networks Warns Of Exploited Firewall Vulnerability
⚠️
Wiz Acquires Gem Security, Pushes Security Tools Consolidation
⚠️
How a 9.8 critical security vulnerability in ZeroMQ was found (with mostly pure luck)
⚠️
Cybersecurity Decluttered: A Journey to Consolidation
⚠️
CISA orders US government agencies to check email systems for signs of Russian compromise
⚠️
Current and former Polish officials face probe of alleged spyware abuse
⚠️
Apple notifies users in 92 countries about mercenary spyware attacks
⚠️
Telegram fixes Windows app zero-day caused by file extension typo
⚠️
Cyber Security Today, Week in Review for week ending Friday, April 12, 2024
⚠️
AL24-005 - Vulnerability impacting PAN-OS GlobalProtect Gateway
⚠️
Several vulnerabilities in LG WebOS. Chained, lead to RCE.
⚠️
State-Sponsored Hackers Exploit Zero-Day to Backdoor Palo Alto Networks Firewalls
⚠️
A Vulnerability in PAN-OS Could Allow for Arbitrary Code Execution
⚠️
Friday Squid Blogging: The Awfulness of Squid Fishing Boats
⚠️
Telegram fixes Windows app zero-day used to launch Python scripts
⚠️
US Cyber Command Expanded 'Hunt Forward' Operations in 2023
⚠️
UK Markets Authority Warns of AI Market Capture by Big Tech
⚠️
iPhone Users in 92 Countries Targeted by Mercenary Spyware Attacks
📢
U.S. Federal Agencies Ordered to Hunt for Signs of Microsoft Breach and Mitigate Risks
📢
Midnight Blizzard’s Microsoft Corporate Email Hack Threatens Federal Agencies: CISA Warns
📢
The Cyber Defense Matrix (CDM) - Wim Remes - 36 minutes
📢
IT Pros Targeted with Malicious Google Ads for PuTTY, FileZilla
📢
Iranian MuddyWater Hackers Adopt New C2 Tool 'DarkBeatC2' in Latest Campaign
📢
Sisence Data Breach, CISA Urges To Reset Login Credentials
📢
CISA Alerts Organizations Regarding Cyber Incident at Global Data Analytics Company
📢
Palo Alto Networks security advisory (AV24-198)
📢
American Privacy Rights Bill: Implications for Health Sector
📢
Combadges, SISENSE, Microsoft, CISA, Lastpass, Palo Alto, Broadband, Aaran and More - SWN #377
📢
CISA Briefs World Travel Organization Expedia with Advice on Security
📢
CISA Partners with State’s K-12 Schools Fighting Cyberattacks to Keep Kids Learning
📢
CISA's Malware Analysis Platform Could Foster Better Threat Intel
🔥
Building a Live SIFT USB with Persistence, (Fri, Apr 12th)
🔥
Cyber Attack Surge by 28%:Education Sector at High Risk
🔥
Hackers Employ Deepfake Technology To Impersonate as LastPass CEO
🔥
US think tank Heritage Foundation hit by cyberattack
🔥
Cyber Attacks Could Cause Global Bank Runs
🔥
UK Councils Under Cyber Attack: The Urgent Need for a Culture of Cybersecurity and Resilience
🔥
Intel and Lenovo Servers Impacted by 6-Year-Old BMC Flaw
🔥
Roku Says More Than 500,000 Accounts Impacted In Cyberattack
🔥
LockBit Copycat DarkVault Spurs Rebranding Rumor
🔥
French Issue Alerte Rouge After Local Govs Knocked Offline By Cyberattack
🔥
More Legal Acrimony For Truth Social, As Executive Says He Was Hacked
🔥
Roku warns 576,000 accounts hacked in new credential stuffing attacks
🔥
Popular Rust Crate liblzma-sys Compromised with XZ Utils Backdoor Files
🔥
Roku says 576,000 user accounts hacked after second security incident
🔥
ISMG Editors: Unpacking the Change Healthcare Attack Saga
🔥
State-Sponsored Disinformation Campaigns Targeting Africa Driving Instability And Violence
🔥
Roku says more than 500,000 accounts impacted in cyberattack
🔥
PE Firm Accuses Synopsys of Breaching Exclusivity Agreement
🔥
Giant Tiger - 2,842,669 breached accounts
🕵️
ISC Stormcast For Friday, April 12th, 2024 https://isc.sans.edu/podcastdetail/8936, (Fri, Apr 12th)
🕵️
Análisis de Malware en América Latina - 8dot8 - SPANISH & ENGLISH
🕵️
Cyber Security Today, April 12, 2024 - A warning to Sisense customers, a new tactic for spreading the Raspberry Robin worm, and more
🕵️
Cyberespionage Group Earth Hundun's Continuous Refinement of Waterbear and Deuterbear
🕵️
LastPass Employee Targeted With Deepfake Calls
🕵️
Cyberespionage Group Earth Hundun's Continuous Refinement of Waterbear and Deuterbear
🕵️
IT pros targeted with malicious Google ads for PuTTY, FileZilla - Help Net Security
🕵️
DuckDuckGo Launches Privacy Pro: 3-in-1 service With VPN
🕵️
Smuggling Gold by Disguising it as Machine Parts
🕵️
Expired Redis Service Abused to Use Metasploit Meterpreter Maliciously
🕵️
Microsoft left internal passwords exposed in latest security blunder
🕵️
Threat Actors Manipulate GitHub Search to Deliver Malware
🕵️
House Will Try Again on Reauthorization of US Spy Program After Republican Upheaval
🕵️
DarkBeatC2: The Latest MuddyWater Attack Framework
🕵️
US-China Competition to Field Military Drone Swarms Could Fuel Global Arms Race
🕵️
US Government On High Alert As Russian Hackers Steal Critical Correspondence From Microsoft
🕵️
CCC Winterkongress 2024 - GERMAN and ENGLISH language
🕵️
RubyCarp: Insights Into the Longevity of a Romanian Cybercriminal Gang
🕵️
U.S. Department of Health Alert: Hackers are Targeting IT Help Desks at Healthcare Organizations
🕵️
Cloned Voice Tech Is Coming for Bank Accounts
🕵️
eXotic Visit includes XploitSPY malware – Week in security with Tony Anscombe
🌐
Sneaky Credit Card Skimmer Disguised as Harmless Facebook Tracker
🌐
Credit Card Skimmer Hidden in Fake Facebook Pixel Tracker
🌐
Importance of Scanning Files on Uploader Applications
📡
Code Keepers: Mastering Non-Human Identity Management
📡
Former AT&T customers get $6.3 million in data throttling refunds
📡
Mitigating the risks of residential proxies | Kaspersky official blog
📡
Security engineer jailed for 3 years for $12M crypto hacks
📡
Ex-Amazon engineer gets 3 years for hacking crypto exchanges
📡
FBI warns of massive wave of road toll SMS phishing attacks
📡
Microsoft now testing app ads in Windows 11's Start menu