106Articles
9Categories
2024-04-23Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2022-38028 Microsoft Windows Print Spooler Privilege Escalation Vulnerability These types of vulnerabilities are frequent attack vectors for m…
KEV
🐛
Critical Apache HugeGraph Flaw Let Attackers Execute Remote Code
🐛
Siemens Industrial Product Impacted by Exploited Palo Alto Firewall Vulnerability
🐛
Russian state-sponsored hacker used GooseEgg malware to steal Windows credentials
🐛
PoC Exploit Released For Critical Oracle VirtualBox Vulnerability
⚠️
Russia's APT28 Exploited Windows Print Spooler Flaw to Deploy 'GooseEgg' Malware
⚠️
Microsoft’s mea culpa moment: how it should face up to the CSRB’s critical report
⚠️
Critical Flaw with Popular API Portal Let Attackers Launch SSRF Attacks
⚠️
Top 10 physical security considerations for CISOs
⚠️
Hacker Offers Upto $300 To Mobile Networks Staff For Illegal SIM Swaps
⚠️
Cloud Console Cartographer: Open-Source Tool Helps Security Teams Transcribe Log Activity
⚠️
Police Chiefs Call for Solutions to Access Encrypted Data in Serious Crime Cases
⚠️
German Authorities Issue Arrest Warrants for Three Suspected Chinese Spies
⚠️
Nespresso Domain Serves Up Steamy Cup of Phish, No Cream or Sugar
⚠️
Webinar: Learn Proactive Supply Chain Threat Hunting Techniques
⚠️
Fraudsters Exploit Telegram’s Popularity for Toncoin Scam
⚠️
Tracing the Steps of Cyber Intruders: The Path of Lateral Movement
⚠️
Russian Cyberspies Deliver ‘GooseEgg’ Malware to Government Organizations
⚠️
Hackers hijack antivirus updates to drop GuptiMiner malware
⚠️
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
⚠️
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
⚠️
Apache Cordova App Harness Targeted in Dependency Confusion Attack
⚠️
CISA Releases Two Industrial Control Systems Advisories
⚠️
US imposes visa bans on 13 spyware makers and their families
⚠️
Phishing Campaign Exploits Nespresso Domain
⚠️
Sustainable Funding of Open Source Tools - Simon Bennetts, Mark Curphey - ASW #282
⚠️
XZ & Open Source, PuTTY's Private Keys, LeakyCLI, LLMs Writing Exploits - ASW #282
⚠️
Behavioral patterns of ransomware groups are changing - Help Net Security
⚠️
Authentication failure blamed for Change Healthcare ransomware attack
⚠️
Russian APT28 Group in New “GooseEgg” Hacking Campaign
⚠️
Vulnerability Exploitation on the Rise as Attackers Ditch Phishing
⚠️
The Assumed Breach conundrum
⚠️
Russian Hackers Exploiting Windows Print Spooler Vuln
⚠️
Uncovering potential threats to your web application by leveraging security reports
📋
Microsoft releases Exchange hotfixes for security update issues
📋
Microsoft pulls fix for Outlook bug behind ICS security alerts
📢
Uncertainty is the Most Common Driver of Noncompliance
📢
Microsoft and Security Incentives
📢
Dell security advisory (AV24-220)
📢
CISA to Issue List of Software Products Critical to Agency Security by End of September
🔥
Weekly Update 396
🔥
Cyber Insurance Gaps Stick Firms With Millions in Uncovered Losses
🔥
Researchers Warn Windows Defender Attack can Delete Databases
🔥
UnitedHealth Pay Ransom After Change Healthcare Cyberattack
🔥
Volkswagen Group’s Systems Hacked: 19,000+ Documents Stolen
🔥
Feds Issue Guide for Change Health Breach Reporting Duties
🔥
Unmasking the True Cost of Cyberattacks: Beyond Ransom and Recovery
🔥
Ransomware Gang Leaks Data Allegedly Stolen From Government Contractor
🔥
Behavioral Patterns of Ransomware Groups are Changing
🔥
UnitedHealth Group Previews Massive Change Healthcare Breach
🔥
Nespresso Domain Serves Up Steamy Cup of Phish, No Cream or Sugar
🔥
UnitedHealth Says Patient Data Exposed in Change Healthcare Cyberattack
🔥
UnitedHealth confirms it paid ransomware gang to stop data leak
🔥
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
🔥
Global Optics Provider Hit with Ransomware Attack and a $10M Ransom
🔥
DPRK hacking groups breach South Korean defense contractors
🔥
US govt sanctions Iranians linked to government cyberattacks
🔥
This Website is Selling Billions of Private Messages of Discord Users
🔥
$10 Million Bounty on Iranian Hackers for Cyber Attacks on US Gov, Defense Contractors
🔥
Ukrainian Energy Sector Under Cyber Siege by Russian Hackers
🔥
Change Health Attack: Details Emerge; Breach Will Top Record
🔥
New Microsoft Incident Response guide helps simplify cyberthreat investigations
🕵️
ISC Stormcast For Tuesday, April 23rd, 2024 https://isc.sans.edu/podcastdetail/8950, (Tue, Apr 23rd)
🕵️
Europol calls for Tech Giants to Get Lawful Access To end-to-end Encryption
🕵️
GitHub Comments Abused to Push Malware via Microsoft Repository URLs
🕵️
Russian Sandworm Hackers Targeted 20 Critical Organizations in Ukraine
🕵️
Microsoft DRM Hack Could Allow Movie Downloads From Popular Streaming Services
🕵️
Microsoft Warns of North Korean Hackers Turning to AI-Fueled Cyber Espionage
🕵️
U.S. to Impose Visa Restrictions on 13 Individuals Involved in Commercial Spyware Operations
🕵️
Androxgh0st Malware Compromises Servers Worldwide for Botnet Attack
🕵️
ToddyCat APT Is Stealing Data on 'Industrial Scale'
🕵️
State Hackers' New Frontier: Network Edge Devices
🕵️
Malvertising: Fake Popular Software Ads Deliver New MadMxShell Backdoor
🕵️
CyberheistNews Vol 14 #17 [HEADS UP] LastPass Warns of a 'CEO' Deepfake Phishing Attempt
🕵️
Passwords, passkeys and familiarity bias
🕵️
The Battle Continues: Mandiant Report Shows Improved Detection But Persistent Adversarial Success
🕵️
Environmental Sustainable Training: KnowBe4's Commitment to a Greener Earth
🕵️
USPS Surges to Take Top Spot as Most Impersonated Brand in Phishing Attacks
🕵️
The Challenges of Managing Security in an IT/OT Environment - John Germain - CSP #171
🕵️
Level Up Your Users’ Cybersecurity Skills with 'The Inside Man: New Recruits’
🕵️
GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining
🕵️
Spain Reopens a Probe Into a Pegasus Spyware Case After a French Request to Work Together
🕵️
US Presures Iran Over Phishing Campaign Against Feds
🕵️
Robofly, CRUSHFTP, Github, Palo Alto, MITRE, Fancy Bear, Deepfakes, Aaran Leyland... - SWN #380
🕵️
CoralRaider attacks use CDN cache to push info-stealer malware
🕵️
US Pressures Iran Over Phishing Campaign Against Feds
🕵️
CyberRisk Alliance Live from RSAC 2024 Day 1
🕵️
CyberRisk Alliance Live from RSAC 2024 Day 2
🕵️
CyberRisk Alliance Live from RSA Conference 2024 - Day 3
🕵️
CyberRisk Alliance Live from RSA Conference 2024 - Day 4
🌐
Sharp Stealer: New Info-stealer Malware Targets Gamers, Crypto Enthusiasts
🌐
U.S. Imposes Visa Restrictions on 13 Linked to Commercial Spyware Misuse
🌐
Majority of Businesses Worldwide are Implementing Zero Trust, Gartner Finds
🌐
GitLab Affected by GitHub-Style CDN Flaw Allowing Malware Hosting
🌐
HHS Beefs Up Privacy Protection for Reproductive Health Info
📡
Content filtering in KSMG 2.1 | Kaspersky official blog
📡
Struts "devmode": Still a problem ten years later?, (Tue, Apr 23rd)
📡
Resilient Together with Priority Telecommunications Services (PTS)
📡
Authorities Investigate LabHost Users After Phishing Service Shutdown
📡
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
📡
Over A Million Neighbourhood Watch Members Exposed
📡
The Future is Now: Tech Trends Driving App Dev—Gen AI, Low-Code and More
📡
Building Security for MSPs: Cisco's Blueprint for Success
📡
How technology drives progress – A Q&A with Nobel laureate Michel Mayor
📡
The vision behind Starmus – A Q&A with the festival’s co-founder Garik Israelian
📡
Secure by Design Turns 1!