102Articles
8Categories
2024-04-30Date
๐Ÿšจ
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-29988 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability These types of vulnerabilities are frequent attack vectors for mโ€ฆ
KEV
๐Ÿ›
Most attacks affecting SMBs target five older vulnerabilities
๐Ÿ›
Vulnerability in R Programming Language Could Fuel Supply Chain Attacks
๐Ÿ›
Delta Electronics CNCSoft-G2 DOPSoft DPAX
๐Ÿ›
Another Day, Another NAS: Attacks against Zyxel NAS326 devices CVE-2023-4473, CVE-2023-4474, (Tue, Apr 30th)
โš ๏ธ
MovieBoxPro - 6,009,014 breached accounts
โš ๏ธ
Close the barn door now! Avoid the risk of not monitoring retained access before itโ€™s a problem
โš ๏ธ
Cyber breach misinformation creates a haze of uncertainty
โš ๏ธ
Major privacy question (linux distro)
โš ๏ธ
Zloader Learns Old Tricks
โš ๏ธ
RSAC Fireside Chat: Secure, flexible web browsers finally available, thanks to open-source code
โš ๏ธ
Safari Vulnerability Exposes EU iOS Users to Malicious Marketplaces
โš ๏ธ
UnitedHealth hackers exploited Citrix vulnerabilities, CEO to testify
โš ๏ธ
WhatsApp in India
โš ๏ธ
UK Enacts IoT Cybersecurity Law
โš ๏ธ
Researchers Unveil Novel Attack Methods Targeting Intelโ€™s Conditional Branch Predictor
โš ๏ธ
Prompt Fuzzer: Open-Source Tool for Strengthening GenAI Apps
โš ๏ธ
Millions of Malicious 'Imageless' Containers Planted on Docker Hub Over 5 Years
โš ๏ธ
Microsoft Releases New-Open Source Tool for OT Security
โš ๏ธ
Securiti adds distributed LLM firewalls to secure genAI applications
โš ๏ธ
CISA Releases Three Industrial Control Systems Advisories
โš ๏ธ
Vulnerability In R Programming Language Could Fuel Supply Chain Attacks
โš ๏ธ
Chinese threat actor engaged in multi-year DNS resolver probing effort
โš ๏ธ
GUEST ESSAY: Recalibrating critical infrastructure security in the wake of evolving threats
โš ๏ธ
Critical Vulnerabilities in Judge0 Lead to Sandbox Escape, Host Takeover
โš ๏ธ
Google now pays up to $450,000 for RCE bugs in some Android apps
โš ๏ธ
R language flaw allows code execution via RDS/RDX files
โš ๏ธ
Patched Deserialization Flaw in Siemens Product Allows RCE
โš ๏ธ
How Personal Branding Can Elevate Your Tech Career
๐Ÿ“ข
New U.K. Law Bans Default Passwords on Smart Devices Starting April 2024
๐Ÿ“ข
Finnish Hacker Kivimaki Found Guilty in Vastaamo Hack
๐Ÿ“ข
Defending Infrastructure, Securing Systems Key To CISA's New AI Guidelines
๐Ÿ“ข
Apptega Raises $15 Million for Cybersecurity Compliance Platform
๐Ÿ“ข
FBI Warns of Verification Scams Targeting Dating Site Users
๐Ÿ“ข
AI, Okta, Chrome, Quantum, Kaiser Permanente, FTC, FCC, NCSC, Josh Marpet, and more. - SWN #382
๐Ÿ“ข
SonicWall security advisory (AV24-233)
๐Ÿ“ข
HPE security advisory (AV24-232)
๐Ÿ“ข
DHS: AI-Enhanced Nuclear and Chemical Threats Are Risk to US
๐Ÿ“ข
Opening Statement by CISA Director Jen Easterly
๐Ÿ“ข
Detecting browser data theft using Windows Event Logs
๐Ÿ”ฅ
An Empty S3 Bucket Can Make Your AWS Bills Explode
๐Ÿ”ฅ
Security Flaws in IRS Systems Pose Risk to Financial Statements, GAO Says
๐Ÿ”ฅ
Kaiser Permanente Cyber Attack Exposes 13.4 Million Users Data
๐Ÿ”ฅ
The State of Ransomware 2024
๐Ÿ”ฅ
Threat Actor Claims Selling of Dell Database with 49M User Records
๐Ÿ”ฅ
AI cybersecurity solutions detect ransomware in under 60 seconds
๐Ÿ”ฅ
Change Healthcare hacked using stolen Citrix account with no MFA
๐Ÿ”ฅ
New Wpeeper Android malware hides behind hacked WordPress sites
๐Ÿ”ฅ
Philadelphia Inquirer: Data of over 25,000ย people stolen in 2023 breach
๐Ÿ•ต๏ธ
Tech CEOs Altman, Nadella, Pichai and Others Join Government AI Safety Board Led by DHSโ€™ Mayorkas
๐Ÿ•ต๏ธ
ISC Stormcast For Tuesday, April 30th, 2024 https://isc.sans.edu/podcastdetail/8960, (Tue, Apr 30th)
๐Ÿ•ต๏ธ
Meet the New Exclusive AI Malware Analyst: Gemini 1.5 Pro
๐Ÿ•ต๏ธ
Darkgate Malware Leveraging Autohotkey Following Teams
๐Ÿ•ต๏ธ
New Android Malware Mimic As Social Media Apps Steals Sensitive Data
๐Ÿ•ต๏ธ
LightSpy Malware Actively Targeting MacOS Devices
๐Ÿ•ต๏ธ
Google Blocks 2.28M Malicious Apps Entering The Play Store
๐Ÿ•ต๏ธ
UserSec, NoName057(16), and Cyber Army of Russia Target UK's Economic Sector
๐Ÿ•ต๏ธ
FCC Fines US Cell Carriers $200M for Selling Location Data
๐Ÿ•ต๏ธ
Agent Tesla and Taskun Malware Targeting US Education and Govt Entities
๐Ÿ•ต๏ธ
Why Using Microsoft Copilot Could Amplify Existing Data Quality and Privacy Issues
๐Ÿ•ต๏ธ
CyberheistNews Vol 14 #18 [Wake Up Call] A Fresh Nespresso Domain Hijack Brews an MFA Phishing Scheme
๐Ÿ•ต๏ธ
Air Gapped! The Myth of Securing OT - Thomas Johnson - CSP #172
๐Ÿ•ต๏ธ
SafeBase Scores $33M Series B Investment
๐Ÿ•ต๏ธ
KnowBe4 to Acquire Egress
๐Ÿ•ต๏ธ
Redline Malware Using Lua Bytecode to Challenge the SOC/TI Team to Detect
๐Ÿ•ต๏ธ
FCC Fines Wireless Carriers for Sharing User Locations Without Consent
๐Ÿ•ต๏ธ
New Payment Rails to Rely on RFP for More Security
๐Ÿ•ต๏ธ
Random Problems, Protecting Packages, and Vulns in Designs, Defaults & Data Leaks - ASW #283
๐Ÿ•ต๏ธ
Why Companies Continue to Struggle with Supply Chain Security - Melinda Marks - ASW #283
๐Ÿ•ต๏ธ
Finnish Hacker Gets Prison for Accessing Thousands of Psychotherapy Records and Demanding Ransoms
๐Ÿ•ต๏ธ
Docker Hub Users Targeted With Imageless, Malicious Repositories
๐Ÿ•ต๏ธ
Island Secures $175M Investment as Enterprise Browser Startups Defy Tech Giants
๐Ÿ•ต๏ธ
Chinese Hackers Have Been Probing DNS Networks Globally for Years: Report
๐Ÿ•ต๏ธ
Phishing Failures: How Not to Phish Your Users
๐Ÿ•ต๏ธ
How New College Graduates Can Avoid Increasingly Personalized Job Scams
๐Ÿ•ต๏ธ
News alert: Cybersixgill unveils โ€˜Third-Party Intelligenceโ€™ to deliver vendor-specific threat intel
๐Ÿ•ต๏ธ
UnitedHealth CEO: Paying Ransom Was 'Hardest Decision' Ever
๐Ÿ•ต๏ธ
Island Gets $175M Series D Funding, Doubles Valuation to $3B
๐Ÿ•ต๏ธ
The Hidden Benefits of Digital Minimalism
๐ŸŒ
The Darkgate Menace: Leveraging Autohotkey & Attempt to Evade SmartScreen
๐ŸŒ
Google Rejected 2.28 Million Risky Android Apps From Play Store in 2023
๐ŸŒ
U.S. Government Releases New AI Security Guidelines for Critical Infrastructure
๐ŸŒ
Millions of Docker repos found pushing malware, phishing sites
๐ŸŒ
New Latrodectus malware attacks use Microsoft, Cloudflare themes
๐Ÿ“ก
Thoma Bravo to take UK cybersecurity company Darktrace private in $5B deal
๐Ÿ“ก
FCC Imposes $200 Million in Fines on Four US Carriers
๐Ÿ“ก
Muddling Meerkat Hackers Manipulate DNS Using Chinaโ€™s Great Firewall
๐Ÿ“ก
Change Healthcare hackers broke in using stolen credentials โ€” and no MFA, says UHG CEO
๐Ÿ“ก
SafeBase taps AI to automate software security reviews
๐Ÿ“ก
Man Who Mass-Extorted Psychotherapy Patients Gets Six Years
๐Ÿ“ก
Researchers Discover Coordinated Attacks on Docker Hub to Plant Millions of Malicious Repositories
๐Ÿ“ก
Emulating RH850 architecture with Unicorn Engine
๐Ÿ“ก
US fines telcos $200M for sharing customer location data without consent
๐Ÿ“ก
Apple's Incredibly Private Safari Is Not So Private In Europe
๐Ÿ“ก
Hacker Jailed For Blackmailing Therapy Patients
๐Ÿ“ก
UK Outlaws Awful Default Passwords On Connected Devices
๐Ÿ“ก
FCC Fines Wireless Carriers For Sharing User Locations Without Consent
๐Ÿ“ก
Application allow list (ITSAP.10.095)
๐Ÿ“ก
Sophos named a Leader in the 2024 IDC MarketScape for Worldwide Managed Detection and Response (MDR)
๐Ÿ“ก
MDR: Unlocking the power of enterprise-grade security for businesses of all sizes
๐Ÿ“ก
Sensor Intel Series: Top CVEs in March 2024
๐Ÿ“ก
Sensor Intel Series: Top CVEs in March 2024