82Articles
10Categories
2024-05-01Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2023-7028 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability These types of vulnerabilities are frequent attack vectors for ma…
KEV
🐛
Programming Language R Patches Code Execution Security Flaw
🐛
3 Windows vulnerabilities that may not be worth patching
🐛
CERT/CC Reports R Programming Language Vulnerability
🐛
“Dirty stream” attack: Discovering and mitigating a common vulnerability pattern in Android apps
⚠️
Cyber Security Today, May 1, 2024 - Data may have been stolen in London Drugs cyber attack, Congressional testimony today by UnitedHealth CEO on ransomware attack, and more
⚠️
Verizon Breach Report: Vulnerability Hacks Tripled in 2023
⚠️
Patched Deserialization Flaw in Siemens Product Allows RCE
⚠️
Millions of Malicious “Imageless” Docker Hub Repositories Drop Malware
⚠️
Attackers Leverage Sidecar Container Injection Technique To Stay Stealthy
⚠️
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks
⚠️
5 key takeways from Verizon’s 2024 Data Breach Investigations Report
⚠️
Take A Tour! NIST Cybersecurity Framework 2.0: Small Business Quick Start Guide
⚠️
Machine Identity Firm Venafi Readies for the 90-day Certificate Lifecycle
⚠️
Google Boosts Bug Bounty Payouts Tenfold in Mobile App Security Push
⚠️
CISA says GitLab account takeover bug is actively exploited in attacks
KEV
⚠️
CISA and Partners Release Fact Sheet on Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity
⚠️
Panda Restaurants discloses data breach after corporate systems hack
⚠️
NIST publishes new guides on AI risk for developers and CISOs
⚠️
GitLab Hackers Use 'Forgot Your Password' to Hijack Accounts
⚠️
Verizon DBIR: Cyber Defenders Are Facing Exploit Fatigue
⚠️
HPE Aruba Networking fixes four critical RCE flaws in ArubaOS
⚠️
Reading the Mandiant M-Trends 2024
📋
Microsoft says April Windows updates break VPN connections
📋
Microsoft: April Windows Server updates cause NTLM auth failures
📢
HPE security advisory (AV24-235)
📢
Google Chrome security advisory (AV24-234)
📢
CISA Unveils Guidelines for AI and Critical Infrastructure
📢
Cisco security advisory (AV24-236)
📢
Microsoft named overall leader in KuppingerCole Leadership Compass for ITDR
🔥
Belarus Secret Service Website Still Down After Hackers Claim the Breach
🔥
UnitedHealth CEO Says Hackers Lurked in Network for Nine Days Before Ransomware Strike
🔥
DHS asked to consider potentially 'devastating’ impact of hacks on rural water systems
🔥
NSA staffer who tried, failed to spy for Russia gets 21+ yrs
🔥
Qantas Airways Says App Showed Customers Each Other's Data
🔥
Wpeeper Android Trojan Uses Compromised WordPress Sites to Shield Command-and-Control Server
🔥
Android Malware Wpeeper Uses Compromised WordPress Sites to Hide C2 Servers
🔥
New Wpeeper Android Malware Hides Behind Hacked WordPress Sites
🔥
UnitedHealth CEO tells Senate all systems now have multi-factor authentication after hack
🔥
London Drugs Pharmacy Closes All Stores To Respond To Cyber Incident
🔥
French hospital CHC-SV refuses to pay LockBit extortion demand
🔥
United HealthCare CEO says ‘maybe a third’ of U.S. citizens were affected by recent hack
🔥
Lawmakers Grill UnitedHealth CEO on Change Healthcare Attack
🔥
AI's Offensive & Defensive Impacts
🔥
DropBox says hackers stole customer data, auth secrets from eSignature service
🕵️
AI Voice Scam
🕵️
Google Guide! How to Detect Browser Data Theft Using Windows Event Logs
🕵️
How to Utilize Azure Logs to Identify Threats: Insights From Microsoft
🕵️
RSAC Fireside Chat: APIs are wondrous connectors — and the wellspring of multiplying exposures
🕵️
CISO Conversations: Talking Cybersecurity With LinkedIn’s Geoff Belknap and Meta’s Guy Rosen
🕵️
ISC Stormcast For Wednesday, May 1st, 2024 https://isc.sans.edu/podcastdetail/8962, (Wed, May 1st)
🕵️
What are You Working on Wednesday
🕵️
DeepKeep Launches AI-Native Security Platform With $10 Million in Seed Funding
🕵️
Adobe Adds Content Credentials and Firefly to Bug Bounty Program
🕵️
Cuttlefish Malware Targets Routers, Harvests Cloud Authentication Data
🕵️
Navigating the Masquerade: Recognizing and Combating Impersonation Attacks
🕵️
[CASE STUDY] Healthcare Organization Hardens Employee Defenses Against Insidious Callback Phishing Attacks
🕵️
North Korean Threat Actors Target Software Developers With Phony Job Interviews
🕵️
Oasis Security Raises $35 Million to Tackle Non-Human Identity Management
🕵️
Traceable AI Raises $30 Million to Safeguard Cloud APIs
🕵️
Corelight Gets $150M to Expand Detection, Improve Workflows
🕵️
US and Allies Issue Cyber Alert on Threats to OT Systems
🕵️
A Web of Surveillance - Amnesty International Security Lab
🌐
New Latrodectus Malware Attacks Use Microsoft, Cloudflare Themes
🌐
ZLoader Malware Evolves with Anti-Analysis Trick from Zeus Banking Trojan
🌐
Linux Trojan - Xorddos with Filename eyshcjdmzg, (Mon, Apr 29th)
🌐
New Cuttlefish malware infects routers to monitor traffic for credentials
🌐
New Cuttlefish Malware Infects Routers to Monitor Traffic for Credential Theft
🌐
China's Attacks On Critical Infrastructure Tip Of Iceberg
🌐
US govt warns of pro-Russian hacktivists targeting water facilities
🎙️
Smashing Security podcast #370: The closed loop conundrum, default passwords, and Baby Reindeer
📡
Everyone's an Expert: How to Empower Your Employees for Cybersecurity Success
📡
Ex-NSA Employee Sentenced to 22 Years for Trying to Sell U.S. Secrets to Russia
📡
Qantas app exposed sensitive traveler details to random users
📡
Belgium’s Aikido lands $17M Series A for its ‘no BS’ security platform aimed at developers
📡
Correlating Cyber Investments With Business Outcomes
📡
Bitcoin Forensic Analysis Uncovers Money Laundering Clusters and Criminal Proceeds
📡
Qantas App Glitch Sees Boarding Passes Fly To Other Accounts
📡
Adobe Adds Content Credentials And Firefly To Bug Bounty Program
📡
Google Boosts Bug Bounty Payouts Tenfold In Mobile App Security Push
📡
Island Raises $175 Million at $3 Billion Valuation
📡
Joint guidance on defending operational technology operations against ongoing pro-Russia hacktivist activity