101Articles
9Categories
2024-05-02Date
🚨
CISA Adds GitLab Flaw to its Known Exploited Vulnerabilities CatalogThis flaw allows for an account takeover via Password Reset, enabling attackers to hijack accounts without any interaction. The affected versions range from 16.1 to 16.7, with GitLab releasing patches for versions 16.1.6 to 16.7.2.
KEV
🚨
CISA and FBI Release Secure by Design Alert to Urge Manufacturers to Eliminate Directory Traversal VulnerabilitiesToday, CISA and the Federal Bureau of Investigation (FBI) released a joint Secure by Design Alert, Eliminating Directory Traversal Vulnerabilities in Software . This Alert was crafted in response to recent well-publicized threat actor campaigns that exploited directory traversal …
KEV
🐛
CISA Warns of Active Exploitation of Severe GitLab Password Reset Vulnerability
KEV
🐛
New "Goldoon" Botnet Targets D-Link Routers With Decade-Old Flaw
🐛
New Goldoon Botnet Targeting D-Link Devices Using Decade-Old Flaw
🐛
ArubaOS Critical Vulnerability Let Attackers Execute Remote Code
🐛
Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796, (Thu, May 2nd)
🐛
Chromium: CVE-2024-4331 Use after free in Picture In Picture
🐛
Chromium: CVE-2024-4368 Use after free in Dawn
⚠️
Panda Restaurant Corporate Systems Hacked: Customer Data Exposed
⚠️
Biden delivers updated take on security for critical infrastructure
⚠️
Most interesting products to see at RSAC 2024
⚠️
RSAC Fireside Chat: How the open-source community hustled to identify LLM vulnerabilities
⚠️
CISA Warns of Active Exploitation of Severe GitLab Password Reset Vulnerability
⚠️
UnitedHealth hack may impact a third of US citizens: CEO testimony
⚠️
Dropbox Sign hack exposed user data, raises security concerns for e-sign industry
⚠️
When is One Vulnerability Scanner Not Enough?
⚠️
Dropbox Discloses Breach of Digital Signature Service Affecting All Users
⚠️
Vulnerability Exploits Triple as Initial Access Point for Breaches
⚠️
HPE Aruba Networking Fixes Four Critical RCE Flaws in ArubaOS
⚠️
1,400 GitLab Servers Impacted by Exploited Vulnerability
⚠️
Iranian hackers harvest credentials through advanced social engineering campaigns
⚠️
Is it possible to use zero knowledge proofs to verify journalism sources?
⚠️
1,400 GitLab Servers Impacted By Exploited Vulnerability
⚠️
Verizon DBIR 2024 Shows Surge in Vulnerability Exploitation, Confirmed Data Breaches
⚠️
VNC Is The Hacker’s New Remote Desktop Tool For Cyber Attacks
⚠️
Popular Android Apps Like Xiaomi, WPS Office Vulnerable to File Overwrite Flaw
⚠️
CISA Releases Three Industrial Control Systems Advisories
⚠️
Managed Service Provider Denies Being Source of Breach
⚠️
EU plan to force messaging apps to scan for CSAM risks millions of false positives, experts warn
⚠️
Police shuts down 12 fraud call centres, arrests 21 suspects
⚠️
Bitwarden launches new MFA Authenticator app for iOS, Android
⚠️
Breach Roundup: REvil Hacker Gets Nearly 14-Year Sentence
⚠️
Critical Flaw in R Language Poses Supply Chain Risk
📋
Attention all Windows Users! The Microsoft April Security Update Could Break Your VPN
📋
The UK Bans Default Passwords
📢
Russian Hackers Actively Attacking Small-scale Infrastructure Sectors
📢
NCSC’s New Mobile Risk Model Aimed at “High-Threat” Firms
📢
Japan’s Kishida Unveils a Framework for Global Regulation of Generative AI
📢
CISA urges software devs to weed out path traversal vulnerabilities
📢
Your Google Account allows you to create passkeys on your phone, computer and security keys
🔥
Change Healthcare Cyberattack Was Due to a Lack of Multifactor Authentication, UnitedHealth CEO says
🔥
REvil Ransomware Affiliate Sentenced for 13 Years in Prison
🔥
Dropbox Data Breach Impacts Customer Information
🔥
Threat Actors Attacking MS-SQL Servers to Deploy Ransomware
🔥
US Warns of Russian Hackers Targeting Operational Technology in Water Systems
🔥
Dropbox Sees Breach of Legally Binding E-Signature Service
🔥
AI is Creating a New Generation of Cyberattacks
🔥
LockBit, Black Basta, Play Dominate Ransomware in Q1 2024
🔥
2024 Data Breach Investigations Report: Most breaches involve a non-malicious human element
🔥
Ukrainian REvil Hacker Sentenced to 13 Years and Ordered to Pay $16 Million
🔥
Hackers Claiming Breach of UAE Government Servers
🔥
Hackers Compromised Dropbox eSignature Service
🔥
REvil Ransomware Scum Gets 14 Years, $16 Million Fine
🔥
REvil hacker behind Kaseya ransomware attack gets 13 years in prison
🔥
GoldDigger Malware Using Deep Fake AI Photos To Hijack Bank Accounts
🔥
Dropbox Sign e-signature service hacked | Kaspersky official blog
🔥
Ransomware Defense Startup Mimic Raises Hefty $27M Seed Round
🔥
Analysis Shows 2023 to be “Worst Year for Phishing on Record”
🔥
Rehab Hospital Chain Hack Affects 101,000; Facing 6 Lawsuits
🕵️
Deepfake of Principal’s Voice Is the Latest Case of AI Being Used for Harm
🕵️
ISC Stormcast For Thursday, May 2nd, 2024 https://isc.sans.edu/podcastdetail/8964, (Thu, May 2nd)
🕵️
USB Malware Attacks Targeting Industrial Systems Adapts LOL Tactics
🕵️
Iranian Hackers Impersonate Journalists in Social Engineering Campaign
🕵️
Digital fraud detection startup BioCatch hits $1.3B valuation as Permira buys majority stake
🕵️
Prisma SASE 3.0 — Securing Work Where It Happens
🕵️
The AWS S3 Denial of Wallet Amplification Attack
🕵️
Russian Hackers Target Industrial Systems in North America, Europe
🕵️
'Cuttlefish' Zero-Click Malware Steals Private Cloud Data
🕵️
News alert: LayerX Security raises $24M Series A funding for its ‘enterprise browser’ security platform
🕵️
Network Security Firm Corelight Raises $150 Million
🕵️
Cuttlefish 0-click Malware Hijacks Routers & Captures Data
🕵️
Kicking Off With Crypto - PSW #827
🕵️
LayerX Security Raises $24M for its Browser Security Platform, Enabling Employees to Work Securely From Any Browser, Anywhere
🕵️
Building the Right Vendor Ecosystem – a Guide to Making the Most of RSA Conference
🕵️
AI Security Startup Apex Emerges From Stealth With Funding From OpenAI CEO
🕵️
Startup Dealflow: New Investments at Resonance, RunReveal, StepSecurity, Insane Cyber
🕵️
Under the Digital Radar: Defending Against People’s Republic of China’s Nation-State Cyber Threats to America’s Small Businesses
🕵️
Cryptohack Roundup: Geosyn Fraud Lawsuit
🕵️
Veracode CEO on Mastering Application Security in the AI Era
🕵️
Is RogerLovesTaco$24 a Strong Password?
🕵️
Permira Takes Majority Stake in BioCatch at $1.3B Valuation
🕵️
Experts Say White House Memo Overlooks Space Cyber Risks
🕵️
Microsoft introduces passkeys for consumer accounts
🌐
New Cuttlefish Malware Hijacks Router Connections, Sniffs for Cloud Credentials
🌐
SafeBase Raises $33M in Series B to Accelerate Vision for Friction-Free Security Reviews
📡
Corelight Gets $150M to Expand Detection, Improve Workflows
📡
How Kaspersky stores passwords | Kaspersky official blog
📡
Cyber Startup Oasis Secures $35 Million Series A Extension, Doubles Valuation
📡
Deepfakes and AI-Driven Disinformation Threaten Polls
📡
Cybersecurity consultant arrested after allegedly extorting IT firm
📡
Hacker Free-For-All Fights For Control Of Home And Office Routers Everywhere
📡
Here's Your Chance To Own A Decommissioned US Government Supercomputer
📡
Microsoft won't fix Windows 0x80070643 errors, manual fix required
📡
Finnish Psychotherapy Center Cyber-Blackmailer Gets Six Years
📡
Hackers Target New NATO Member Sweden with Surge of DDoS Attacks
📡
Protecting Model Updates in Privacy-Preserving Federated Learning: Part Two
📡
Google expands passkey support to its Advanced Protection Program ahead of the US presidential election
📡
Microsoft warns of "Dirty Stream" attack impacting Android apps
📡
CEO who sold fake Cisco devices to US military gets 6 years in prison
📡
Adding insult to injury: crypto recovery scams