125Articles
10Categories
2024-05-15Date
🚨
Microsoft fixes three zero-day vulnerabilities, two actively exploitedMicrosoft released its monthly batch of security fixes on Tuesday, which included patches for three vulnerabilities that already had exploits available. Two of those vulnerabilities are being actively exploited, with one being used by multiple groups to deliver malware, including…
KEV
πŸ›
Backlogs at National Vulnerability Database prompt action from NIST and CISA
πŸ›
Experts Warn the NVD Backlog Is Reaching a Breaking Point
πŸ›
New Google Chrome Zero-day Exploited in the Wild, Patch Now!
KEV
πŸ›
(Cyber) Risk = Probability of Occurrence x Damage
πŸ›
Apple Fixes Safari WebKit Zero-Day Flaw Exploited at Pwn2Own
πŸ›
I/O 2024: What’s new in Android security and privacy
⚠️
No mayday call necessary for the year’s fifth Patch Tuesday
⚠️
Multiple Vulnerabilities in Siemens Ruggedcom Crossbow Could Allow for Arbitrary Code Execution
⚠️
Beware Of New Social Engineering Attack That Delivers Black Basta Ransomware
⚠️
MITRE EMB3D Improves Security for Embedded Devices
⚠️
Microsoft Patches 61 Flaws, Including Two Actively Exploited Zero-Days
KEV
⚠️
Clock is ticking for companies to prepare for EU NIS2 Directive
⚠️
PoC Exploit Released for RCE Zero-Day in D-Link EXO AX4800 Routers
⚠️
FortiOS & FortiProxy SSL-VPN Flaw Allows IP Spoofing via Malicious Packets
⚠️
BLint: Open-Source Tool to Check the Security Properties of Your Executables
⚠️
Microsoft Fixes Three Zero-Days in May Patch Tuesday
KEV
⚠️
QakBot Malware Exploiting Windows Zero-Day To Gain System Privileges
⚠️
VMware Fixed Zero-Day Flaws Demonstrated at Pwn2Own2024
⚠️
Ebury Botnet Compromised 400K Linux Servers for Crypto Theft and Financial Gain
⚠️
Zero-day alert! Apple security updates are out, including 0-day fixes for iOS 16 and macOS 13
⚠️
Dangerous Google Chrome Zero-Day Allows Sandbox Escape
⚠️
Log4Shell shows no sign of fading, spotted in 30% of CVE exploits
⚠️
Meet Hackbat: An Open-Source, More Powerful Flipper Zero Alternative
⚠️
Cyber Security Today, May 15, 2024 - Ebury botnet still exploiting Linux servers, Microsoft, SAP and Apple issue security updates, and more
⚠️
Adobe Releases Security Updates for Multiple Products
⚠️
Got MFA? If not, Now is the Time!, (Wed, May 15th)
⚠️
CISA, FBI, and DHS Unveil Cybersecurity Guide For Civil Society Groups
⚠️
Cerebral Valley Hackers Build $20 Open Source Smart Glasses
⚠️
Microsoft Warns Of Active Zero Day Exploitation, Patches 60 Windows Vulns
⚠️
Singing River ransomware attack now thought to have affected over 895,000
⚠️
Hackers Attacking Foxit PDF Reader Users To steal Sensitive Data
⚠️
FTC Fires β€˜Shot Across the Bow’ at Automakers Over Connected-Car Data Privacy
⚠️
FBI Seizes Criminal Site BreachForums
⚠️
FBI Seizes BreachForums Again, Urges Users to Report Criminal Activity
⚠️
FBI seizes hacking forum BreachForums β€” again
⚠️
How you may be affected by the new proposed Critical Infrastructure Cyber Incident Reporting Rule
⚠️
Google patches third exploited Chrome zero-day in a week
⚠️
A Vulnerability in SolarWinds Access Rights Manager Could Allow for Privilege Escalation
⚠️
Google fixes third actively exploited Chrome zero-day in a week
KEV
πŸ“‹
ICS Patch Tuesday: Advisories Published by Siemens, Rockwell, Mitsubishi Electric
πŸ“‹
Singapore Cybersecurity Update Puts Cloud Providers on Notice
πŸ“‹
Intel Publishes 41 Security Advisories for Over 90 Vulnerabilities
πŸ“’
Senators Urge $32 Billion in Emergency Spending on AI After Finishing Yearlong Review
πŸ“’
Critical vulnerabilities in Telit Cinterion modems | Kaspersky official blog
πŸ“’
New cybersecurity sheets from CISA and NSA: An overview
πŸ“’
Turla Group Deploys LunarWeb and LunarMail Backdoors in Diplomatic Missions
πŸ“’
NIST Issues New Guidelines on Protecting Unclassified Data in Government Systems
πŸ“’
Slovakia's Prime Minister Fico Shot After Government Meeting
πŸ“’
HPE security advisory (AV24-271)
πŸ“’
Microsoft Edge security advisory (AV24-270)
πŸ“’
F5 security advisory (AV24-272)
πŸ“’
Securing Tomorrow: A Recap of CISA’s Cyber Resilient 911 Symposium (Central Region)
πŸ“’
Cisco security advisory (AV24-273)
πŸ“’
Opening Statement by CISA Director Jen Easterly at the Update on Foreign Threats to the 2024 Elections Hearing
πŸ“’
UK NCSC Launches New Hacking Alert System for Politicians
πŸ“’
To the Moon and back(doors): Lunar landing in diplomatic missions
πŸ”₯
Dell Hack: Attacker Steals Customer Phone Numbers & Service Reports
πŸ”₯
IT Teams Beware! Weaponized WinSCP & PuTTY Delivers Ransomware
πŸ”₯
How Did Authorities Identify the Alleged Lockbit Boss?
πŸ”₯
Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators
πŸ”₯
Ebury Botnet Malware Compromises 400,000 Linux Servers Over Past 14 Years
πŸ”₯
900k Impacted by Data Breach at Mississippi Healthcare Provider
πŸ”₯
Santander Data Breach Impacts Customers, Employees
πŸ”₯
Banco Santander warns of a data breach exposing customer info
πŸ”₯
Santander Data Breach Impacts Customers, Employees
πŸ”₯
LockBit Ransomware Spread In Millions Of Emails Via Phorpiex Botnet
πŸ”₯
FBI seize BreachForums hacking forum used to leak stolen data
πŸ”₯
Report: Data Breaches in US Schools Exposed 37.6M Records
πŸ”₯
Phishing and Pretexting Dominate Social Engineering-Related Data Breaches
πŸ”₯
Windows Quick Assist abused in Black Basta ransomware attacks
πŸ”₯
Google adds live threat detection and screen-sharing protection to Android
πŸ”₯
Nissan North America data breach impacts over 53,000 employees
πŸ”₯
Report: 11 Vulnerabilities Found in GE Ultrasound Devices
πŸ”₯
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
πŸ•΅οΈ
Vermont Legislature Passes One of the Strongest Data Privacy Measures in the Country
πŸ•΅οΈ
ISC Stormcast For Wednesday, May 15th, 2024 https://isc.sans.edu/podcastdetail/8982, (Wed, May 15th)
πŸ•΅οΈ
Cybersecurity Expert Jailed For Hacking 400K Smart Homes, Selling Videos
πŸ•΅οΈ
Tor Browser 13.0.15 Released: What’s New!
πŸ•΅οΈ
JSSI 2024 - 8 talks in FRENCH
πŸ•΅οΈ
Tornado Cash Developer Jailed for Laundering Billions of Dollars
πŸ•΅οΈ
Adobe Patches Multiple Code Execution Flaws in a Wide Range of Products
πŸ•΅οΈ
Southeast Asian scam syndicates stealing $64 billion annually, researchers find
πŸ•΅οΈ
400,000 Linux Servers Hit by Ebury Botnet
πŸ•΅οΈ
Unwanted Tracking Alerts Rolling Out to iOS, Android
πŸ•΅οΈ
Russian Actors Weaponize Legitimate Services in Multi-Malware Attack
πŸ•΅οΈ
The Dark Side of AI in Cybersecurity β€” AI-Generated Malware
πŸ•΅οΈ
SideCopy APT Campaign Found Targeting Indian Universities
πŸ•΅οΈ
Threat Actors Abuse GitHub to Distribute Multiple Information Stealers
πŸ•΅οΈ
FBI Warns of AI-Assisted Phishing Campaigns
πŸ•΅οΈ
Russian Actors Weaponize Legitimate Services in Multi-Malware Attack
πŸ•΅οΈ
What are You Working on Wednesday
πŸ•΅οΈ
Android 15 Rolls Out Advanced Features to Protect Users from Scams and Malicious Apps
πŸ•΅οΈ
Thoma Bravo-owned LogRhythm Announces Merger with Rival Exabeam
πŸ•΅οΈ
RSAC Cryptographers' Panel Tackles AI, Post-Quantum, Privacy
πŸ•΅οΈ
Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach
πŸ•΅οΈ
SIEM Stalwart LogRhythm to Merge With Exabeam
πŸ•΅οΈ
EU and US Advance Bilateral Talks on AI, Cybersecurity
πŸ•΅οΈ
Bipartisan Senators Endorse $32M Annually for AI Research
🌐
Scammers are Getting Creative Using Malvertising, Deepfakes, and YouTube
🌐
400,000 Linux Servers Hit By Ebury Botnet
🌐
Android 15, Google Play get new anti-malware and anti-fraud features
🌐
Android 15, Google Play Protect get new anti-malware and anti-fraud features
πŸŽ™οΈ
Smashing Security podcast #372: The fake deepfake, and Estate insecurity
πŸ“‘
Dutch Court Sentences Tornado Cash Co-Founder to 5 Years in Prison for Money Laundering
πŸ“‘
It's Time to Master the Lift & Shift: Migrating from VMware vSphere to Microsoft Azure
πŸ“‘
DeRusha Stepping Down From Federal CISO Role
πŸ“‘
Making Waves: LATAM Sales Team Clears Beach Debris in Panama
πŸ“‘
Tornado Cash cryptomixer dev gets 64 months for laundering $2 billion
πŸ“‘
Several Vulnerabilities Addressed in Ubuntu 24.04
πŸ“‘
How to identify misinformation, disinformation, and malinformation (ITSAP.00.300)
πŸ“‘
AI Is an Expert Liar
πŸ“‘
FCC Names And Shames Royal Tiger AI Robocall Crew
πŸ“‘
Australia: AFL Players Call for Data Protection Overhaul as Concerns Include Drug Test Results
πŸ“‘
Security considerations for research and development organizations (ITSAP.00.130)
πŸ“‘
Sophos Firewall v20 MR1 is now available
πŸ“‘
A Cost-Effective Encryption Strategy Starts With Key Management
πŸ“‘
Google’s call-scanning AI could dial up censorship by default, privacy experts warn
πŸ“‘
Apple blocked $7 billion in fraudulent App Store purchases in 4 years
πŸ“‘
Google Launches AI-Powered Theft and Data Protection Features for Android Devices
πŸ“‘
Brothers arrested for $25 million theft in Ethereum blockchain attack
πŸ“‘
Rethink your password habits to protect your accounts from hackers (ITSAP.30.036)
πŸ“‘
Android to add new anti-theft and data protection features
πŸ“‘
Live Webinar | Practical Strategies for Accelerating AI Adoption in Cybersecurity
πŸ“‘
Understanding Imposter Syndrome in the Technology Sector