98Articles
9Categories
2024-05-24Date
🚨
Three-Year-Old Apache Flink Flaw Now Under Active AttackAn improper access control bug in Apache Flink that was fixed in January 2021 has been added to the US government's Known Exploited Vulnerabilities Catalog, meaning criminals are right now abusing the flaw in the wild to compromise targets.
KEV
🐛
Google Patches Fourth Chrome Zero-Day in Two Weeks
KEV
🐛
Courtroom Software Backdoored to Deliver RustDoor Malware in Supply Chain Attack
🐛
Google Detects 4th Chrome Zero-Day in May Actively Under Attack - Update ASAP
KEV
🐛
Kroll cyber threat landscape report: AI assists attackers
🐛
Google Fixes Eighth Actively Exploited Chrome Zero-Day This Year
KEV
🐛
High-Severity GitLab Flaw Lets Attackers Take Over Accounts
⚠️
Operation SpecTor: Authorities Seized Dark Markets Offering Illicit Goods
⚠️
Emerging ransomware groups on the rise: Who they are, how they operate
⚠️
Beware Of HTML That Masquerade As PDF Viewer Login Pages
⚠️
Google fixes eighth actively exploited Chrome zero-day this year
KEV
⚠️
What is spear phishing? Examples, tactics, and techniques
⚠️
On the Zero-Day Market
⚠️
Chinese State-Backed Hackers Turn to Massive ORB Proxy Networks to Evade Detection
⚠️
DNSBomb : A New DoS Attack That Exploits DNS Queries
⚠️
Kinsing Malware Attacking Apache Tomcat Server With Vulnerabilities
⚠️
Cyber Force Provision Gets House Committee’s Approval
⚠️
Cisco Releases May 2024 Cisco ASA, FMC, and FTD Software Security Publication
⚠️
Google Patches Fourth Chrome Zero Day In Two Weeks
⚠️
Cencora data breach exposes US patient info from 8 drug companies
⚠️
Hackers Created Rogue VMs to Evade Detection in Recent MITRE Cyber Attack
⚠️
ShrinkLocker Ransomware Exploits Microsoft's BitLocker
⚠️
CISA Releases Cybersecurity Resources for High-Risk Communities
⚠️
AI-as-a-Service Platform Patches Critical RCE Vulnerability
⚠️
Hacker defaces spyware app’s site, dumps database and source code
⚠️
Cencora data breach exposes US patient info from 11 drug companies
📢
Three-year-old Apache Flink flaw under active attack
📢
Chinese Cyberespionage Campaign Targets Governmental Entities in the Middle East, Africa, and Asia
📢
White House Seeks Critical Cyber Assistance for Water Utilities, Healthcare
📢
Google Chrome security advisory (AV24-293)
📢
EU Commission and Microsoft Appeal EDPS Office 365 Decision
🔥
A Fireside Chat with CyberArk's Incident Response & Red Teams
🔥
Microsoft President Set to Testify Before Congress on ‘Security Shortcomings’
🔥
Hacktivists Turn to Ransomware in Attacks on Philippines Government
🔥
Cyber Security Today, May 24, 2024 - A threat actor leverages Windows BitLocker in ransomware attacks, beware of ORB networks, and more
🔥
Cyberattacks are Good for Security Vendors, and Business is Booming
🔥
DevOps Dilemma: How Can CISOs Regain Control in the Age of Speed?
🔥
New ransomware group abusing BitLocker
🔥
Ireland Police Facing Nearly a Million-Dollar Fine After Data Breach Exposes Officers’ Details
🔥
Courtroom Recording Software Compromised With Backdoor Installer
🔥
Hackers Weaponizing Microsoft Access Documents To Execute Malicious Program
🔥
Microsoft Warns Of Storm-0539’s Aggressive Gift Card Theft
🔥
Almost all citizens of city of Eindhoven have their personal data exposed
🔥
Averlon Emerges From Stealth Mode With $8 Million in Funding
🔥
US drug maker Cencora says Americans’ health information stolen in data breach
🔥
London Drugs Waiting On LockBit's Next Move
🔥
New ShrinkLocker ransomware uses BitLocker to encrypt your files
🔥
Australian Telecom Watchdog Sues Optus Over 2022 Data Breach
🔥
LockBit Publishes Data Stolen in London Drugs Attack
🔥
ISMG Editors: UnitedHealth Group's HIPAA Breach Fallout
KEV
🔥
Mandatory reporting for ransomware attacks? – Week in security with Tony Anscombe
🕵️
ISC Stormcast For Friday, May 24th, 2024 https://isc.sans.edu/podcastdetail/8996, (Fri, May 24th)
🕵️
Pakistani-Aligned APT36 Targets Indian Defense Organizations
🕵️
Japanese Experts Warn of BLOODALCHEMY Malware Targeting Government Agencies
🕵️
APT41 Deploys KeyPlug Backdoor Against Italian Industries
🕵️
Malicious PyPI & NPM Packages Attacking MacOS Users
🕵️
Deep Dive Into Unfading Sea Haze: A New Threat Actor in the South China Sea
🕵️
IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders
🕵️
Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia
🕵️
A root-server at the Internet’s core lost touch with its peers. We still don’t know why.
🕵️
Windows Recall — a ‘privacy nightmare’?
🕵️
In Other News: China’s Undersea Spying, Hotel Spyware, Iran’s Disruptive Attacks
🕵️
NSA Releases Guidance On Zero Trust Maturity To Secure Application From Attackers
🕵️
Chinese Hackers Stay Hidden On Military And Government Networks For Six Years
🕵️
JAVS Courtroom Audio-Visual Software Installer Serves Backdoor
🕵️
Fake Antivirus Websites Deliver Malware to Android and Windows Devices
🕵️
Off-Topic Friday
🕵️
CISOs Pursuing AI Readiness Should Start by Updating Their Email Security Policy
🕵️
How Major Acquisitions Are Transforming Security Operations
🕵️
The /c/cybersecurity community on Infosec.pub has new icon and banner artwork courtesy of @bolo ! It already makes the space look nicer if you ask me 🎨 😄
🕵️
Courtroom Recording Software Hit by Supply Chain Attack
🕵️
Attempts to Regulate AI’s Hidden Hand in Americans’ Lives Flounder in US Statehouses
🕵️
Gold Pressed Latinum, VBScript, ORBS, Rockwell, Chrome, SKY, Aaran Leyland, and More - SWN #389
🕵️
Which OS/Distro?
🕵️
As Many as 1 in 7 Emails Make it Past Your Email Filters
🕵️
CyberRiskTV Live Coverage from Identiverse 2024 - Day 2
🕵️
CyberRiskTV Live Coverage from Identiverse 2024 - Day 1
🕵️
Friday Squid Blogging: Dana Squid Attacking Camera
🌐
How Do Hackers Blend In So Well? Learn Their Tricks in This Expert Webinar
🌐
JAVS Courtroom Audio-Visual Software Installer Serves Backdoor
🌐
BloodAlchemy Malware Used to Target Government Agencies in Southern and Southeastern Asia
🎙️
Cyber Security Today, Week in Review for week ending May 24, 2024
📡
SOCRadar raises $25.2 million to accelerate investments in key areas
📡
Report Reveals 341% Rise in Advanced Phishing Attacks
📡
Why Shareable SBOMs are Essential for Software Security
📡
UK Government in $10.8m Bid to Tackle AI Cyber-Threats
📡
US Man Gets 10 Years for Laundering Cash From Online Fraud
📡
How Microsoft secures Generative AI
📡
Bolster Raises $14M Led by Microsoft's M12
📡
Machine Identities Lack Essential Security Controls, Pose Major Threat
📡
Three-Year-Old Apache Flink Flaw Under Active Attack
📡
Morocco-based Cybercriminals Cashing in on Bold Gift Card Scams
📡
Bugcrowd Buys Informer to Enhance Attack Surface Management
📡
A Strategic Approach to Stopping SIM Swap Fraud
📡
Microsoft Copilot fixed worldwide after 24 hour outage
📡
Microsoft: Windows 24H2 will remove Cortana and WordPad apps
📡
Protecting yourself from identity theft online (ITSAP.00.033)
📡
ICQ messenger shuts down after almost 28 years