148Articles
7Categories
2024-06-11Date
πŸ›
Arm Warns of Actively Exploited Zero-Day Vulnerability in Mali GPU Drivers
KEV
πŸ›
Arm Warns Of Mali GPU Kernel Driver Flaws Exploited In The Wild
KEV
πŸ›
Arm Warns of Exploited Kernel Driver Vulnerability
πŸ›
Apple Patches Vision Pro Vulnerability Used in Possibly β€˜First Ever Spatial Computing Hack’
πŸ›
TellYouThePass ransomware exploits recent PHP RCE flaw to breach servers
πŸ›
CVE-2024-30069 Windows Remote Access Connection Manager Information Disclosure Vulnerability
πŸ›
CVE-2024-30070 DHCP Server Service Denial of Service Vulnerability
πŸ›
CVE-2024-30072 Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability
πŸ›
CVE-2024-30074 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
πŸ›
CVE-2024-30075 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
πŸ›
CVE-2024-30076 Windows Container Manager Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30077 Windows OLE Remote Code Execution Vulnerability
πŸ›
CVE-2024-30078 Windows Wi-Fi Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-30080 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30082 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-35250 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-35255 Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
πŸ›
CVE-2023-50868 MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU
πŸ›
CVE-2024-29187 GitHub: CVE-2024-29187 WiX Burn-based bundles are vulnerable to binary hijack when run as SYSTEM
πŸ›
CVE-2024-29060 Visual Studio Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30062 Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability
πŸ›
CVE-2024-30063 Windows Distributed File System (DFS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30064 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30065 Windows Themes Denial of Service Vulnerability
πŸ›
CVE-2024-30066 Winlogon Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30067 Winlogon Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30068 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30083 Windows Standards-Based Storage Management Service Denial of Service Vulnerability
πŸ›
CVE-2024-30084 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30085 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30086 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30087 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30088 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30089 Microsoft Streaming Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30090 Microsoft Streaming Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30091 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30093 Windows Storage Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30094 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30095 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30096 Windows Cryptographic Services Information Disclosure Vulnerability
πŸ›
CVE-2024-30097 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30099 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30100 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-30101 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2024-30102 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2024-30103 Microsoft Outlook Remote Code Execution Vulnerability
πŸ›
CVE-2024-30104 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
πŸ›
CVE-2024-35249 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
πŸ›
CVE-2024-35252 Azure Storage Movement Client Library Denial of Service Vulnerability
πŸ›
CVE-2024-35253 Microsoft Azure File Sync Elevation of Privilege Vulnerability
πŸ›
CVE-2024-35254 Azure Monitor Agent Elevation of Privilege Vulnerability
πŸ›
CVE-2024-35263 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
πŸ›
CVE-2024-35265 Windows Perception Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-37325 Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
πŸ›
CVE-2024-30052 Visual Studio Remote Code Execution Vulnerability
⚠️
Certified Ethical Hacker (CEH): Certification cost, training, and value
⚠️
The risks in mergers and acquisitions CISOs need to know
⚠️
China-Linked ValleyRAT Malware Resurfaces with Advanced Data Theft Tactics
⚠️
DarkGate Malware Being Spread Via Excel Docs Attached To Phishing Emails
⚠️
New HR-Themed Credential Harvesting Phishing Attack Uses Legitimate Signature Platform Yousign
⚠️
Fortinet grabs cloud security player Lacework
⚠️
CyberheistNews Vol 14 #24 [NEW 2024 RESEARCH] Reveals that 34% of Green Users Will Fail a Phishing Test
⚠️
Arm Warns Of Exploited Kernel Driver Vulnerability
⚠️
CISA Releases Six Industrial Control Systems Advisories
⚠️
Let’s Go into the rabbit hole (part 2) β€” the challenges of dynamically hooking Golang programs
⚠️
Sinister "More_eggs" Malware Cracks Into Companies by Targeting Hiring Managers
⚠️
City of Cleveland shuts down IT systems after cyberattack
⚠️
MFA soon compulsory for AWS users, passwordless authentication an option
⚠️
Fortinet Releases Security Updates for FortiOS
⚠️
Microsoft June 2024 Patch Tuesday fixes 51 flaws, 18 RCEs
⚠️
JetBrains warns of IntelliJ IDE bug exposing GitHub access tokens
⚠️
CISOs may be too reliant on EDR/XDR defenses
⚠️
Microsoft Releases June 2024 Security Updates
⚠️
Microsoft Patch Tuesday June 2024, (Tue, Jun 11th)
⚠️
Patch Tuesday: Remote Code Execution Flaw in Microsoft Message Queuing
⚠️
Cleveland Cyber Incident Prompts Shutdown of City IT Systems
⚠️
Ransomware Gang TellYouThePass Exploits PHP Vulnerability
⚠️
Critical Patches Issued for Microsoft Products, June 11, 2024
πŸ“‹
Adobe Plugs Code Execution Holes in After Effects, Illustrator
πŸ“‹
Patch Tuesday, June 2024 β€œRecall” Edition
πŸ“’
Hackers Weaponizing MSC Files In Targeted Attack Campaign
πŸ“’
SSLoad Malware Employs MSI Installer To Kick-Start Delivery Chain
πŸ“’
HPE security advisory (AV24-324)
πŸ“’
SAP security advisory – June 2024 monthly rollup (AV24-325)
πŸ“’
Microsoft Recall's Security & Privacy, Hacking Web APIs, Secure Design Pledge - ASW #288
πŸ“’
[Control systems] Schneider Electric security advisory (AV24-326)
πŸ“’
Mozilla security advisory (AV24-327)
πŸ“’
[Control systems] Siemens security advisory (AV24-328)
πŸ“’
JetBrains security advisory (AV24-329)
πŸ“’
Microsoft security advisory – June 2024 monthly rollup (AV24-330)
πŸ“’
Adobe security advisory (AV24-331)
πŸ”₯
Snowflake Breach Exposes 165 Customers' Data in Ongoing Extortion Campaign
πŸ”₯
Privacy Regulators Probe Impact of 23andMe's Mega-Breach
πŸ”₯
Top 10 Critical Pentest Findings 2024: What You Need to Know
πŸ”₯
Pure Storage confirms data breach after Snowflake account hack
πŸ”₯
BlackBerry Cylance Data Offered for Sale on Dark Web
πŸ”₯
Ransomware Gangs Are Adopting More Brutal Tactics Amidst Crackdowns
πŸ”₯
Mandiant Links Snowflake Breaches To Infostealer Infections
πŸ”₯
The mystery of an alleged data broker’s data breach
πŸ”₯
New Warmcookie Windows backdoor pushed via fake job offers
πŸ”₯
Chinese hackers breached 20,000 FortiGate systems worldwide
πŸ”₯
IT downtime cuts enterprise profit by 9%, says study
πŸ”₯
How Cynet Makes MSPs Rich & Their Clients Secure
πŸ”₯
Half a Dozen Flaws in Netgear Router Put User Data at Risk
πŸ”₯
DOJ Investigating Medical Transcribers' Mega Hack: Report
πŸ”₯
Dutch Agency Renews Warning of Chinese Fortigate Campaign
πŸ•΅οΈ
ISC Stormcast For Tuesday, June 11th, 2024 https://isc.sans.edu/podcastdetail/9018, (Tue, Jun 11th)
πŸ•΅οΈ
Apple is bringing RCS to the iPhone in iOS 18
πŸ•΅οΈ
Hackers Used Homemade Mobile Antenna To Send Thousands Of Smishing Text
πŸ•΅οΈ
RSAC Fireside Chat: Ontinue ups the β€˜MXDR’ ante β€” by emphasizing wider automation, collaboration
πŸ•΅οΈ
Noodle RAT: Reviewing the New Backdoor Used by Chinese-Speaking Groups
πŸ•΅οΈ
Xona Raises $18 Million for OT Remote Access Platform
πŸ•΅οΈ
Bruce Schneier: "AI Will Increase the Quantityβ€”and Qualityβ€”of Phishing Scams"
πŸ•΅οΈ
LLMs Acting Deceptively
πŸ•΅οΈ
Chinese Hackers using New Noodle RAT to Attack Linux Servers
πŸ•΅οΈ
Vietnamese Entities Targeted By China-Linked Mustang Panda In Cyber Espionage
πŸ•΅οΈ
Rogue Cell Tower Shut Down in London
πŸ•΅οΈ
SAP Patches High-Severity Vulnerabilities in Financial Consolidation, NetWeaver
πŸ•΅οΈ
Dangerous Liaisons: The Interaction Between Threat Actors and High-Risk Devices
πŸ•΅οΈ
Supreme Court Will Take Up Meta’s Bid to End Lawsuit Over Cambridge Analytica Privacy Scandal
πŸ•΅οΈ
Remcos RAT Distributed As UUEncoding (UUE) File To Steal Logins
πŸ•΅οΈ
Netskope secures SaaS apps with genAI
πŸ•΅οΈ
Multiple Vulnerabilities Plague Discontinued Netgear WNR614 Routers
πŸ•΅οΈ
Forrester Names Palo Alto Networks a Leader in OT Security
πŸ•΅οΈ
CISO and the Board: Demonstrating value and relevant metrics - Max Shier - CSP #178
πŸ•΅οΈ
Two Arrested in UK for Smishing Campaign Powered by Homemade SMS Blaster
πŸ•΅οΈ
Beware: Major AI Chatbots Now Intentionally Spreading Election Disinformation
πŸ•΅οΈ
Buzz Aldrin, the Gray Lady, Veeam, Microsoft squared, Nvidia, Josh Marpet... - SWN #392
πŸ•΅οΈ
Dutch intelligence says Chinese hacking campaign β€˜more extensive’ than previously known
πŸ•΅οΈ
WARMCOOKIE backdoor masquerades as a recruiting offer
πŸ•΅οΈ
AI Will Soon Exhaust the Internet. What's Next?
πŸ•΅οΈ
Atos Agrees to New Financial Restructuring Plans
πŸ•΅οΈ
Cyberhaven Secures $88M to Strengthen Data Security Platform
πŸ•΅οΈ
US DOD Seeks Commercial Partner for AI Governance Overhaul
πŸ•΅οΈ
Chinese-Made Biometric Access System Has 24 Vulnerabilities
πŸ“‘
Notifications from FB and theft of business account passwords
πŸ“‘
Apple Integrates OpenAI's ChatGPT into Siri for iOS, iPadOS, and macOS
πŸ“‘
Why Passwords Still Matter In The Age Of AI
πŸ“‘
VSCode Extensions With Malicious Code Installed 229M Times
πŸ“‘
Protecting the data of our commercial and public sector customers in the AI era
πŸ“‘
Chinese Actor SecShow Conducts Massive DNS Probing on Global Scale
πŸ“‘
Windows 10 KB5039211 update released with new feature, 12 fixes
πŸ“‘
At last, Apple’s Messages app will support RCS and scheduling texts
πŸ“‘
Windows 11 KB5039212 update released with 37 changes, fixes
πŸ“‘
Top 10 IT security actions: Number 4 harden operating systems and applications (ITSM.10.090)
πŸ“‘
New Windows Server KB5039227 and KB5039217Β updates fix LSASS crashes
πŸ“‘
UK Sides With APP Fraud Victims - Despite Industry Pressure