96Articles
8Categories
2024-06-28Date
🚨
CISA Adds GeoServer, Linux Kernel, and Roundcube Webmail Bugs to its Known Exploited Vulnerabilities CatalogThe US cybersecurity agency CISA has issued a warning about cyber threat actors exploiting vulnerabilities in GeoServer (CVE-2022-24816), the Linux kernel (CVE-2022-2586), and Roundcube Webmail (CVE-2020-13965).
KEV
πŸ›
Vanna AI Prompt Injection Vulnerability Enables RCE
πŸ›
Progress Software Releases Security Bulletin for MOVEit Transfer
⚠️
TeamViewer Detects Security Breach in Corporate IT Environment
⚠️
Chinese Hacker Groups Using Off-The-Shelf Tools To Deploy Ransomware
⚠️
Researchers Warn of Flaws in Widely Used Industrial Gas Analysis Equipment
⚠️
B+ Security Rating Masks Healthcare Supply Chain Risks
⚠️
Snowblind Abuses Android seccomp Sandbox To Bypass Security Mechanisms
⚠️
Top 12 cloud security certifications
⚠️
New SnailLoad Attack Exploits Network Latency to Spy on Users' Web Activities
⚠️
CISA Report Finds Critical Open-Source Memory Safety Risks
⚠️
Fortra Patches Critical SQL Injection in FileCatalyst Workflow
⚠️
GitLab vulnerability permits running pipeline tasks under another user
⚠️
8220 Gang Exploits Oracle WebLogic Server Flaws for Cryptocurrency Mining
⚠️
Defense in Depth podcast - Securing Identities in the Cloud
⚠️
TeamViewer Corporate Network Breached in Alleged APT Attack
⚠️
Vulnerability management empowered by AI
⚠️
Gitleaks: Open-Source Solution for Detecting Secrets in Your Code
⚠️
In Other News: Malware Delivered by ISP, Temu Spying, Critical Dataverse Vulnerability
⚠️
GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 Others
⚠️
TeamViewer targeted by APT29 hackers, containment measures in place
⚠️
Shifting Cybersecurity Philosophy from Threat-Centric to Compromise-Centric - Martin R... - ESW #366
⚠️
Vanna AI Prompt Injection Vulnerability Enables RCE
⚠️
Infosys McCamish says LockBit stole data of 6 million people
⚠️
Supply-chain ransomware attack cripples thousands of car dealerships
⚠️
LevelBlue Lays Off 15% of Employees After Being Sold by AT&T
⚠️
MoveIT, Entrust, Fed Reserve, ISPs, Volt Typhoon & More - SWN #395
πŸ“’
CISA and Fauquier County Hold K-12 Active Shooter Exercise
πŸ“’
Microsoft Edge security advisory (AV24-357)
πŸ“’
HPE security advisory (AV24-358)
πŸ“’
Juniper Networks security advisory (AV24-359)
πŸ“’
Gartner: 55% of Firms Now Rely on AI Governance Boards
πŸ“’
Startup Odaseva Raises $54M to Bolster Global Expansion, R&D
πŸ”₯
Ticketek - 17,643,173 breached accounts
πŸ”₯
Philippines Data Security Officer Hacked 93 Different Sites
πŸ”₯
Former IT Employee Stolen 1 Million Geisinger Patient’s Personal Data
πŸ”₯
U.S. Department of Justice Announced $10 Million Reward For Russian Hacker
πŸ”₯
πŸ”₯
Russian APT Reportedly Behind New TeamViewer Hack
πŸ”₯
TeamViewer Internal Systems Accessed by APT Hackers
πŸ”₯
WhisperGate Data-Wiping Malware Suspect Indicted
πŸ”₯
New Ransomware, Infostealers Pose Growing Risk in 2024
πŸ”₯
Chicago Children’s Hospital Says 791,000 Impacted by Ransomware Attack
πŸ”₯
Nuance Ex-Employee Indicted for Breach Affecting 1 Million
πŸ”₯
Remote access giant TeamViewer says Russian spies hacked its corporate network
πŸ”₯
TeamViewer links corporate cyberattack to Russian state hackers
πŸ”₯
Is GenAI Having a Rough Time? We check in to see how it's doing. - ESW #366
πŸ”₯
Remote Access Giant TeamViewer Says Russian Spies Hacked Its Corporate Network
πŸ”₯
New Unfurling Hemlock Threat Actor Floods Systems with Malware
πŸ”₯
Breaches Due to Credential Stuffing: Who's Accountable?
πŸ”₯
Dairy giant Agropur says data breach exposed customer info
πŸ”₯
Ticketmaster sends notifications about recent massive data breach
πŸ”₯
ISMG Editors: Growing Fallout From the Snowflake Breach
πŸ”₯
Microsoft Is Warning More Customers About Russian State Hack
πŸ”₯
Hubspot says it’s investigating customer account hacks
πŸ”₯
Multiple Vulnerabilities Found in Gas Chromatographs
πŸ”₯
Insurance Software Vendor Notifies 6.1 Million of 2023 Hack
πŸ•΅οΈ
ISC Stormcast For Friday, June 28th, 2024 https://isc.sans.edu/podcastdetail/9040, (Fri, Jun 28th)
πŸ•΅οΈ
Cyber Security Today, June 28, 2024 - Cyber authorities remind developers to switch to memory-safe coding languages
πŸ•΅οΈ
Xeno RAT Spread via .gg Domains and GitHub
πŸ•΅οΈ
Polyfill Domain Shut Down as Owner Disputes Accusations of Malicious Activity
πŸ•΅οΈ
Support of SSL 2.0 on web servers in 2024, (Fri, Jun 28th)
πŸ•΅οΈ
James Bamford on Section 702 Extension
πŸ•΅οΈ
TeamViewer investigating intrusion of corporate IT environment
πŸ•΅οΈ
Combatting the Evolving SaaS Kill Chain: How to Stay Ahead of Threat Actors
πŸ•΅οΈ
Your KnowBe4 Fresh Content Updates from June 2024
πŸ•΅οΈ
KnowBe4 Recognized as Cyber Security Educator of the Year at IT Europa Awards 2024
πŸ•΅οΈ
Fairness and Safety of LLMs
πŸ•΅οΈ
Microsoft Details β€˜Skeleton Key’ AI Jailbreak Technique
πŸ•΅οΈ
Kimsuky Deploys TRANSLATEXT to Target South Korean Academia
πŸ•΅οΈ
GetReal Labs Emerges From Stealth to Tackle Deepfakes
πŸ•΅οΈ
AuthZed Raises $12 Million for Permissions Management Technology
πŸ•΅οΈ
The risks and best practices of deploying AI to an enterprise - Anurag Lal - ESW #366
πŸ•΅οΈ
Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data
πŸ•΅οΈ
Russian APT Reportedly Behind New TeamViewer Hack
πŸ•΅οΈ
Google cuts ties with Entrust in Chrome over trust issues
πŸ•΅οΈ
'Poseidon' Mac stealer distributed via Google ads
πŸ•΅οΈ
Microsoft Alerts More Customers to Email Theft in Expanding Midnight Blizzard Hack
πŸ•΅οΈ
Russian hackers read the emails you sent us, Microsoft warns more customers
πŸ•΅οΈ
Friday Squid Blogging: New Squid Species
🌐
Polyfill.io, BootCDN, Bootcss, Staticfile attack traced to 1 operator
🌐
Malware Peddlers Experimenting with BPL Sideloading and Masking Malicious Payloads as PGP Keys
🌐
AI Pulse: Siri Says Hi to OpenAI, Deepfake Olympics & more
🌐
Mac Users Served Info Stealer Malware Through Google Ads
🌐
Key trends shaping the threat landscape in H1 2024 – Week in security with Tony Anscombe
πŸ“‘
Examining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
πŸ“‘
No Patches for Hospital Temperature Monitors' Critical Flaws
πŸ“‘
Mitigating Skeleton Key, a New Type of Generative AI Jailbreak Technique
πŸ“‘
California Privacy Regulator to Partner With French Data Authority
πŸ“‘
Cyber Insurance Terms Drive Companies To Invest More in Security, Report Finds
πŸ“‘
US Federal Agencies Warn Healthcare Sector of Payment Diversion Schemes
πŸ“‘
Crypto-Gang Leader Convicted of Vicious Kidnaps, Robbery
πŸ“‘
Hijacking GitHub accounts using phishing emails | Kaspersky official blog
πŸ“‘
β€˜Poseidon’ Mac stealer Distributed via Malicious Google Ads
πŸ“‘
On Point: Risk Management Strategies for AI Tools
πŸ“‘
Google Cuts Ties With Entrust In Chrome Over Trust Issues