90Articles
10Categories
2024-07-10Date
🚨
CISA Adds Microsoft Windows and Rejetto HTTP File Server Bugs to its Known Exploited Vulnerabilities CatalogThe vulnerabilities added include CVE-2024-23692 affecting Rejetto HTTP File Server, CVE-2024-38080 impacting Windows Hyper-V, and CVE-2024-38112 targeting Windows MSHTML Platform.
KEV
πŸ›
New OpenSSH Vulnerability Discovered: Potential Remote Code Execution Risk
πŸ›
New Flaw in OpenSSH can Lead to Remote Code Execution
πŸ›
New Ransomware Group Exploiting Veeam Backup Software Vulnerability
πŸ›
CISA and FBI Release Secure by Design Alert on Eliminating OS Command Injection Vulnerabilities
⚠️
More than a CISO: the rise of the dual-titled IT leader
⚠️
Software supply chain still dangerous despite new protections
⚠️
U.S. Disrupts AI-Powered Russian State-Sponsored Hackers Bot Farm
⚠️
Hackers Target WordPress Calendar Plugin Used by 150,000 Sites
⚠️
How CISA Plans to Measure Trust in Open-Source Software
⚠️
Monocle: Open-Source LLM for Binary Analysis Search
⚠️
Blast RADIUS Attack can Bypass Authentication for Clients
⚠️
FBI disrupts 1,000 Russian bots spreading disinformation on X
⚠️
Chinese State Actor APT40 Exploits N-Day Vulnerabilities Within Hours
⚠️
Crypto Thefts Double to $1.4 Billion, TRM Labs Finds
⚠️
Microsoft July 2024 Patch Tuesday Fixes 142 Flaws, 4 Zero-Days
KEV
⚠️
Smash-and-Grab Extortion
⚠️
Microsoft's July Update Patches 143 Flaws, Including Two Actively Exploited
KEV
⚠️
Chinese APT40 Is Ready To Exploit New Vulnerabilities Within Hours Of Release
⚠️
Citrix Patches Critical NetScaler Console Vulnerability
⚠️
RADIUS Vulnerability
⚠️
Windows MSHTML zero-day used in malware attacks for over a year
KEV
⚠️
Citrix Patches Critical NetScaler Console Vulnerability
⚠️
Four Zero Days Headline Hefty July Patch Tuesday Drop
⚠️
The Stark Truth Behind the Resurgence of Russia’s Fin7
⚠️
Evolve data breach impacted upward of 7.64 million consumers
⚠️
Australia Flags Persistent Chinese Cyberespionage Hacking
⚠️
GitLab: Critical bug lets attackers run pipelines as other users
⚠️
Researchers Discover New Malware Aimed at Mining Sector
⚠️
Widely Used RADIUS Authentication Flaw Enables MITM Attacks
πŸ“‹
"Privatephoneshop" and "Myntex" are scam, selling insecure devices, and harrassing a GrapheneOS developers
πŸ“‹
ICS Patch Tuesday: Siemens, Schneider Electric, CISA Issue Advisories
πŸ“‹
Microsoft Patch Tuesday July 2024 - Four Critical Vulnerabilities Patched
πŸ“’
As CISOs Grapple with the C-Suite, Job Satisfaction Takes a Hit
πŸ“’
Digital solidarity vs. digital sovereignty: Which side are you on?
πŸ“’
Can AI be Meaningfully Regulated, or is Regulation a Deceitful Fudge?
πŸ“’
From Policy to Practice in Security Culture: What Security Frameworks Recommend
πŸ“’
Mozilla security advisory (AV24-378)
πŸ“’
After Customers Get Breached, Snowflake Refines Security
πŸ“’
Japan warns of attacks linked to North Korean Kimsuky hackers
πŸ“’
CISA urges devs to weed out OS command injection vulnerabilities
πŸ“’
Adobe security advisory (AV24-379)
πŸ“’
Red Hat security advisory (AV24-380)
πŸ“’
[Control systems] Schneider Electric security advisory (AV24-381)
πŸ“’
SAP security advisory – July 2024 monthly rollup (AV24-382)
πŸ“’
Palo Alto Networks security advisory (AV24-383)
πŸ”₯
Threat Actors Claiming Breach of KFC Database
πŸ”₯
The Heritage Foundation - 72,004 breached accounts
πŸ”₯
It’s Time to Reassess Your Cybersecurity Priorities
πŸ”₯
True Protection or False Promise? The Ultimate ITDR Shortlisting Guide
πŸ”₯
New Eldorado Ransomware Attacking Windows And Linux Systems
πŸ”₯
Most Security Pros Admit Shadow SaaS and AI Use
πŸ”₯
Microsoft emails that warned customers of Russian hacks criticized for looking like spam and phishing
πŸ•΅οΈ
ISC Stormcast For Wednesday, July 10th, 2024 https://isc.sans.edu/podcastdetail/9046, (Wed, Jul 10th)
πŸ•΅οΈ
X-Files Stealer Attacking Windows Users to Steal Passwords
πŸ•΅οΈ
Persistent npm Campaign Shipping Trojanized jQuery
πŸ•΅οΈ
Scammers Offering Fraud-as-a-service to Other Scammers to Drain Victims Funds
πŸ•΅οΈ
New Golang Botnet "Zergeca" Discovered, Delivers Brutal DDoS Attacks
πŸ•΅οΈ
US Disrupts AI-Powered Russian Bot Farm on X
πŸ•΅οΈ
Passkeys Available for Passkeys high-risk Users in the Advanced Protection Program
πŸ•΅οΈ
BSides SF 2024 - 61 videos
πŸ•΅οΈ
Russian Spear Phishing Campaigns Target NATO Entities
πŸ•΅οΈ
Houthi-Aligned APT Targets Mideast Militaries With 'GuardZoo' Spyware
πŸ•΅οΈ
AI Provides an Rx for Cybersecurity in Healthcare
πŸ•΅οΈ
VMware Patches Critical SQL-Injection Flaw in Aria Automation
πŸ•΅οΈ
Cytactic Snags $16M Seed Funding for Cyber Crisis Management Technology
πŸ•΅οΈ
Singapore to Phase Out One-Time Passwords in Banking
πŸ•΅οΈ
BitMEX Pleads Guilty to Violating Anti-Money Laundering Laws
🌐
ViperSoftX Malware Disguises as eBooks on Torrents to Spread Stealthy Attacks
🌐
UK Government Advises Best Practices for Embedded Device Security
🌐
Ticket Heist network of 700 domains sells fake Olympic Games tickets
🌐
Malware Wormed Its Way Through Fujitsu Japan's Systems
🌐
Ticket Heist fraud gang uses 700 domains to sell fake Olympics tickets
🌐
ViperSoftX malware covertly runs PowerShell using AutoIT scripting
πŸŽ™οΈ
Understanding IoT security risks and how to mitigate them | Cybersecurity podcast
πŸ“‘
Crypto Analysts Expose HuiOne Guarantee's $11 Billion Cybercrime Transactions
πŸ“‘
Google Advanced Protection Program gets passkeys for high-risk users
πŸ“‘
Google Adds Passkeys to Advanced Protection Program for High-Risk Users
πŸ“‘
US Senate NDAA 2025 Boosts Military Cyber and AI Initiatives
πŸ“‘
Ticket Heist Network of 700 Domains Sells Fake Olympic Games Tickets
πŸ“‘
Regional Transport Office Themed Phishing Campaign Targets Android Users In India
πŸ“‘
US Busts Russian AI-Driven Disinformation Operation
πŸ“‘
Finding Honeypot Data Clusters Using DBSCAN: Part 1, (Wed, Jul 10th)
πŸ“‘
Sophos ZTNA now supports on-premise Microsoft AD
πŸ“‘
Microsoft fixes Windows 11 bug causing reboot loops, taskbar freezes
πŸ“‘
US Disrupts AI-Powered Russian Bot Farm On X
πŸ“‘
Announcing The Bug Bounty Program Pack 1.0
πŸ“‘
Huione Guarantee exposed as a $11 billion marketplace for cybercrime
πŸ“‘
Deep Observability: Why You Need It. How You Get It.
πŸ“‘
Microsoft 365, Office users hit by wave of β€˜30088-27’ update errors