108Articles
8Categories
2024-07-24Date
๐Ÿšจ
CISA Adds Twilio Authy and IE Flaws to Exploited Vulnerabilities ListThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2012-4792 (CVSS score: 9.3) - Microsoft Interneโ€ฆ
KEV
๐Ÿ›
Microsoft Defender Flaw Exploited to Deliver ACR, Lumma, and Meduza Stealers
๐Ÿ›
Infostealer Campaign Exploits Microsoft Windows SmartScreen Flaw to Spread Payloads
๐Ÿ›
Microsoft Defender SmartScreen bug actively used in stealer campaign
KEV
๐Ÿ›
Two Vulnerabilities Discovered in LangChain GenAI Framework
๐Ÿ›
Organizations Warned of Exploited Twilio Authy Vulnerability
๐Ÿ›
ISC Releases Security Advisories for BIND 9
๐Ÿ›
Docker Patches Critical AuthZ Plugin Bypass Vulnerability Dating Back to 2018
๐Ÿ›
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regimeโ€™s Military and Nuclear Programs
โš ๏ธ
Port shadow: Yet another VPN weakness ripe for exploit
โš ๏ธ
Countdown to DORA: How CISOs can prepare for EUโ€™s Digital Operational Resilience Act
โš ๏ธ
The Power and Peril of RMM Tools
โš ๏ธ
CrowdStrike meltdown highlights ITโ€™s weakest link: Too much administration
โš ๏ธ
How to Reduce SaaS Spend and Risk Without Impacting Productivity
โš ๏ธ
Hackers leak documents stolen from Pentagon contractor Leidos
โš ๏ธ
Google's reCAPTCHAv2 is just labor exploitation, boffins say
โš ๏ธ
CrowdStrike blames testing shortcomings for Windows meltdown
KEV
โš ๏ธ
Telegram App Flaw Exploited to Spread Malware Hidden in Videos
โš ๏ธ
BlueStacks Emulator For Windows Flaw Exposes Millions Of Gamers To Attack
โš ๏ธ
Chinese Hackers Using Shared Framework To Create Multi-Platform Malware
โš ๏ธ
Robot Dog Internet Jammer
โš ๏ธ
CrowdStrike offers a $10 apology gift card to say sorry for outage
โš ๏ธ
Docker fixes critical 5-year old authentication bypass flaw
โš ๏ธ
Zest Security Aims to Resolve, Not Just Mitigate Cloud Risks
โš ๏ธ
Guide your SOC Leaders to More Engineering Wisdom for Detection(Part 9)
โš ๏ธ
A Tumblr User Talks Crowdstrike
โš ๏ธ
US CISA Urges BIND 9 Users to Address New DNS Exploits
โš ๏ธ
Vulnerabilities in LangChain Gen AI Could Prompt Data Leak
๐Ÿ“‹
Windows July security updates send PCs into BitLocker recovery
๐Ÿ”ฅ
BreachForums v1 database leak is an OPSEC test for hackers
๐Ÿ”ฅ
Verizon to Pay $16 Million in TracFone Data Breach Settlement
๐Ÿ”ฅ
Pentagon IT Service Provider Hacked: U.S. Government Secrets Exposed
๐Ÿ”ฅ
CrowdStrike Explains Friday Incident Crashing Millions of Windows Devices
๐Ÿ”ฅ
BreachForums v1 database leak is an OPSEC test for hackers
๐Ÿ”ฅ
Patchwork Hackers Target Bhutan with Advanced Brute Ratel C4 Tool
๐Ÿ”ฅ
Chinese Espionage Group Upgrades Malware Arsenal to Target All Major Operating Systems
๐Ÿ”ฅ
CrowdStrike Explains Why Bad Update Was Not Properly Tested
๐Ÿ”ฅ
Dazz snaps up $50M for AI-based, automated cloud security remediation
๐Ÿ”ฅ
Unique malware identified in Panchan botnet with advanced persistence techniques
๐Ÿ”ฅ
DeFi Crypto Exchange dYdX v3 Website Hacked in DNS Hijacking Attack
๐Ÿ”ฅ
Verizon Subsidiary Settles With FCC for $16M Over Three Data Breaches
๐Ÿ”ฅ
Crisis communication: What NOT to do
๐Ÿ”ฅ
BreachForumsV1 Database Leaked: Private messages, Emails & IP Exposed
๐Ÿ”ฅ
Beware Of Malicious Python Packages That Steal Users Sensitive Data
๐Ÿ”ฅ
CrowdStrike: 'Content Validator' bug let faulty update pass checks
๐Ÿ”ฅ
ShadowRoot Ransomware Attacking Organizations With Weaponized PDF Documents
๐Ÿ”ฅ
57,000 Patients Impacted by Michigan Medicine Data Breach
๐Ÿ”ฅ
Is GhostEmperor Back? Sygnia Finds Clues in Recent Cyber Incident
๐Ÿ”ฅ
How to Lead When a Crisis Occurs
๐Ÿ”ฅ
Daixin Gang Threatening to Leak 10 Million Ambulance Records
๐Ÿ”ฅ
A Hacker โ€˜Ghostโ€™ Network Is Quietly Spreading Malware on GitHub
๐Ÿ•ต๏ธ
Most Airlines Except One Are Recovering From the CrowdStrike Tech Outage. The Feds Have Noticed
๐Ÿ•ต๏ธ
KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware
๐Ÿ•ต๏ธ
ISC Stormcast For Wednesday, July 24th, 2024 https://isc.sans.edu/podcastdetail/9066, (Wed, Jul 24th)
๐Ÿ•ต๏ธ
Spanish Police Arrest Three Suspects Linked to Pro-Moscow NoName057(16) Hackers
๐Ÿ•ต๏ธ
Possible APT28-linked Hackers Target Ukraineโ€™s Scientific Institutions
๐Ÿ•ต๏ธ
Researchers Detail on How Defenders Eliminate Detection Gaps in AWS Environments
๐Ÿ•ต๏ธ
Attackers Can Bypass 'Windows Hello' Strong Authentication
๐Ÿ•ต๏ธ
CrowdStrike Says Code-Testing Bugs Failed to Prevent Outage
๐Ÿ•ต๏ธ
Russia Shifts Cyber Focus to Battlefield Intelligence in Ukraine
๐Ÿ•ต๏ธ
What are You Working on Wednesday
๐Ÿ•ต๏ธ
Vanta Raises $150 Million at $2.45 Billion Valuation
๐Ÿ•ต๏ธ
Chrome 127 Patches 24 Vulnerabilities
๐Ÿ•ต๏ธ
Chinese Daggerfly uses a new version of Macma macOS backdoor
๐Ÿ•ต๏ธ
Malware Campaigns Target Hamster Kombat Players
๐Ÿ•ต๏ธ
Google Chrome 127 Released with a fix for 24 Security Vulnerabilities
๐Ÿ•ต๏ธ
250 Million Hamster Kombat Players Targeted Via Android And Windows Malware
๐Ÿ•ต๏ธ
Siemens Patches Power Grid Product Flaw Allowing Backdoor Deployment
๐Ÿ•ต๏ธ
Cyber firm KnowBe4 hired a fake IT worker from North Korea
๐Ÿ•ต๏ธ
Companies Are Playing Catch-Up to Secure Generative AI
๐Ÿ•ต๏ธ
KnowBe4 mistakenly hires North Korean hacker, faces infostealer attack
๐Ÿ•ต๏ธ
Dazz Scores Hefty $50M Investment for AI-Powered Risk Remediation Tech
๐Ÿ•ต๏ธ
Why Chatbots Aren't Always the Answer: Insights from Application Security Weekly
๐Ÿ•ต๏ธ
The Blob of Cybersecurity: Allie Mellen's Take on Industry Groupthink
๐Ÿ•ต๏ธ
US FTC Investigates Impact of AI-Powered Dynamic Pricing
๐Ÿ•ต๏ธ
Congratulations to the Top MSRC 2024 Q2 Security Researchers!
๐Ÿ•ต๏ธ
FBI Encountered Encryption Hurdles in Trump Shooting Probe
๐Ÿ•ต๏ธ
Email Gateway Security Gaps Enable New Malware Tactics
๐Ÿ•ต๏ธ
Over 3,000 GitHub accounts used by malware distribution service
๐Ÿ•ต๏ธ
Senator: Top Banks Only Reimburse 38% of Unauthorized Scams
๐Ÿ•ต๏ธ
Check Point Snags Team8's Nadav Zafrir to Replace Gil Shwed
๐Ÿ•ต๏ธ
Smashing Security podcast #382: CrowdStrike, Dark Wire, and the Paris Olympics
๐Ÿ•ต๏ธ
Zero Trust in the Age of AI: Join our online event to learn how to strengthen your security posture
๐Ÿ•ต๏ธ
Building security into the redesigned Chrome downloads experience
๐ŸŒ
CrowdStrike CEO is summoned before the Homeland Security committee. Cyber Security Today for Wednesday, July 24, 2023
๐ŸŒ
"Mouse Logger" Malicious Python Script, (Wed, Jul 24th)
๐ŸŒ
Fake CrowdStrike Repair Manual Pushes New Infostealer Malware
๐ŸŒ
Paris Wi-Fi Security Study | Kaspersky official blog
๐ŸŒ
How Russian Malware Cut Heat To 600 Heat To Ukrainian Buildings In Deep Winter
๐ŸŒ
Hot topics: Canโ€™t-miss sessions at Mandiantโ€™s 2024 mWISE event
๐Ÿ“ก
Chinese โ€˜Cybercrime Syndicateโ€™ Behind Gambling Sites Advertised at European Sporting Events
๐Ÿ“ก
Google Abandons Plan to Drop Third-Party Cookies in Chrome
๐Ÿ“ก
Unlocking cyber insurance savings to fund MDR
๐Ÿ“ก
Alphabet's Reported $23B Bet on Wiz Fizzles Out
๐Ÿ“ก
Report: HHS Needs to Beef up Cloud Security and Skills
๐Ÿ“ก
How a Trust Center Solves Your Security Questionnaire Problem
๐Ÿ“ก
Philippines to End Online Casinos, Maybe Scams Too
๐Ÿ“ก
Physicists Just Created An Element Using A Particle Beam
๐Ÿ“ก
Spain Arrested Three In Pro-Russian DDoS Crew Takedown
๐Ÿ“ก
Chrome 127 Patches 24 Vulnerabilities
๐Ÿ“ก
CrowdStrike Explains Why Bad Update Was Not Properly Tested
๐Ÿ“ก
School Gets An F For Using Facial Recognition On Kids In Canteen
๐Ÿ“ก
Cybersecurity Startup Protexxa Closes $10M Series A Round
๐Ÿ“ก
Google Chrome now warns about risky password-protected archives
๐Ÿ“ก
Microsoft fixes bug behind Windows 10 Connected Cache delivery issues
๐Ÿ“ก
SAFECOM and NCSWIC Publish Fall 2023 Joint SAFECOM-NCSWIC Bi-Annual Meeting Executive Summaries
๐Ÿ“ก
NCSWICโ€™s Planning, Training, and Exercise Committee releases โ€œSet Your PACE Planโ€ Flyer
๐Ÿ“ก
Google Chrome now asks for passwords to scan protected archives