122Articles
9Categories
2024-07-25Date
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogThe vulnerabilities are as follows: CVE-2012-4792, a decade-old vulnerability in Internet Explorer allowing remote code execution, and CVE-2024-39891, an information disclosure flaw in Twilio Authy.
KEV
πŸ›
Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins
πŸ›
Okta Browser Plugin Reflected Cross-Site Scripting CVE-2024-0981
πŸ›
Docker re-fixes a critical authorization bypass vulnerability
πŸ›
Docker Patches Critical AuthZ Plugin Bypass Vulnerability Dating Back to 2018
πŸ›
CVE-2024-39379 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
πŸ›
Chromium: CVE-2024-6988 Use after free in Downloads
πŸ›
Chromium: CVE-2024-6989 Use after free in Loader
πŸ›
Chromium: CVE-2024-6999 Inappropriate implementation in FedCM
πŸ›
Chromium: CVE-2024-6998 Use after free in User Education
πŸ›
Chromium: CVE-2024-6996 Race in Frames
πŸ›
Chromium: CVE-2024-6997 Use after free in Tabs
πŸ›
Chromium: CVE-2024-6994 Heap buffer overflow in Layout
πŸ›
Chromium: CVE-2024-6993
πŸ›
Chromium: CVE-2024-6995 Inappropriate implementation in Fullscreen
πŸ›
Chromium: CVE-2024-6992
πŸ›
Chromium: CVE-2024-7005 Insufficient validation of untrusted input in Safe Browsing
πŸ›
Chromium: CVE-2024-6991 Use after free in Dawn
πŸ›
Chromium: CVE-2024-7004 Insufficient validation of untrusted input in Safe Browsing
πŸ›
Chromium: CVE-2024-7003 Inappropriate implementation in FedCM
πŸ›
Chromium: CVE-2024-7001 Inappropriate implementation in HTML
πŸ›
Chromium: CVE-2024-7000 Use after free in CSS
πŸ›
CVE-2024-38103 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
πŸ›
Huge Increase in Scanning for CVE-2017-9841 With Large Variability in Scanning Infrastructure
πŸ›
Huge Increase in Scanning for CVE-2017-9841 With Large Variability in Scanning Infrastructure
⚠️
Explore Talent - 5,371,574 breached accounts
⚠️
How attackers evade your EDR/XDR system β€” and what you can do about it
⚠️
CISA Warns of Exploitable Vulnerabilities in Popular BIND 9 DNS Software
⚠️
Russia-Linked Brute-Force Campaign Targets EU via Microsoft Infrastructure
⚠️
XWorm Hidden With Process Hollowing, (Thu, Jul 25th)
⚠️
Fraudsters Abuse Legitimate Blockchain Protocols to Steal Your Cryptocurrency Wallet
⚠️
Researchers Reveal ConfusedFunction Vulnerability in Google Cloud Platform
⚠️
Project 2025 could escalate US cybersecurity risks, endanger more Americans
⚠️
Infisical: Open-source secret management platform - Help Net Security
⚠️
Major Russian Banks Hit with DDoS Attacks as Ukraine Claims Responsibility
⚠️
Microsoft’s Windows Hello for Business Flaw Let Attackers Bypass Authentication
⚠️
Tag-100 Hacker Group Exploiting Citrix NetScaler & F5 BIG-IP Vulnerabilities
⚠️
US CISA Urges BIND 9 Users to Address New DNS Exploits
⚠️
Anyone can Access Deleted and Private Repository Data on GitHub β—† Truffle Security Co.
⚠️
BIND Updates Resolve High-Severity DoS Vulnerabilities
⚠️
AI Accelerates Code Development Faster Than Security Teams can Keep up
⚠️
MS Patch Tuesday: Which Vulnerabilities Really Need Prioritizing. - Douglas McKee - PSW #836
⚠️
Crowdstrike: The Aftermath - PSW #836
⚠️
CISA Releases Two Industrial Control Systems Advisories
⚠️
Progress warns of critical RCE bug in Telerik Report Server
⚠️
FBI, CISA, and Partners Release Advisory Highlighting North Korean Cyber Espionage Activity
⚠️
ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions
⚠️
Critical ServiceNow RCE flaws actively exploited to steal credentials
KEV
⚠️
Cryptohack Roundup: Tornado Cash Sees Uptick in Use
⚠️
Chainguard Raises $140M to Drive AI Support, Global Growth
πŸ“‹
CrowdStrike Outage Losses Will Hit Healthcare, Banking Hard
πŸ“’
[Control systems] Siemens security advisory (AV24-417)
πŸ“’
Mitel security advisory (AV24-418)
πŸ“’
ISC BIND security advisory (AV24-419)
πŸ“’
Google Chrome security advisory (AV24-420)
πŸ“’
HPE security advisory (AV24-421)
πŸ“’
Your KnowBe4 Compliance Plus Fresh Content Updates from July 2024
πŸ”₯
Condo.com - 1,481,555 breached accounts
πŸ”₯
Phone Lines Down in Multiple Courts Across California After Ransomware Attack
πŸ”₯
Mandiant: North Korean Hackers Targeting Healthcare, Energy
πŸ”₯
Mandiant Shines Spotlight on APT45 Behind North Korea’s Digital Military Machine
πŸ”₯
North Korean Fake IT Worker FAQ
πŸ”₯
Data breach exposes US spyware maker behind Windows, Mac, Android and Chromebook malware
πŸ”₯
Pro-Palestinian Actor Levels 6-Day DDoS Attack on UAE Bank
πŸ”₯
North Korean Hackers Shift from Cyber Espionage to Ransomware Attacks
πŸ”₯
SEXi / APT Inc ransomware – what you need to know
πŸ”₯
US offers $10M for tips on DPRK hacker linked to Maui ransomware attacks
πŸ”₯
US Indicts Alleged North Korean Ransomware Attacker
πŸ”₯
CISO's True Role: It's Not About Preventing Every Breach! πŸ›‘οΈ #CyberSecurity #CISO
πŸ”₯
The CrowdStrike Outage and Market-Driven Brittleness
πŸ”₯
North Korean Charged in Ransomware Attacks on American Hospitals
πŸ”₯
Breach Roundup: ICANN Warns .top Domain About Phishing
πŸ”₯
Cybercrooks Continue to Capitalize on CrowdStrike Outage
πŸ”₯
Software Maker MCG Health Settles Data Breach Suit for $8.8M
πŸ”₯
UK Blood Stocks Drop After Ransomware Hack
πŸ•΅οΈ
MVP 14
πŸ•΅οΈ
ISC Stormcast For Thursday, July 25th, 2024 https://isc.sans.edu/podcastdetail/9068, (Thu, Jul 25th)
πŸ•΅οΈ
Ukraine Hackers Hit Major Russian banks with DDoS attacks
πŸ•΅οΈ
LW ROUNDTABLE: CrowdStrike outage reveals long road ahead to achieve digital resiliency
πŸ•΅οΈ
Google Boosts Chrome Protections Against Malicious Files
πŸ•΅οΈ
Nvidia Patches High-Severity Vulnerabilities in AI, Networking Products
πŸ•΅οΈ
LummaC2 Malware Using Steam Gaming Platform as C2 Server
πŸ•΅οΈ
Data Wallets Using the Solid Protocol
πŸ•΅οΈ
Network of 3,000 GitHub Accounts Used for Malware Distribution
πŸ•΅οΈ
APT45: North Korea’s Digital Military Machine
πŸ•΅οΈ
'Stargazer Goblin' Amasses Thousands of Rogue GitHub Accounts to Spread Malware
πŸ•΅οΈ
Unveiling the latest banking trojan threats in LATAM
πŸ•΅οΈ
Senator: Top Banks Only Reimburse 38% of Unauthorized Claims
πŸ•΅οΈ
Google Chrome Warns of Malicious Files While Downloading
πŸ•΅οΈ
KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware
πŸ•΅οΈ
Threat Actors Claiming Leak of IOC list with 250M Data, CrowdStrike Responded
πŸ•΅οΈ
Chainguard Raises $140 Million, Expands Tech to Secure AI Workloads
πŸ•΅οΈ
North Korean Hacker Group Targeting Healthcare, Energy Sectors
πŸ•΅οΈ
Major Russian banks hit with DDoS attacks as Ukraine claims responsibility
πŸ•΅οΈ
Robot dog trained to jam wireless devices during police raids
πŸ•΅οΈ
The Real Cost of Cybersecurity: A Money Talk πŸ’° | Business Security Weekly
πŸ•΅οΈ
Onyx Sleet uses array of malware to gather intelligence for North Korea
πŸ•΅οΈ
Proof of Concept: How Can We Outpace Deepfake Threats?
🌐
Echoes of Braodo Tales from the Cyber Underworld
🌐
6 Types of Applications Security Testing You Must Know About
🌐
Report: Malware Attacks Surge 30% in First Half of 2024
🌐
Network Of 3,000 GitHub Accounts Used For Malware Distribution
🌐
Hackers Bypass Windows SmartScreen Flaw To Launch Malware
🌐
French police push PlugX malware self-destruct payload to clean PCs
🌐
PKfail Secure Boot bypass lets attackers install UEFI malware
πŸ“‘
Hacker claims theft of Piramal Group’s employee data
πŸ“‘
New Chrome Feature Scans Password-Protected Files for Malicious Content
πŸ“‘
Phish-Friendly Domain Registry β€œ.top” Put on Notice
πŸ“‘
Webinar: Securing the Modern Workspace: What Enterprises MUST Know about Enterprise Browser Security
πŸ“‘
Lakera Raises $20 Million to Secure GenAI Applications
πŸ“‘
Meta Removes 63,000 Instagram Accounts Linked to Nigerian Sextortion Scams
πŸ“‘
Pro-Palestinian Actor Levels Six-Day DDoS Attack on UAE Bank
πŸ“‘
A shield of trust: managing cybersecurity risks through an evidence-based approach | Kaspersky official blog
πŸ“‘
Vanta Raises $150M Series C, Now Valued at $2.45B
πŸ“‘
Sophos MDR for Microsoft Defender: Gaining momentum with Microsoft-specific service enhancements
πŸ“‘
HHS Audit Finds Serious Gaps In Cloud Security At Agency Office
πŸ“‘
Why Multivendor Cybersecurity Stacks Are Increasingly Obsolete
πŸ“‘
TransparentTribe’s Spear-Phishing Targeting Indian Government Departments
πŸ“‘
The Automation Dilemma: Understanding the role of bots in your web apps and APIs
πŸ“‘
Live Webinar | Every Transaction Counts: How to Improve Your Payment Performanceβ€”and Your Bottom Line
πŸ“‘
Meta nukes massive Instagram sextortion network of 63,000 accounts
πŸ“‘
Windows 11 KB5040527 update fixes Windows Backup failures