110Articles
9Categories
2024-07-30Date
🚨
Critical ServiceNow vulnerabilities expose businesses to data breachesThree critical vulnerabilities in the ServiceNow IT service management platform have been disclosed and reported to have been under active exploitation. The vulnerabilities have exposed sensitive information from over 105 organizations including government agencies, data centers,…
KEV
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-37085 VMware ESXi Authentication Bypass Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber acto…
KEV
🐛
VMware ESXi Flaw Exploited by Ransomware Groups for Admin Access
KEV
🐛
RaspAP Flaw Let Hackers Escalate Privileges with Raspberry Pi Devices
🐛
Critical OpenSSH “regreSSHion” Vulnerability Impacted macOS  Systems, Patch Now
🐛
Progress Patched New MOVEit File Transfer Flaw that Allows Privilege Escalation
⚠️
CrowdStrike crisis gives CISOs opportunity to rethink key strategies
⚠️
Microsoft Warns of Ransomware Gangs Abusing VMware ESXi Authentication Bypass in Attacks
⚠️
Hackers Exploiting ESXi Hypervisor Auth Bypass Flaw For Ransomware Attacks
⚠️
Proofpoint’s Email Protection Let Attackers Send Millions Of Phishing Emails
⚠️
NIST Releases Open Source Platform For AI Security Testing
⚠️
Hackers Exploit VMware Vulnerability That Gives Them Hypervisor Admin
⚠️
Heap exploitation, glibc internals and nifty tricks.
⚠️
Study: Average Cost of a Data Breach Rises to $4.9 Million
⚠️
Driving the Business of Infosec Through the GRC Program - Greg Bee - CSP #185
⚠️
Massive Phishing Campaign Exploiting Proofpoint’s Email Protection to Dispatch Millions of Perfectly Spoofed Emails
⚠️
Apple Releases Security Updates for Multiple Products
⚠️
SAFECOM Releases New Resource for Cloud Adoption
⚠️
Cirrus: Open-source Google Cloud forensic collection - Help Net Security
⚠️
Phishers exploited Proofpoint weakness to spoof emails from IBM, Nike, and more
⚠️
AI-Powered Deepfake Tools Becoming More Accessible Than Ever
⚠️
Ransomware Gangs Exploit VMware ESXi Flaw
⚠️
CISA warns of VMware ESXi bug exploited in ransomware attacks
⚠️
Lineaje raises $20M to help organizations combat software supply chain threats
⚠️
Ubook - 699,908 breached accounts
⚠️
CyberRiskTV Live Coverage from BlackHat 2024 - Day 2
⚠️
Improving the security of Chrome cookies on Windows
📋
Apple Rolls Out Security Updates for iOS, macOS
📋
Providing Security Updates to Automobile Software
📢
Apple security advisory (AV24-428)
📢
The Power and Peril of RMM Tools
📢
The AI Fix #9: When AI detectors fail (spectacularly), and OpenAI’s five steps to Skynet
📢
Google Cloud CISO Phil Venables: ‘I’m short-term pessimistic, long-term optimistic’
📢
HPE security advisory (AV24-429)
📢
AI Pulse: Brazil Gets Bold with Meta, Interpol’s Red Flag & more
📢
Forever mouse, RPC, WhatsApp, NIST, PKFail, 0Auth, Josh Marpet, and More... - SWN #402
📢
GUEST ESSAY: CrowdStrike outage fallout — stricter regulations required to achieve resiliency
📢
DigiCert Certificate Revocations
🔥
New SideWinder Cyber Attacks Target Maritime Facilities in Multiple Countries
🔥
Surging data breach disruption drives costs to record highs
🔥
Threat Actor Allegedly Claiming Breach of Cyepr
🔥
Threat Actor Allegedly Claiming Hack of Microsoft Employee’s Device
🔥
Ukraine Claims Cyber Attack Disrupted Russian ATMs and Banking System
🔥
UK govt links 2021 Electoral Commission breach to Exchange server
🔥
40 Million UK Voters Hacked Due To Security Lapses
🔥
ubook Suffered Data Breach, 710,000 Users’ Data Exposed
🔥
The State of Ransomware in Healthcare 2024
🔥
HealthEquity data breach affects 4.3 million people
🔥
Change Healthcare Begins to Notify Millions Affected by Hack
🔥
How a Rapid Response Update Broke 8 Million Laptops!
🔥
Columbus investigates whether data was stolen in ransomware attack
🔥
News Alert: Adaptive Shield to showcase new ITDR platform for SaaS at Black Hat USA
🔥
Organizations Prepare for More Evolved AI-Based Cyber Attacks as Deepfakes Become Top Concern
🔥
Dark Angels Ransomware Group Scores Record-Breaking $75 Million Payday
🔥
Trellix's Dual AI Strategy: Combating and Using AI in Cyber
🔥
Judge Allows Lawsuit Against EHR Vendor in Hack to Proceed
🔥
Black Basta ransomware switches to more evasive custom malware
🔥
Dark Angels ransomware receives record-breaking $75 million ransom
🔥
Spytech - 5,645 breached accounts
🕵️
ISC Stormcast For Tuesday, July 30th, 2024 https://isc.sans.edu/podcastdetail/9074, (Tue, Jul 30th)
🕵️
DigiCert to Revoke Thousands of Certificates Following Domain Validation Error
🕵️
ZeroTier Raises $13.5 Million in Series A Funding
🕵️
Cyber Insurance Provider Cowbell Raises $60 Million
🕵️
Thousands Download New Mandrake Android Spyware Version From Google Play
🕵️
Hacker Attacking Bank Users With AI-powered Phishing Tools and Android Malware
🕵️
AcidPour Malware Attacking Linux Data Storage Devices To Wipe Out Data
🕵️
Cyber Threat Intelligence: Illuminating the Deep, Dark Cybercriminal Underground
🕵️
SocGholish Malware Attacking Windows Users Using Fake Browser Update
🕵️
1 million HotJar users vulnerable to XSS attacks
🕵️
'Zeus' Hacker Group Strikes Israeli Olympic Athletes in Data Leak
🕵️
Walmart Discovers New PowerShell Backdoor Linked to Zloader Malware
🕵️
CyberheistNews Vol 14 #31 How The Whole World Now Knows About Fake North Korean IT Workers
🕵️
Indian APT Targeting Mediterranean Ports and Maritime Facilities
🕵️
AI, Cybersecurity Top Investment Areas for Industrial Organizations: Cisco
🕵️
Software Supply Chain Security Firm Lineaje Raises $20M in Series A Funding
🕵️
A CISO's Perspective on AI, Appsec, and Changing Behaviors - Paul Davis - ASW #293
🕵️
ADHD Struggles in Cybersecurity & Security News Roundup
🕵️
SideWinder Utilizes New Infrastructure to Target Ports and Maritime Facilities in the Mediterranean Sea
🕵️
New Phishing Kit Uses Voice Call Generator to Impersonate Spanish Banks
🕵️
Account Takeover Fraud Declines in Financial Services
🕵️
Meta Prompt Guard Is Vulnerable to Prompt Injection Attacks
🕵️
New Microsoft whitepaper shares how to prepare your data for secure AI adoption
🕵️
CyberRiskTV Live Coverage from BlackHat 2024 - Day 1
🕵️
CyberRiskTV Live Coverage from BlackHat 2024 - Day 3
🌐
Live Webinar Today | Accelerate your SOC with AI-driven security analytics with Elastic and Google Cloud
🌐
OneDrive Phishing Scam Tricks Users into Running Malicious PowerShell Script
🌐
Malware Campaign Lures Users With Fake W2 Form
🌐
Cybercriminals Target Polish Businesses with Agent Tesla and Formbook Malware
🌐
New Mandrake Spyware Found in Google Play Store Apps After Two Years
🌐
Crafty ClickFix-Style Phishing Campaign Targets Microsoft OneDrive Users
🌐
New PowerShell Backdoor Linked to Zloader Malware
🌐
Google Chrome adds app-bound encryption to block infostealer malware
🌐
Massive SMS stealer campaign infects Android devices in 113 countries
🌐
Phishing targeting Polish SMBs continues via ModiLoader
📡
Microsoft 365 Users Targeted by Phishers Abusing Microsoft Forms
📡
Attackers Bypassed Google’s Email Verification to Create Workspace Accounts, Access Third-Party Services
📡
Hotjar, Business Insider Vulnerabilities Expose OAuth Data Risks
📡
US Senators Turn Up Heat On Automakers Over Sale Of Driver Data
📡
Malaysia Is Working On An Internet Kill Switch
📡
Fake leaks of passwords and seed phrases are scammers' new weapons | Kaspersky official blog
📡
Microsoft 365 and Azure outage takes down multiple services
📡
Is your password policy working? Key cybersecurity KPIs to measure
📡
DigiCert mass-revoking TLS certificates due to domain validation bug
📡
European Central Bank Concludes Banking Cyber Stress Test
📡
Cowbell Secures $60 Million Series C Funding From Zurich Insurance Group
📡
US State Department Says UN Cybercrime Treaty Must Include Human Rights Protections
📡
Meta's AI Safety System Manipulated by Space Bar Characters to Enable Prompt Injection
📡
Apple Patches Everything. July 2024 Edition, (Tue, Jul 30th)
📡
It took some serious nerve for Wiz to walk away from Google’s $23B offer
📡
Israeli athletes doxed at Olympic Games by Zeus hacking group