107Articles
9Categories
2024-08-05Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2018-0824 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability These types of vulnerabilities are frequent attack vectors…
KEV
🐛
Critical Flaw in Rockwell Automation Devices Allows Unauthorized Access
🐛
Leaked Wallpaper Vulnerability Exposes Windows Users to Privilege Escalation Attacks
🐛
Increased Botnet Activity Against Apache OFBiz Exploiting CVE-2024-32113
🐛
Security Bypass Vulnerability Exposed in Rockwell Automation Logix Controllers
🐛
New Linux kernel cross-cache attack allows arbitrary memory writes
🐛
New critical Apache OFBiz vulnerability patched as older flaw is actively exploited
KEV
⚠️
Switcher’s guide to mesh VPNs: Pros, cons, and how to set up key features
⚠️
Beware Of New BingoMod Android Malware Steals Money And Formats Your Device
⚠️
Newly Identified BITSLOTH Backdoor Uses Novel C2 Communication Channel
⚠️
Threat Actor Abuses Trial Feature for Cloudflare Tunnels to Deliver RATs
⚠️
New NSA AI-powered Tool Would Help Industry Optimize Cyber Defense Testing
⚠️
Cisco Investments Backs Anti-Ransomware Firm Halcyon
⚠️
Design flaw has Microsoft Authenticator overwriting MFA accounts, locking users out
⚠️
Mirai Botnet Attacking Apache OFBiz Directory Traversal Vulnerability
⚠️
Hackers Abused StackExchange Platform To Deliuver Malicious Python Package
⚠️
Tech contractor exposes data of 4.6 million US voters
⚠️
Hackers Infect Windows With Backdoor Malware Via “Car For Sale” Ad
⚠️
Apache OFBiz Users Warned of New and Exploited Vulnerabilities
⚠️
Kazakh Organizations Targeted by 'Bloody Wolf' Cyber Attacks
⚠️
Cryptonator Seized for Laundering Ransom Payments, Stolen Crypto
⚠️
New SLUBStick Attack Makes Linux Kernel Vulnerabilities More Dangerous
⚠️
Linux Kernel Impacted by New SLUBStick Cross-Cache Attack
⚠️
Critical Vulnerability in Apache OFBiz Requires Immediate Patching
⚠️
North Korean hackers exploit VPN update flaw to install malware
⚠️
Windows Smart App Control, SmartScreen bypass exploited since 2018
⚠️
Brand Impersonation of Microsoft Increases 50% in One Quarter
⚠️
Google fixes Android kernel zero-day exploited in targeted attacks
⚠️
Shoe Zone - 46,140 breached accounts
📋
China-Linked Hackers Compromise ISP to Deploy Malicious Software Updates
📋
Chinese hacker group StormBamboo successfully hijacked an ISP's automatic software updates with backdoor malware and bad Chrome extensions to breach a downstream target
📋
Hackers Hijacked ISP Service Provider To Poison Software Updates
📋
Evasive Panda Compromises ISP to Distribute Malicious Software Updates
📋
CrowdStrike Outage Renews Supply Chain Concerns, Federal Officials Say
📢
US Senate Panel Advances Cyber Regulatory Harmonization Bill
📢
New Tech, Personnel Will Help CISA with Coming Rush of Cyber Incident Reports
📢
Australian Companies Will Soon Need to Report Ransom Payments
📢
The Loper Bright Decision: How it Impacts Cybersecurity Law
📢
Mozilla Follows Google in Distrusting Entrust’s TLS Certificates
📢
US Senate Confirms First DOD Cyber Policy Chief
🔥
Ransomware Attack Cost Keytronic Over $17 Million
🔥
Germany Summons Chinese Ambassador Over Cyberattack on Cartography Agency
🔥
Enhancing Incident Response Readiness with Wazuh
🔥
Mint-stealer Targeting web browsers, VPN clients & messaging apps to Steal Logins
🔥
Hackers directly email customers of immigration firm after damaging cyberattack
🔥
Threat Actor Claiming Breach of Gregory’s Foods 400Gb Database
🔥
Surge in Magniber Ransomware Attacks Impact Home Users Worldwide
🔥
Supply Chain Security Harm Reduction with 3TOFU
🔥
332 Million Email Addresses Scraped from SOCRadar.io Dumped Online
🔥
Supply Chain Security Harm Reduction with 3TOFU
🔥
Keytronic reports losses of over $17 million after ransomware attack
🔥
Organizations Fail to Log 44% of Cyberattacks, Major Exposure Gaps Remain
🔥
Low-Drama ‘Dark Angels’ Reap Record Ransoms
🔥
Ransomware gang targets IT workers with new SharpRhino malware
🕵️
ISC Stormcast For Monday, August 5th, 2024 https://isc.sans.edu/podcastdetail/9082, (Mon, Aug 5th)
🕵️
Authorities Seized Cryptonator Site & Charged the Admin
🕵️
Script obfuscation using multiple instances of the same function, (Mon, Aug 5th)
🕵️
Researchers Details How Hackers Can Steal Passwords via HDMI Cables
🕵️
Security+ SY0-701 Exam Cram Playlist - 2024 Edition
🕵️
Justice Department Sues TikTok, Accusing the Company of Illegally Collecting Children’s Data
🕵️
Fighting Ursa Luring Targets With Car for Sale
🕵️
Critical Infrastructure Group Launches Effort to Aid Federal Agencies’ Cyber Defenses
🕵️
Russian Threat Actors Hijacked Over 30,000 Domains in Sitting Ducks Attacks
🕵️
US Releases Russian Hackers and Spies as Part of Prisoner Swap
🕵️
Exodus Underground Market Place Emerging As A Heaven For Cybercriminals
🕵️
New Patent Application for Car-to-Car Surveillance
🕵️
Beware Of Fake AI Editor Website That Steals Your Login Credentials
🕵️
Mentorship Monday - Discussions for career and learning!
🕵️
China's APT41 Targets Taiwan Research Institute for Cyber Espionage
🕵️
Threat Actor Allegedly Claims Leak of SisaCloud Database
🕵️
New LianSpy Attacking Android Users to Steal Sensitive Data
🕵️
Researchers Uncover Flaws in Windows Smart App Control and SmartScreen
🕵️
AI in the Enterprise: Cutting Through the Hype and Assessing Real Risks
🕵️
Chinese Hackers Deliver Malware via ISP-Level DNS Poisoning
🕵️
Former NSA Director Paul Nakasone Joins Ballistic Ventures as Strategic Advisor
🕵️
Black Hat Fireside Chat: Token’s wearable MFA solution combines PKI, biometrics — in a ring
🕵️
Chinese Hackers Deliver Malware Via ISP-Level DNS Poisoning
🕵️
Creating a Big Security Culture With a Tiny Button
🕵️
AWS Deploying ‘Mithra’ Neural Network to Predict and Block Malicious Domains
🕵️
Say Easy, Do Hard - Job Search Strategies for CISOs - Part 1 - Merlin Namuth, Brad Rager - BSW #359
🕵️
Say Easy, Do Hard - Job Search Strategies for CISOs - Part 2 - Merlin Namuth, Brad Rager - BSW #359
🌐
New Android Trojan "BlankBot" Targets Turkish Users' Financial Data
🌐
New LianSpy spyware targets Android smartphones | Kaspersky official blog
🌐
Tech Support Scam Ring Leader Gets Seven Years in Prison, $6M Fine
🌐
Airlines are Flying Blind on Third-Party Risks
🌐
Ongoing DEV#POPPER Malware Campaign Expands Targeting
🌐
New BlankBot Android Malware Targets Users' Banking Data
🌐
New LianSpy malware hides by blocking Android security feature
📡
Industry Moves for the week of August 5, 2024 - SecurityWeek
📡
New Discord DDoS Campaign Called Panamorfi Targets Vulnerable Jupyter Notebooks
📡
FBI Warns of Scammers Posing as Crypto Exchange Employees
📡
Cybersecurity Innovator Clutch Security Nets $8.5m in Funding Led by Lightspeed
📡
Protect AI Raises $60M in Series B Financing
📡
AWS launches Mithra to identify and mitigate malicious domains across its massive system
📡
Upgrading your Sophos Firewall from XG to XGS
📡
Countdown is on: Last chance for discount registration at Mandiant’s mWISE 2024
📡
White House Officials Meet with Allies, Industry on Connected Car Risks
📡
US Sues TikTok for Violating Children Privacy Protection Laws
📡
New SLUBStick Attack Makes Linux Kernel Vulnerabilities More Dangerous
📡
Ukraine Steps Up Cyberwar With DDoS On Russian Banks
📡
SnakeKeylogger Slithers Into Windows Inboxes To Steal Secrets
📡
Israeli Hacktivist Group Claims it Took Down Iran’s Internet
📡
More Legal Records Stolen in 2023 Than Previous 5 Years Combined
📡
Microsoft Bounty Program Year in Review: $16.6M in Rewards
📡
Crowdstrike: Delta Air Lines refused free help to resolve IT outage
📡
Microsoft Azure outage takes down services across North America
📡
Microsoft Bounty Program Year in Review: $16.6M in Rewards