85Articles
6Categories
2024-08-09Date
🐛
MongoDB Vulnerabilities Let Attackers Escalate Privileges
🐛
Critical 1Password flaws may allow hackers to snatch your passwords (CVE-2024-42219, CVE-2024-42218)
🐛
5 key takeaways from Black Hat USA 2024
⚠️
A Dive into Earth Baku’s Latest Campaign
⚠️
CISA Warns of Hackers Exploiting Legacy Cisco Smart Install Feature
⚠️
One of the largest data breaches in history? Cyber Security Today for Friday, August 9th, 2024
⚠️
Hackers Exploit iOS Settings to Trigger Fake iOS Updates on Hijacked Devices
⚠️
Exclusive: CrowdStrike eyes Action1 for $1B amid fallout from Falcon update mishap
⚠️
Windows Zero-day Flaw Let Hackers Downgrade Fully Updated Systems To Old Vulnerabilities
⚠️
GhostWrite Vulnerability Let Hackers Read And Write Any Part Of The Computer’s Memory
⚠️
Researchers Unveil AWS Vulnerabilities, New 'Shadow Resource' Attack Vector
⚠️
Vulnerability Allowed Eavesdropping via Sonos Smart Speakers
⚠️
OpenWrt Dominates, but Vulnerabilities Persist in OT/IoT Router Firmware
⚠️
RustScan: Open-Source Port Scanner
⚠️
6 IT risk assessment frameworks compared
⚠️
Not SOCRadar - 282,478,425 breached accounts
⚠️
Ransomware Drill Targets Healthcare in Operation 911
⚠️
CISA Warns of Cisco Smart Install Feature Actively Exploited by Hackers
KEV
⚠️
Phishing Attack Exploits Google, WhatsApp to Steal Data
⚠️
New Ransomware Groups Emerge Despite Crackdowns
⚠️
Critical Jenkins Vulnerabilities Expose Servers To RCE Attack
⚠️
Warnings Issued Over Cisco Device Hacking, Unpatched Vulnerabilities
⚠️
Confusion Attacks Vulnerability In Apache HTTP Server Allow Attackers To Gain Root Access Remotely
⚠️
North Korean Kimusky Group Attacking University Professors
⚠️
0.0.0.0 Day – 18 Yr Old Vulnerability Allow Attackers to Bypass All Browser Security
⚠️
Threat Actors Exploiting Windows Systems To Deploy Multiple Malwares
⚠️
New Flaws in Sonos Smart Speakers Allow Hackers to Eavesdrop on Users
⚠️
CrowdStrike Dismisses Claims Of Vulnerability In Falcon Sensor Bug
⚠️
Malware force-installs Chrome extensions on 300,000 browsers, patches DLLs
⚠️
Microsoft discloses Office zero-day, still working on a patch
⚠️
AI Red Teaming and AI Safety - Amanda Minnich - ESW #371
⚠️
New AMD SinkClose flaw helps install nearly undetectable malware
⚠️
CSC ServiceWorks discloses data breach after 2023 cyberattack
⚠️
Microsoft Reveals Four OpenVPN Flaws Leading to Potential RCE and LPE
⚠️
[WHOA] - This 'Unpatch Attack' Is A New One To Me!
⚠️
Microsoft discloses unpatched Office flaw that exposes NTLM hashes
📢
CISA Releases Guide to Enhance Software Security Evaluations
📢
Consumer Reports Study Finds Data Removal Services are Often Ineffective
📢
Leaked MDM Credentials Exposes Commonly Laptops And Smartphones For Hacking
📢
HPE security advisory (AV24-446)
📢
F5 security advisory (AV24-447)
📢
Microsoft Edge security advisory (AV24-448)
📢
Russia blocks Signal for 'violating' anti-terrorism laws
🔥
DISPOSSESSOR And RADAR Ransomware Emerging With RaaS Model
🔥
Ransomware Attack Costs loanDepot Almost $27 Million
🔥
Physical Security Firm ADT Confirms Hack and Data Breach
🔥
Russian cyber spies stole data and emails from UK government systems
🔥
Number of Incidents Affecting GitHub, Bitbucket, GitLab, and Jira Continues to Rise
🔥
How to Weaponize Microsoft Copilot for Cyberattackers
🔥
Paris Olympics Deal With Ransomware Attack
🔥
How a cybersecurity researcher befriended, then doxed, the leader of LockBit ransomware gang
🔥
Ecovacs home robots can be hacked to spy on their owners, researchers say
🕵️
ISC Stormcast For Friday, August 9th, 2024 https://isc.sans.edu/podcastdetail/9090, (Fri, Aug 9th)
🕵️
Authorities Dismantled North Korean Remote IT Worker Laptop Farm
🕵️
DOJ Charges Nashville Man for Helping North Koreans Get U.S. Tech Jobs
🕵️
Microsoft researchers report Iran hackers targeting US officials before election
🕵️
Delta: CrowdStrike’s offer for help too little, too late
🕵️
[Crosspost from !appsec] Looking for a new training/certification. People who did OSWA (Web-200 by OffSec), how was it?
🕵️
New APT Actor240524 Weaponizing Official Documents To Deliver Malware
🕵️
Off-Topic Friday
🕵️
Iranian Hackers Targeting 2024 US Election Campaigns
🕵️
US Offers $10 Million for Information on Iranian Hackers Behind CyberAv3ngers Water Utility Attacks
🕵️
People-Search Site Removal Services Largely Ineffective
🕵️
In Other News: KnowBe4 Product Flaws, SEC Ends MOVEit Probe, SOCRadar Responds to Hacking Claims
🕵️
Iran Is Accelerating Cyber Activity That Appears Meant to Influence the US Election, Microsoft Says
🕵️
More AI funding, Crowdstrike ripples continue, GPT yourself - ESW #371
🕵️
Interviewing Black Hat Startup Spotlight Winner, Knostic - Sounil Yu - ESW #371
🕵️
0.0.0.0, Blacksuit, OpenAI, AWS, Cisco Phones, Win 10, Aaran Leyland, and More... - SWN #405
🕵️
Friday Squid Blogging: SQUID Is a New Computational Tool for Analyzing Genomic AI
🕵️
Not Just Us: North Korean Remote IT Fraudster Arrested in Tennessee
🕵️
512-bit RSA key in home energy system gives control of “virtual power plant” - sh.itjust.works
🕵️
A Whopping 33% of Young American Are Exposed to Political Lies on TikTok
🕵️
How can 2FA be disabled without permission and what can I do about it?
📡
Ireland's DPC Takes Twitter to Court Over AI User Data Concerns
📡
Russia's Kursk Region Suffers ‘Massive’ DDoS Attack Amid Ukraine Offensive
📡
Sports Venues Must Vet Their Vendors to Maintain Security
📡
FTX Ordered To Pay $12.7 Billion To Customers
📡
Pro-Iran Groups Lay Groundwork For Chaos And Violence As US Election Meddling Intensifies
📡
512-bit RSA Key In Home System Gives Control Of Virtual Power Plant
📡
0.0.0.0 Day Browser Flaw Enables Malicious Requests To Local Networks
📡
SEC Takes No Action On Progress MOVEit Transfer Case
📡
Phishing-as-a-Service through Telegram bot
📡
How to ask Google to remove deepfake porn results from Google Search
📡
Black Hat USA 2024 recap – Week in security with Tony Anscombe
📡
Black Hat USA 2024: All eyes on election security