107Articles
9Categories
2024-08-20Date
🚨
CISA Adds Jenkins CLI Bug to its Known Exploited Vulnerabilities CatalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Jenkins Command Line Interface (CLI) Path Traversal vulnerability, known as CVE-2024-23897 with a CVSS score of 9.8, to its Known Exploited Vulnerabilities catalog.
KEV
πŸ›
CISA Warns of Critical Jenkins Vulnerability Exploited in Ransomware Attacks
KEV
πŸ›
Autodesk AutoCAD Vulnerability Let Attackers Execute Arbitrary Code
πŸ›
Unauthenticated RCE in WordPress Plugin Exposes 100,000 WordPress Sites
πŸ›
CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
πŸ›
Where are we with CVE-2024-38063: Microsoft IPv6 Vulnerability, (Tue, Aug 20th)
πŸ›
Hackers use PHP exploit to backdoor Windows systems with new malware
πŸ›
CVE-2024-38175 Azure Managed Instance for Apache Cassandra Elevation of Privilege Vulnerability
πŸ›
Windows Downdate: exploitation techniques and countermeasures
⚠️
Thousands of Oracle NetSuite Sites at Risk of Exposing Customer Information
⚠️
Windows 0-day was exploited by North Korea to install advanced rootkit
⚠️
Blind Eagle Hackers Exploit Spear-Phishing to Deploy RATs in Latin America
⚠️
How CISOs can tackle the pernicious problem of poisoned packages
⚠️
apps .. repo or not
⚠️
Cybercriminals Exploit Paris Olympics With Fake Domains
⚠️
Microsoft Mandates MFA for all Azure Sign-Ins
⚠️
CISOs urged to prepare now for post-quantum cryptography
KEV
⚠️
Update: Ransomware Attack on Indian Payment System Traced Back to Jenkins Bug
⚠️
Authentik: Open-Source Identity Provider
⚠️
Hackers Exploit PHP Vulnerability to Deploy Stealthy Msupedge Backdoor
⚠️
Anatomy of an Attack
⚠️
Researchers Uncover TLS Bootstrap Attack on Azure Kubernetes Clusters
⚠️
No Deal: Action1 Rebuffs CrowdStrike's Interest in $1B Buy
⚠️
Critical Jenkins vulnerability added to CISA’s known vulnerabilities catalog
⚠️
Cisco, Microsoft Disagree on Severity of macOS App Vulnerabilities
⚠️
Tech giants warn proposed Hong Kong cyber rules could undermine digital economy
⚠️
x64dbg: Open-Source Binary Debugger for Windows
⚠️
Cybercriminals Exploit Popular Software Searches to Spread FakeBat Malware
⚠️
Phrack Magazine Issue 71
⚠️
US government accuses Iran of Trump campaign hack; Iran scoffs
⚠️
Windows Zero-Day Attack Linked To North Korea's Lazarus APT
⚠️
Critical Jenkins Vulnerability Added To CISA's Known Vulnerabilities Catalog
⚠️
Iran Named As Source Of Trump Campaign Phish, Leaks
⚠️
Critical Flaw in Donation Plugin Exposed 100,000 WordPress Sites to Takeover
⚠️
Navigating the Path to Maturity & AI is helping combat cyber threats - Shimon Modi, Bo... - ASW #296
⚠️
North Korea Exploited Windows Zero-Day to Deploy Fudmodule
⚠️
Microchip Technology discloses cyberattack impacting operations
⚠️
Data Exfiltration from Slack AI via indirect prompt injection
⚠️
Best Practices for Event Logging and Threat Detection
πŸ“‹
August Windows updates break dual boot on some Linux systems
πŸ“‹
August Windows security update breaks dual boot on Linux systems
πŸ“’
FBI and CISA Assure Public on Election Ransomware Security
πŸ“’
Update: US Agencies Attribute Presidential Campaign Cyberattacks to Iran
πŸ“’
CISA to Get New $524 Million Headquarters in DC, Backed by Inflation Reduction Act Funding
πŸ“’
UK: NCSC Opens Cyber Resilience Audit Scheme to Applicants
πŸ“’
Balancing AI Regulation: Comprehensive vs. Targeted Approach
πŸ“’
Cybersecurity Is Everywhere: ENISA COO
πŸ“’
News alert: INE Security advisory: The steep cost of neglecting cybersecurity training
πŸ”₯
US Bipartisan Committee Urges Investigation Into Chinese Wi-Fi Routers
πŸ”₯
Ransomware Victims Paid $460 Million in First Half of 2024
πŸ”₯
MegaMedusa, Highly Scalable Web DDoS Attack Tool Used By Hacker Groups
πŸ”₯
Cost of a data breach: The industrial sector
πŸ”₯
Ransomware Resilience Drives Down Cyber Insurance Claims
πŸ”₯
Common API Security Issues: From Exposed Secrets To Unauthorized Access
πŸ”₯
Russia-linked Vermin Hackers Target Ukraine With new Malware Strain
πŸ”₯
Hacker locks Unicoin staff out of Google accounts for 4 days
πŸ”₯
The Fallout and Lessons Learned from the CrowdStrike Fiasco - Allie Mellen, Jeff Pollard - ASW #296
πŸ”₯
Oregon Zoo warns visitors their credit card details were stolen
πŸ”₯
Ransomware Trends: Most Attacks Hit Between 1am and 5am, Study Finds
πŸ”₯
McLaren Health Expects IT Disruption to Last Through August
πŸ”₯
How Ransomware Group Stability Affects Payment Decisions
πŸ”₯
CannonDesign confirms Avos Locker ransomware data breach
πŸ•΅οΈ
Identity Protection That Spans the Entire Attack Lifecycle
πŸ•΅οΈ
US Intelligence Officials Say Iran is to Blame for Hacks Targeting Trump, Biden-Harris Campaigns
πŸ•΅οΈ
ISC Stormcast For Tuesday, August 20th, 2024 https://isc.sans.edu/podcastdetail/9104, (Tue, Aug 20th)
πŸ•΅οΈ
NEWS ANALYSIS Q&A: The early going of Generative AI and LLMs impacting cybersecurity
πŸ•΅οΈ
Iranian Cyber Group TA453 Targets Jewish Leader with New AnvilEcho Malware
πŸ•΅οΈ
2GB variant of Raspberry Pi Launched for Just $50
πŸ•΅οΈ
Hacking Wireless Bicycle Shifters
πŸ•΅οΈ
How Exceptional CISOs Are Igniting the Security Fire in Their Development Team
πŸ•΅οΈ
F5 Patches High-Severity Vulnerabilities in BIG-IP, NGINX Plus
πŸ•΅οΈ
How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions
πŸ•΅οΈ
US warns of Iranian hackers escalating influence operations
πŸ•΅οΈ
Fabric Cryptography Raises $33 Million for VPU Chip
πŸ•΅οΈ
Digital Wallets Bypassed To Allow Purchase With Stolen Cards
πŸ•΅οΈ
Backdoor MIFARE Smart Cards Exposes User-Defined Keys On Cards
πŸ•΅οΈ
CyberheistNews Vol 14 #34 [HEADS UP] Real Social Engineering Attack on KnowBe4 Employee Foiled
πŸ•΅οΈ
New Styx Stealer Attacking Users to Steal Login Passwords
πŸ•΅οΈ
Are You Vulnerable to Deep Fakes? Controlling the Risk - Paul Neff - CSP #188
πŸ•΅οΈ
Major Backdoor in Millions of RFID Cards Allows Instant Cloning
πŸ•΅οΈ
Dangerous books, Microsoft plus, NPD, Solar Winds, Jenkins, and more... - SWN #408
πŸ•΅οΈ
Darktrace Co-founder Mike Lynch Presumed Dead After Superyacht Sinks
πŸ•΅οΈ
CISOs on the Hook: SEC Tightens Cybersecurity Disclosures
πŸ•΅οΈ
California AI Catastrophe Bill Clears Committee
πŸ•΅οΈ
Addressing the OT SOC Challenges in Industrial Environments
πŸ•΅οΈ
Real-Time Deepfakes: A Growing Threat to Corporate Security
🌐
New UULoader Malware Distributes Gh0st RAT and Mimikatz in East Asia
🌐
Implementation Challenges in Privacy-Preserving Federated Learning
🌐
MIFARE Classic: exposing the static encrypted nonce variant... and a few hardware backdoors
πŸ“‘
Ukrainian Bank's Service for Military Donations Targeted by β€˜Massive’ DDoS Attack
πŸ“‘
Multiple Microsoft Apps for macOS Vulnerable to Library Injection Attacks
πŸ“‘
Sophos NDR 1.7 is now available
πŸ“‘
Chrome Will Redact Credit Cards, Passwords When You Share Android Screen
πŸ“‘
Xeon Sender Enables Large-Scale SMS Spam Attacks Using Legitimate SaaS Providers
πŸ“‘
Digital Wallets can Allow Purchases With Stolen Credit Cards
πŸ“‘
OpenAI Kills Iranian Accounts Spreading Us Election Disinformation
πŸ“‘
OpenAI Killed Iranian Accounts Using ChatGPT To Write Election Disinfo
πŸ“‘
Critical Flaw In Donation Plugin Exposed 100,000 WordPress Sites To Takeover
πŸ“‘
Digital Wallets Can Allow Purchases With Stolen Credit Cards
πŸ“‘
Hackers Linked to $14M Holograph Crypto Heist Arrested in Italy
πŸ“‘
To Improve Your Cybersecurity Posture, Focus on the Data
πŸ“‘
Free ZTNA licenses for Sophos Firewall customers
πŸ“‘
Africa's Economies Feel Pain of Cybersecurity Deficit
πŸ“‘
Microsoft launches unified Teams app for personal, work accounts
πŸ“‘
Cisco employees face a month of silence ahead of second layoff in 2024
πŸ“‘
Be careful what you pwish for – Phishing in PWA applications
πŸ“‘
Shaping the legacy of partnership between government and private sector globally: JCDC