92Articles
10Categories
2024-08-23Date
🚨
SolarWinds fixes critical developer oversightSolarWinds has issued a hotfix to patch up a security oversight that could allow remote access to sensitive credentials hardcoded in its Web Help Desk (WHD) product. The vulnerability, tracked as CVE-2024-28987 , has been rated β€œcritical” with a CVSS score of 9.1 out of 10. β€œThe …
KEV
🚨
CISA Adds One Known Exploited Vulnerability to Catalog for Versa Networks DirectorCISA has added one new vulnerability to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-39717 Versa Director Dangerous File Type Upload Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cy…
KEV
πŸ›
Critical GitHub Enterprise Server Flaw Patched, Admin Access at Risk
πŸ›
PoC Exploit Released for RCE 0-day CVE-2024-41992 in Arcadyan FMIMG51AX000J Model
πŸ›
Microsoft Patches Critical Copilot Studio Vulnerability Exposing Sensitive Data
πŸ›
GitHub fixes critical Enterprise Server bug granting admin privileges
πŸ›
SonicWall Issues Urgent Patch for Critical Firewall Vulnerability
πŸ›
Chinese APT group Velvet Ant deployed custom backdoor on Cisco Nexus switches
πŸ›
WordPress users not on Windows urged to update due to critical LiteSpeed Cache flaw
πŸ›
Dell Power Manager Privilege Escalation Vulnerability
πŸ›
Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
⚠️
Equiniti settles SEC charges stemming from a pair of cyber intrusions
⚠️
Cybercriminals Exploit File Sharing Services to Advance Phishing Attacks
⚠️
SolarWinds Leaks Credentials in Hotfix for Exploited Web Help Desk Flaw
⚠️
New Opportunistic Campaign Exploit Log4j Vulnerability for Cryptomining and System Compromise
⚠️
The Trouble with Procurement Departments, Resellers and Stripe
⚠️
Main Line Health deploys chaos engineering to bolster healthcare resilience
KEV
⚠️
Leveraging Ancient Tactics for Modern Malware
⚠️
Google Chrome Update Fixes Flaw Exploited in the Wild
KEV
⚠️
Google Patches Ninth Chrome Zero Day Of 2024
⚠️
Kanister Vulnerability Opens Door to Cluster-Level Privilege Escalation
⚠️
PG_MEM Malware Targets PostgreSQL Databases for Crypto Mining
⚠️
US oil giant Halliburton confirms cyberattack behind systems shutdown
⚠️
Critical Vulnerabilities Uncovered in Progress WhatsUp Gold
⚠️
Secure Web Gateways Have Failed Us & Using AI to Prevent the Next CrowdStrike Outage -... - ESW #373
⚠️
Let’s Get Real About Where AI can Help SecOps & AI, Automation & Low-Code - Mike Lybor... - ESW #373
⚠️
Secure Web Gateways Have Failed Us & Using AI to Prevent the Next CrowdStrike Outage -... - ESW #373
⚠️
The Number of Email-Based Cyber Attacks Detected Surge 239% in 1H 2024
⚠️
American Radio Relay League confirms $1 million ransom payment
⚠️
Slack Patches Prompt Injection Flaw in AI Tool Set
⚠️
Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Remote Code Execution
⚠️
Cybersicherheitsvorschriften: So erfΓΌllen Sie Ihre Compliance-Anforderungen
⚠️
Chrome Zero-day Vulnerability Actively Exploited in the Wild
KEV
⚠️
Progress WhatsUp Gold Vulnerabilities Let Attackers Inject SQL Commands
KEV
πŸ“‹
Microsoft shares temp fix for Linux boot issues on dual-boot systems
πŸ“’
Microsoft Edge security advisory (AV24-476)
πŸ“’
SonicWall security advisory (AV24-477)
πŸ”₯
Popular search terms are leveraged in cyber attacks: Cyber Security Today for Friday, August 23, 2024
πŸ”₯
From Cybercrime to Terrorism, FBI Director Says America Faces Many Elevated Threats β€˜All at Once’
πŸ”₯
New Qilin Ransomware Attack Uses VPN Credentials, Steals Chrome Data
πŸ”₯
How Paris Olympic authorities battled cyberattacks, and won gold
πŸ”₯
Qilin Ransomware Caught Stealing Credentials Stored in Google Chrome
πŸ”₯
New macOS Malware "Cthulhu Stealer" Targets Apple Users' Data
πŸ”₯
Karakurt Ransomware Group Suspect Appears in US Courtroom
πŸ”₯
Halliburton shuts down systems after cyberattack
πŸ”₯
Medibank to Spend AU$126M on Post-Breach Security Upgrade
πŸ”₯
ISMG Editors: CISO Disclosure Rules Changing Post-SolarWinds
πŸ”₯
Feds to Health Sector: Don't Skimp on Physical Security
πŸ”₯
Banking Lobby Asks Ginnie Mae to Modify Cyber Reporting Rule
πŸ•΅οΈ
Surveillance Watch
πŸ•΅οΈ
ISC Stormcast For Friday, August 23rd, 2024 https://isc.sans.edu/podcastdetail/9110, (Fri, Aug 23rd)
πŸ•΅οΈ
New macOS Malware "Cthulhu Stealer" Targets Apple Users' Data
πŸ•΅οΈ
New macOS Malware TodoSwift Linked to North Korean Hacking Groups
πŸ•΅οΈ
FBI Exposing Sensitive Data via Improper Handling of Storage Devices: Audit
πŸ•΅οΈ
Russian Member of Karakurt Cyber Extortion Gang Charged in US
πŸ•΅οΈ
Take a Selfie Using a NY Surveillance Camera
πŸ•΅οΈ
Hacker Tried to Dodge Child Support by Breaking Into Registry to Fake His Death, Prosecutors Say
πŸ•΅οΈ
US, Allies Release Guidance on Event Logging and Threat Detection
πŸ•΅οΈ
Degraded Performance Issue Sparks Concern Among CrowdStrike Customers
πŸ•΅οΈ
Malvertising Campaign Impersonates Dozens of Google Products
πŸ•΅οΈ
Deceptive AI: A New Wave of Cyber Threats
πŸ•΅οΈ
Russian laundering millions for Lazarus hackers arrested in Argentina
πŸ•΅οΈ
Greasy Opal's CAPTCHA solver still serving cybercrime after 16 years
πŸ•΅οΈ
In Other News: FAA Improving Cyber Rules, Android Malware Enables ATM Withdrawals, Data Theft via Slack AI
πŸ•΅οΈ
Off-Topic Friday
πŸ•΅οΈ
Defenders Get A MoonPeak At North Korea's Malware Backbone
πŸ•΅οΈ
MoonPeak Malware From North Korean Actors Unveils New Details on Attacker Infrastructure
πŸ•΅οΈ
DOJ Lawsuit Accuses Georgia Tech of Cybersecurity Failures
πŸ•΅οΈ
The end of the road for some cyber startups & making detection actually work! - ESW #373
πŸ•΅οΈ
Faking your own death, Fake Reviews, Solar Winds, Recall, Winux, Kubernetes, and More - SWN #409
πŸ•΅οΈ
Business Email Compromise Scams Rise 20%, Making up Nearly Half of all Spam Emails
πŸ•΅οΈ
Friday Squid Blogging: Self-Healing Materials from Squid Teeth
🌐
Hardware Backdoor in Millions of Shanghai Fudan Microelectronics RFID Cards Allows Cloning
🌐
New PEAKLIGHT Dropper Deployed in Attacks Targeting Windows with Malicious Movie Downloads
🌐
Learn with Region 8’s Webinar Program
🌐
NGate Android Malware Relays NFC Traffic to Steal Credit Card Data
πŸŽ™οΈ
Episode 360 looks at fake Taylor Swift, Nvidia un the docs, TV ads and much more! | Kaspersky official blog
πŸ“‘
Latvian Hacker Extradited to U.S. for Role in Karakurt Cybercrime Group
πŸ“‘
Fraudulent Slack Ad Shows Malvertiser’s Patience and Skills
πŸ“‘
Focus on What Matters Most: Exposure Management and Your Attack Surface
πŸ“‘
New Phishing Campaign Targets US Government Organizations
πŸ“‘
Webinar: Experience the Power of a Must-Have All-in-One Cybersecurity Platform
πŸ“‘
Pandas Errors: What encoding are my logs in?, (Fri, Aug 23rd)
πŸ“‘
Local Networks Go Global When Domain Names Collide
πŸ“‘
SolarWinds Leaks Credentials In Hotfix
πŸ“‘
How To Manipulate The Execution Flow Of TOCTOU Attacks
πŸ“‘
How to hack wireless bicycle gears | Kaspersky official blog
πŸ“‘
Is AI Making Banking Safer or Just More Complicated?
πŸ“‘
Hackers now use AppDomain Injection to drop CobaltStrike beacons
πŸ“‘
New Windows 10 22H2 beta fixes memory leaks and crashes
πŸ“‘
A Tangled Web We Weave: When Reported M&A Never Materializes
πŸ“‘
PWA phishing on Android and iOS – Week in security with Tony Anscombe