115Articles
8Categories
2024-09-04Date
🚨
Russian Military Cyber Actors Target US and Global Critical InfrastructureSummary The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) assess that cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (…
KEV
🐛
Google Patches Actively Exploited Android 0-day Privilege Escalation Vulnerability
KEV
🐛
PoC Exploit Released For 0-Day Windows Kernel Privilege Escalation Vulnerability
🐛
Zyxel Warns of Critical OS Command Injection Flaw in Routers
🐛
Debian Patches Two Dovecot Vulnerabilities
🐛
Zyxel Patches Critical OS Command Injection Flaw in Access Points and Routers
🐛
Google Confirms CVE-2024-32896 Exploited in the Wild, Releases Android Security Patch
KEV
🐛
Google backports fix for Pixel EoP flaw to other Android devices
KEV
🐛
VMware Fixed a Code Execution Flaw in Fusion Hypervisor
🐛
VMWare releases Fusion vulnerability with 8.8 rating
🐛
Attackers are exploiting vulnerabilities at a record pace—here’s what to do about it
⚠️
6 things hackers know that they don’t want security pros to know that they know
KEV
⚠️
D-Link Says it is Not Fixing Four RCE Flaws in DIR-846W Routers
⚠️
Android’s September 2024 Update Patches Exploited Vulnerability
⚠️
White House Calls Attention to ‘Hard Problem’ of Securing Internet Traffic Routing
⚠️
Building a Culture of Email Security Awareness
⚠️
D-Link Warns of Code Execution Flaws in Discontinued Router Model
⚠️
Verkada to Pay $2.95 Million for Alleged CAN-SPAM Act Violations
⚠️
ToddyCat APT Abuses SMB, Exploits IKEEXT A Exchange RCE To Deploy ICMP Backdoor
⚠️
Security Flaw Allows Attackers to Clone YubiKeys by Extract Private Key
⚠️
Crypto Vulnerability Allows Cloning of YubiKey Security Keys
⚠️
Hackers Hijack 22,000 Removed PyPI Packages, Spreading Malicious Code to Developers
KEV
⚠️
Thousands of abandoned PyPI projects could be hijacked: Report
⚠️
Audit of Operator Fabric
⚠️
Threat Actors Increasingly Exploit Deepfakes for Social Engineering
⚠️
Scans for Moodle Learning Platform Following Recent Update, (Wed, Sep 4th)
⚠️
Deploying Rust in Existing Firmware Codebases
⚠️
Cisco warns of backdoor admin account in Smart Licensing Utility
⚠️
What asset management (ITAM) looks like outside cybersecurity - Jeremy Boerger - ESW #374
⚠️
Dutch regulator fines Clearview €30 million… or more
⚠️
‘Unusual’ Voldemort cyberespionage attack impersonates tax authorities
⚠️
Cisco fixes root escalation vulnerability with public exploit code
⚠️
US Targets Russian Media and Hackers Over Election Meddling
⚠️
New AlphV-like ransomware targets VMware ESXi servers
KEV
⚠️
News alert: INE Security releases a strategies guide for cyber threat preparedness, response capabilities
⚠️
Smashing Security podcast #383: The Godfather club, and AirTags to the rescue
📢
Clearview AI Faces €30.5M Fine for Building Illegal Facial Recognition Database
📢
Learning, Sharing, and Exploring with NIST’s New Human-Centered Cybersecurity Community of Interest
📢
HHS Drops Appeal of Hospital Web Tracking Decision
📢
Criminal IP Secures PCI DSS v4.0 Certification, Enhancing Payment Security with Top-Level Compliance
📢
Cisco security advisory (AV24-497)
📢
Drupal security advisory (AV24-498)
📢
Telegram Removes Deepfake Videos at South Korea's Behest
🔥
FBI Warns that North Korean Hackers Aggressively Attacking Employees of Crypto Companies
🔥
Halliburton Confirms that Hackers Stolen Data in Cyber Attack
🔥
Security Researcher Sued for Disproving Government Statements
🔥
Swan Bitcoin Alerts Users of Phishing Emails Carrying Fake Data Breach Notice
🔥
Record breaking Ransomware attacks on Schools and Colleges in 2023
🔥
Warning: New Emansrepo Malware Uses HTML Files to Target Windows Users
🔥
How Ransomware Groups Weaponize Stolen Data
🔥
Cicada Ransomware May Be A BlackCat/ALPHV Rebrand And Upgrade
🔥
Ransomware Gangs Pummel Southeast Asia
🔥
Emansrepo Stealer: Multi-Vector Attack Chains
🔥
Ransomware Crisis Deepens as Attacks and Payouts Rise
🔥
London Tube Riders Reporting Payment Difficulties After Hack
🔥
US Government Isn’t Ready for Cyber Chaos in the Food and Agriculture Sector
🔥
Specialize in Securing Critical Infrastructure
🔥
Microchip Technology confirms data was stolen in cyberattack
🕵️
Blackwired Launches ThirdWatch℠, A Paradigm Shift in Cybersecurity
🕵️
FTC: Over $110 million lost to Bitcoin ATM scams in 2023
🕵️
ISC Stormcast For Wednesday, September 4th, 2024 https://isc.sans.edu/podcastdetail/9124, (Wed, Sep 4th)
🕵️
White House Outlines Plan for Addressing BGP Vulnerabilities
🕵️
White House publishes latest plan to protect a key component of the internet: BGP
🕵️
Zyxel Patches Critical Vulnerabilities in Networking Devices
🕵️
INE Security Announces 5 Practical Steps to Elevate Cyber Defense Strategies
🕵️
CyberheistNews Vol 14 #36
🕵️
Crush It, Don’t Get Crushed — Combat SOC Analyst Burnout with AI
🕵️
Hackers Use Fake GlobalProtect VPN Software in New WikiLoader Malware Attack
🕵️
Revival Hijack supply-chain attack threatens 22,000 PyPI packages
🕵️
FBI: North Korea Aggressively Hacking Cryptocurrency Firms
🕵️
Criminal IP Earns PCI DSS v4.0 Certification for Top-Level Security
🕵️
FBI: North Korea Aggressively Hacking Cryptocurrency Firms
🕵️
[Security Masterminds Podcast] The Human Side of Cybersecurity: Bridging the Gap with Empathy and Strategy
🕵️
Aembit Named Finalist in Best Identity Management Solution for 2024 SC Awards
🕵️
Sanity check: Yubikeys and password shares
🕵️
North Korean Hackers Targets Job Seekers with Fake FreeConference App
🕵️
Microsoft Tackling Windows Logfile Flaws With New HMAC-Based Security Mitigation
🕵️
New Eucleak attack lets threat actors clone YubiKey FIDO keys
🕵️
DDoS Attacks Hit France Over Telegram's Pavel Durov Arrest
🕵️
News alert: Blackwired launches ‘ThirdWatch?’ — an advanced third-party risk management platform
🕵️
News alert: AI SPERA wins PCI DSS certification for its search engine solution ‘Criminal IP’
🕵️
AI Is Changing the Face of Fraud - And Fraud Fighting
🕵️
Hacker Heroes - Mark Loveless - PSW Vault
🕵️
Federal CIO Says Agencies on Track for Zero Trust Milestones
🕵️
Red team tool ‘MacroPack’ abused in attacks to deploy Brute Ratel
🕵️
Dutch Agency Fines Clearview AI 30M Euros for Data Scraping
🕵️
NSA Eyes Global Partnerships to Combat Chinese Cyberthreats
🌐
Hackers Use Fake GlobalProtect VPN Software in New WikiLoader Malware Attack
🌐
Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion
🌐
Spoofed GlobalProtect Used to Deliver Unique WikiLoader Variant
🌐
Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion
🌐
Is Your SIEM Ready for the AI Era? Essential Insights and Preparations
📡
Keeping up With Automated Threats is Becoming Harder
📡
AI Model Security Challenges: Financial and Healthcare Data
📡
Post-Quantum Cryptography Is Here: What Are You Waiting For?
📡
FTC: Over $110 Million Lost to Bitcoin ATM Scams in 2023
📡
The New Effective Way to Prevent Account Takeovers
📡
Three UK Men Convicted of Running Website Behind Fraud Calls During COVID-19 Lockdown
📡
Sextortion Scams Now Include Photos of Your Home
📡
Damn Vulnerable UEFI: Simulate Real-world Firmware Attacks
📡
VMware Fusion13.x Code Execution Bug Patched
📡
Ex-Senior New York State Staffer Charged In Cash-For-Favors Scandal With China
📡
Zyxel Patches Critical Vulns In Networking Devices
📡
White House Thinks It's Time To Fix The Insecure Glue Of The Internet: Yup, BGP
📡
Stop Scanning Random QR Codes
📡
Complying with PCI DSS Requirements by 2025
📡
Hackers inject malicious JS in Cisco store to steal credit cards, credentials
📡
Dutch Privacy Watchdog Fines Clearview AI $34 Million for ‘Illegal’ Database of Faces
📡
Quantum-resistant encryption and compatibility issues | Kaspersky official blog
📡
Travelers Targeted in New Booking.com Phishing Scam
📡
Initial Access Brokers Target $2bn Revenue Companies
📡
X is hiring staff for security and safety after two years of layoffs
📡
US cracks down on Russian disinformation before 2024 election
📡
Oswal: AI, Platformization Key to Network Security Evolution
📡
The key considerations for cyber insurance: A pragmatic approach