92Articles
9Categories
2024-09-11Date
๐Ÿšจ
CISA adds SonicWall SonicOS, ImageMagick,ย and Linux Kernel Bugs to its Known Exploited Vulnerabilities catalog. The ImageMagick vulnerability (CVE-2016-3714) could allow remote code execution through crafted images. Linux Kernel flaw (CVE-2017-1000253) enables privilege escalation for unpatched systems.
KEV
๐Ÿ›
Ivanti Releases Urgent Security Updates for Endpoint Manager Vulnerabilities
๐Ÿ›
FreeBSD Issues Urgent Security Advisory for CVE-2024-43102 (CVSS 10)
๐Ÿ›
Microsoft warns of bug reversing updates on old Windows 10, patches critical flaws
๐Ÿ›
Critical Command Injection Flaw in Zyxel NAS Devices, Hotfixes Released for End-of-Support Products
๐Ÿ›
Siemens Industrial Edge Management Vulnerable to Authorization Bypass Attacks
๐Ÿ›
Siemens Issues Critical Security Advisory for User Management Component (UMC)
๐Ÿ›
Researchers Hacked Car EV Chargers To Execute Arbitrary Code
โš ๏ธ
Bug Left Some Windows PCs Dangerously Unpatched โ€“ Krebs on Security
โš ๏ธ
Opus Security Elevates Vulnerability Management With its AI-Powered Multi-Layered Prioritization Engine
โš ๏ธ
Immediate threats or long-term security? Deciding where to focus is the modern CISOโ€™s dilemma
โš ๏ธ
12 dark web monitoring tools
โš ๏ธ
Microsoft Issues Patches for 79 Flaws, Including 3 Actively Exploited Windows Flaws
KEV
โš ๏ธ
Data Breach at Golf Course Management Firm KemperSports Impacts 62,000
โš ๏ธ
Windows Elevation of Privilege Flaw Exploited by QakBot Malware, PoC Published
โš ๏ธ
Evaluating the Effectiveness of Reward Modeling of Generative AI Systems
โš ๏ธ
Microsoft Discloses 4 Zero-Days in September Update
โš ๏ธ
OpenZiti: Secure, Open-Source Networking for Your Applications
โš ๏ธ
Singapore Police Arrest Six Hackers Linked to Global Cybercrime Syndicate
โš ๏ธ
Forget the Talent Gap โ€“ Itโ€™s an Experience Gap
โš ๏ธ
Criminal IP and IPLocation.io Join Forces for Enhanced IP Analysis
โš ๏ธ
Threat Actors Exploiting Legitimate Software For Stealthy Cyber Attacks
โš ๏ธ
Microsoft Says Windows Update Zero-Day Being Exploited To Undo Security Fixes
โš ๏ธ
Adobe fixes Acrobat Reader zero-day with public PoC exploit
โš ๏ธ
Bashing Windows Bugs, Take 2: Microsoft Restores Nixed Fixes
โš ๏ธ
Tech Stack Uniformity has Become a Systemic Vulnerability
โš ๏ธ
Geopolitical Tensions Fuel Growth in Cross-Border Fraud
โš ๏ธ
Legal Firms Increasingly Targeted by Phishing Attacks, Ransomware
โš ๏ธ
TLS security subverted due to CA use of outdated WHOIS servers
โš ๏ธ
NoName Apparently Allies With RansomHub Operation
โš ๏ธ
Election Experts Still Demanding More Federal Cyber Support
๐Ÿ“‹
Adobe Security Update, Multiple Vulnerabilities Patched
๐Ÿ“‹
Chrome 128 Update Resolves High-Severity Vulnerabilities
๐Ÿ“‹
ICS Patch Tuesday: Advisories Published by Siemens, Schneider, ABB, CISA
๐Ÿ“ข
New RansomHub Attack Killing Kasperskyโ€™s TDSSKiller To Disable EDR
๐Ÿ“ข
Live Webinar | From Compliance to Culture: Leveraging ISO 27001 and Global Standards for Security Excellence
๐Ÿ“ข
Google Chrome security advisory (AV24-512)
๐Ÿ“ข
[Control systems] ABB security advisory (AV24-513)
๐Ÿ“ข
Compliance and Risk Management Startup Datricks Raises $15 Million
๐Ÿ“ข
Intel security advisory (AV24-514)
๐Ÿ“ข
Cisco security advisory (AV24-515)
๐Ÿ“ข
Palo Alto Networks security advisory (AV24-516)
๐Ÿ”ฅ
1.7 million credit card records leaked by payment gateway. Cyber Security Today for Wednesday, September 11, 2024
๐Ÿ”ฅ
CosmicBeetle Upgrades Arsenal with New ScRansom Ransomware to Target SMBs
๐Ÿ”ฅ
DHS Cyber Review Board Will Announce Next Investigation โ€˜Soonโ€™
๐Ÿ”ฅ
PIXHELL Attack Allows Air-Gap Jumping via Noise From Screens
๐Ÿ”ฅ
DDoS Attacks Double With Governments Most Targeted
๐Ÿ”ฅ
NPD Breach Underscores The Need For Stronger Digital Identities
๐Ÿ”ฅ
Google Introduces โ€˜Air-Gappedโ€™ Backup Vault to Thwart Ransomware
๐Ÿ•ต๏ธ
ISC Stormcast For Wednesday, September 11th, 2024 https://isc.sans.edu/podcastdetail/9134, (Wed, Sep 11th)
๐Ÿ•ต๏ธ
German Cyber Agency Investigating APT28 Phishing Campaign
๐Ÿ•ต๏ธ
Python Libraries Used for Malicious Purposes, (Wed, Sep 11th)
๐Ÿ•ต๏ธ
New Android Spyware As TV Streaming App Steals Sensitive Data From Devices
๐Ÿ•ต๏ธ
Hacker pleads guilty after arriving on plane from Ukraine with a laptop crammed full of stolen credit card details
๐Ÿ•ต๏ธ
Developers Beware: Lazarus Group Uses Fake Coding Tests to Spread Malware
๐Ÿ•ต๏ธ
Microsoft Adds Support for Post-Quantum Algorithms in SymCrypt Library
๐Ÿ•ต๏ธ
Ivanti Patches Critical Vulnerabilities in Endpoint Manager
๐Ÿ•ต๏ธ
DockerSpy: Search for images on Docker Hub, extract sensitive information - Help Net Security
๐Ÿ•ต๏ธ
Rogue WHOIS server gives researcher superpowers no one should ever have
๐Ÿ•ต๏ธ
Quad7 botnet evolves to more stealthy tactics to evade detection
๐Ÿ•ต๏ธ
ColorTokens Strengthens Zero Trust With PureID Acquisition
๐Ÿ•ต๏ธ
Chinese โ€˜Crimson Palaceโ€™ Espionage Campaign Keeps Hacking Southeast Asian Governments
๐Ÿ•ต๏ธ
Losses From Investment Scams have Increased Six-Fold Since 2021
๐Ÿ•ต๏ธ
Chinese hackers linked to cybercrime syndicate arrested in Singapore
๐Ÿ•ต๏ธ
Intel Informs Customers About Over a Dozen Processor Vulnerabilities
๐Ÿ•ต๏ธ
Beyond Immature Rhetoric: The Case Against Mockery and Ambulance Chasing in the Security Industry
๐Ÿ•ต๏ธ
Chinese Hackers Linked To Syndicate Arrested In Singapore
๐Ÿ•ต๏ธ
SplxAI Raises $2 Million to Protect AI Chatbot Apps
๐Ÿ•ต๏ธ
Mental Health Records Database Found Exposed on Web
๐Ÿ•ต๏ธ
French Cyber Agency Warns of APT28 Hacks Against Think Tanks
๐Ÿ•ต๏ธ
Fake password manager coding test used to hack Python developers
๐ŸŒ
Earth Preta Upgrades Attack Strategy via Removable Drives
๐ŸŒ
Quad7 Botnet Targets More SOHO and VPN Routers, Media Servers
๐ŸŒ
Quad7 Botnet Expands to Target SOHO Routers and VPN Appliances
๐ŸŒ
6 common Geek Squad scams and how to defend against them
๐Ÿ“ก
Experts Demonstrate How to Bypass WhatsApp View Once Feature
๐Ÿ“ก
Gallup Poll Bugs Open Door to XSS Attacks
๐Ÿ“ก
UK: National Crime Agency, Responsible for Fighting Cybercrime, โ€˜On Its Knees,โ€™ Warns Report
๐Ÿ“ก
Reputation Hijacking With JamPlus: A Maneuver To Bypass Smart App Control (SAC)
๐Ÿ“ก
FBI Report Says Cryptocurrency Scams Surged in 2023
๐Ÿ“ก
Why Is It So Challenging to Go Passwordless?
๐Ÿ“ก
AI Cybersecurity Needs to be as Multi-Layered as the System itโ€™s Protecting
๐Ÿ“ก
Proposed Underwater Datacenter Surprises Regulators Who Hadn't Heard About It
๐Ÿ“ก
Hacker Steals Data On 300k From Avis
๐Ÿ“ก
When You Pay A Ransom And The Decryptor Doesn't Work
๐Ÿ“ก
Security Budgets Continue Modest Growth, but Staff Hiring Slows Considerably, Research Finds
๐Ÿ“ก
DragonRank Black Hat SEO Campaign Targeting IIS Servers Across Asia and Europe
๐Ÿ“ก
DoJ Distributes $18.5 Million to Western Union Fraud Victims
๐Ÿ“ก
WordPress.org to require 2FA for plugin developers by October
๐Ÿ“ก
Alert notification as phishing bait | Kaspersky official blog
๐Ÿ“ก
UKโ€™s ICO and NCA Sign Memorandum to Boost Reporting and Resilience
๐Ÿ“ก
Why Hellman & Friedman Wants to Unload Checkmarx for $2.5B