98Articles
9Categories
2024-10-02Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-29824 Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability These types of vulnerabilities are frequent attack vectors for malicious …
KEV
πŸ›
Researchers Sound Alarm on Active Attacks Exploiting Critical Zimbra Postjournal Flaw
πŸ›
New Bluetooth Vulnerability Leak, Your Passcode to Hackers During Pairing
πŸ›
14 underrated pentesting tools to round out your red team arsenal
πŸ›
Alert: Adobe Commerce and Magento Stores Under Attack from CosmicSting Exploit
⚠️
FCC orders T-Mobile to deliver zero trust and better MFA
⚠️
Zimbra RCE Vuln Under Attack Needs Immediate Patching
⚠️
Ransomware explained: How it works and how to remove it
⚠️
Political Manipulation with Massive AI Model-driven Misinformation and Microtargeting
⚠️
Critical Zimbra Vulnerability Exploited One Day After PoC Release
KEV
⚠️
Lockbit dismantling progresses
⚠️
New Bluetooth Vulnerability Leak, Your Passcode to Hackers During Pairing
⚠️
Critical Zimbra Vulnerability Exploited One Day After PoC Release
⚠️
Zimbra Mail Servers Under Siege Through RCE Vuln
⚠️
Critical Zimbra RCE flaw actively exploited to take over servers
KEV
⚠️
DrayTek fixed critical flaws in over 700,000 exposed routers
⚠️
Alert: Over 700,000 DrayTek Routers Exposed to Hacking via 14 New Vulnerabilities
⚠️
Critical Zimbra RCE flaw exploited to backdoor servers using emails
⚠️
CISA: Network switch RCE flaw impacts critical infrastructure
⚠️
New Bluetooth Vulnerability Leak, Your Passcode to Hackers During Pairing
⚠️
Questioning security of hardware security keys
⚠️
Cloudflare reports thwarting the largest-ever publicly disclosed DDoS attack
⚠️
How Are We Going to Fill 4.8 Million Cybersecurity Jobs?
⚠️
Zero-Day Breach at Rackspace Sparks Vendor Blame Game
⚠️
More Car Hacks, CUPS Vulns, Microsoft's SFI, Memory Safety, Password Complexity - ASW #301
⚠️
Cybercrime is Still Evil Incorporated, But Disruptions Help
⚠️
Critical Ivanti RCE flaw with public exploit now used in attacks
KEV
⚠️
Hawaii Clinic Notifies 124,000 of Hack Credited to Lockbit
⚠️
Global Governments Release New Ransomware Response Guidance
⚠️
Smashing Security podcast #387: Breaches in your genes, and Kaspersky switcheroo raises a red flag
⚠️
UK ICO Fines Police Service Northern Ireland 750,000 Pounds
πŸ“‹
Patch Tuesday early release has huge issues: Cyber Security Today for Wednesday, October 2, 2024
πŸ“‹
Addressing Git Vulnerabilities in Ubuntu 18.04 and 16.04
πŸ“’
NIST's Security Flaw Database Still Backlogged With 17k+ Unprocessed Bugs. Not Great
πŸ“’
Mozilla security advisory (AV24-552)
πŸ“’
Juniper Networks security advisory (AV24-554)
πŸ“’
Google Chrome security advisory (AV24-553)
πŸ“’
HPE security advisory (AV24-555)
πŸ“’
The U.K.'s NCSC and U.S. FBI Warn of Iranian Spear-Phishing Attacks
πŸ“’
Jenkins security advisory (AV24-556)
πŸ“’
Zimbra security advisory (AV24-558)
πŸ“’
Cisco security advisory (AV24-557)
πŸ”₯
Evil Corp hit with new sanctions, BitPaymer ransomware charges
πŸ”₯
Community Clinic of Maui says 123,000 affected by May cyberattack
πŸ”₯
Andariel Hacking Group Shifts Focus to Financial Attacks on U.S. Organizations
πŸ”₯
Microsoft Alert: New INC Ransomware Targets US Healthcare
πŸ”₯
Evil Corp/REvil Malware Crime Group Outed As Family Affair
πŸ”₯
More LockBit Hackers Arrested, Unmasked As Servers Siezed
πŸ”₯
T-Mobile Pays $16 Million Fine For Three Years' Worth Of Data Breaches
πŸ”₯
News agency AFP notifies French authorities of potential data breach
πŸ”₯
China-Linked CeranaKeeper Targeting Southeast Asia with Data Exfiltration
πŸ”₯
The Top 5 Largest Scale Intrusions in 2023
πŸ”₯
Fake browser updates spread updated WarmCookie malware
πŸ”₯
Manufacturers Rank as Ransomware's Biggest Target
πŸ”₯
Dick’s Sporting Goods Cyber Attack Underscores Importance of Email Security and Internal Controls
πŸ”₯
How to protect schools from cyberthreats | Kaspersky official blog
πŸ”₯
Separating the bee from the panda: CeranaKeeper making a beeline for Thailand
πŸ•΅οΈ
ISC Stormcast For Wednesday, October 2nd, 2024 https://isc.sans.edu/podcastdetail/9162, (Wed, Oct 2nd)
πŸ•΅οΈ
AI-Powered Rhadamanthys Stealer Targets Crypto Wallets with Image Recognition
πŸ•΅οΈ
GhostStrike – A Cyber Security Tool for Red Team to Evade Detection
πŸ•΅οΈ
California AI Safety Bill Vetoed
πŸ•΅οΈ
The fix for BGP’s weaknesses – RPKI – has issues of its own
πŸ•΅οΈ
Cryptocurrency Wallets Targeted via Python Packages Uploaded to PyPI
πŸ•΅οΈ
Harmonic Raises $17.5M to Defend Against AI Data Harvesting
πŸ•΅οΈ
Record-Breaking DDoS Attack Peaked at 3.8 Tbps, 2.14 Billion Pps
πŸ•΅οΈ
After Code Execution, Researchers Show How CUPS Can Be Abused for DDoS Attacks
πŸ•΅οΈ
What are You Working on Wednesday
πŸ•΅οΈ
Cybersecurity Awareness Month: Cybersecurity awareness for developers
πŸ•΅οΈ
MITRE Adds Mitigations to EMB3D Threat Model
πŸ•΅οΈ
US, Allies Release Guidance on Securing OT Environments
πŸ•΅οΈ
Mario Duarte, Former Snowflake Cybersecurity Leader, Joins Aembit as CISO to Tackle Non-Human Identities
πŸ•΅οΈ
News alert: Aembit appoints former Snowflake security director Mario Duarte as its new CISO
πŸ•΅οΈ
LLMs hallucinating non-existent developer packages could fuel supply chain attacks
πŸ•΅οΈ
Warnings Mount Over Fake North Korean IT Workers
πŸ•΅οΈ
Amazon CISO Amy Herzog on Embedding Security in Ring, Alexa
πŸ•΅οΈ
From Desire Paths to Security Highways: Lessons from Disney's Approach to User-Centric Design
πŸ•΅οΈ
Security related Docker containers, (Wed, Oct 2nd)
πŸ•΅οΈ
OpenAI's New Model is Berry Good at Deception
πŸ•΅οΈ
FIN7 hackers launch deepfake nude β€œgenerator” sites to spread malware
πŸ•΅οΈ
OpenAI Valuation Nearly Doubles to $157B After $6.6B Funding
πŸ•΅οΈ
US DOJ Unveils New Strategic Approach to Counter Cybercrime
🌐
New PyPI Malware Poses as Crypto Wallet Tools to Steal Private Keys
🌐
5 Must-Have Tools for Effective Dynamic Malware Analysis
🌐
Fake Job Applications Deliver Dangerous More_eggs Malware to HR Professionals
πŸ“‘
Crook made millions by breaking into execs’ Office365 inboxes, feds say
πŸ“‘
Cyble Researchers Uncover Sophisticated Attack Using VSCode for Remote Access
πŸ“‘
Iran-linked Threat Group Handala Actively Targets Israel
πŸ“‘
PyPI Repository Found Hosting Fake Crypto Wallet Recovery Tools That Steal User Data
πŸ“‘
Microsoft warns of Windows 11 24H2 gaming performance issues
πŸ“‘
Microsoft blocks Windows 11 24H2 on some Intel PCs over BSOD issues
πŸ“‘
Sophos Firewall v21: Streamlined management
πŸ“‘
The Fix For BGP's Weaknesses Has Issues Of Its Own
πŸ“‘
Record Breaking DDoS Attack Peaked At 3.8 Tbps, 2.14 Billion Pps
πŸ“‘
Region 8 Invites You to Secure Our World
πŸ“‘
Microsoft Office 2024 now available for Windows and macOS users
πŸ“‘
Cybersecurity Awareness Month: A timely reminder to review your security posture
πŸ“‘
Fake Trading Apps Target Victims Globally via Apple App Store and Google Play
πŸ“‘
Snake Oilers: Sandfly Security, Permiso and Wiz