98Articles
9Categories
2024-10-22Date
🚨
CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day AttackThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting ScienceLogic SL1 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation as a zero-day. The vulnerability in question, tracke…
KEV
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-38094 Microsoft SharePoint Deserialization Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber a…
KEV
🐛
VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability
🐛
VMware fixes bad patch for critical vCenter Server RCE flaw
⚠️
Hackers exploit Roundcube webmail flaw to steal email, credentials
⚠️
Using gRPC and HTTP/2 for Cryptominer Deployment: An Unconventional Approach
⚠️
Pharma Giant Johnson & Johnson Discloses Data Breach
⚠️
7 risk management mistakes CISOs still make
⚠️
Low turnover leaves job-seeking CISOs with nowhere to go
⚠️
Bumblebee Malware Loader Resurfaces Following Law Enforcement Takedown
⚠️
Bumblebee and Latrodectus Malware Return with Sophisticated Phishing Strategies
⚠️
IcePeony Hackers Exploiting Public Web Servers To Inject Webshells
⚠️
Critical Chrome Vulnerabilities Let Malicious Apps Run Shell Command on Your PC
⚠️
New AI Tool To Discover 0-Days At Large Scale With A Click Of A Button
⚠️
Bumblebee malware returns after recent law enforcement disruption
⚠️
Fortinet releases patches for undisclosed critical FortiManager vulnerability
⚠️
Socket lands a fresh $40M to scan software for security flaws
⚠️
Socket Accelerates Open-Source Security With $40M Series B
⚠️
IBM adds quantum-resistant controls within new security suite
⚠️
Google Warns of Samsung Zero-Day Exploited in the Wild
KEV
⚠️
Security Flaw in Styra's OPA Exposes NTLM Hashes to Remote Attackers
⚠️
Cybercriminals Exploiting Docker API Servers for SRBMiner Crypto Mining Attacks
⚠️
CISA Releases One Industrial Control Systems Advisory
⚠️
Aligning Tech Execs on Cyber Resilience - Theresa Lanowitz - BSW #369
⚠️
macOS HM Surf Vuln Might Already Be Under Exploit By Malware
⚠️
Google Warns Of Samsung Zero Day Exploited In The Wild
KEV
⚠️
Beyond ChatGPT: The rise of agentic AI and its implications for security
⚠️
The Complexities, Configurations, and Challenges in Cloud Security - Scott Piper - ASW #304
⚠️
Exploit released for new Windows Server "WinReg" NTLM Relay attack
⚠️
5 new protections on Google Messages to help keep you safe
⚠️
Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans
⚠️
Nearly Two-Thirds of IT Leaders Have Fallen For Phishing Attacks
⚠️
Exploit released for new Windows Server "WinReg" NTLM Relay attack
⚠️
CISA and USPIS Release Two Election Mail Security Resources
⚠️
ICS Detection Improves, Response Still Lacking
⚠️
AWS, Azure auth keys found in Android and iOS apps used by millions
⚠️
Retaining EU Adequacy Crucial to UK Economy: Lawmaker
⚠️
Critical OPA Vulnerability Exposes Windows Credentials
📢
FBI & CISA Warns of Tactics Used by Hackers Targeting 2024 U.S. General Election
📢
Singapore unveils AI system guidelines, emphasizing secure-by-design
📢
No, The Chinese Have Not Broken Modern Encryption Systems with a Quantum Computer
📢
IoT Assignment Completed! Report on Barriers to U.S. IoT Adoption
📢
What NIST’s post-quantum cryptography standards mean for data security
📢
JSON Parsing, Email Parsing, CISA's Bad Practices Guide, Abusing Disclosure Policies - ASW #304
📢
CISA proposes new security requirements to protect govt, personal data
🔥
Winnebago Public Schools Suffers Cyber Attack, Services Shut Down
🔥
Ransomware-Attacke auf Autozulieferer Yorozu
🔥
BlackCat Ransomware Successor Cicada3301 Emerges
🔥
50,000 Files Exposed in Nidec Ransomware Attack
🔥
Over 6,000 WordPress hacked to install plugins pushing infostealers
🔥
Russia-Linked Hacktivists Attack Japan's Govt, Ports
🔥
Data Storage In Spotlight Of Italian Security Committee After Intesa Breach
🔥
SEC charges tech companies for downplaying SolarWinds breaches
🔥
More Than 33,000 People in the UK Have Been Hacked Over the Past Year
🔥
Microsoft Threat Intelligence healthcare ransomware report highlights need for collective industry action
🕵️
ISC Stormcast For Tuesday, October 22nd, 2024 https://isc.sans.edu/podcastdetail/9190, (Tue, Oct 22nd)
🕵️
WeChat modified TLS encryption protocol exposes users to security risks
🕵️
Best practices on securing your AI deployment
🕵️
Palo Alto Networks Adds New Capabilities to OT Security Solution
🕵️
Latrodectus Malware Increasingly Used by Cybercriminals
🕵️
Russia-Linked Hackers Attacking Governmental And Political Organizations
🕵️
GHOSTPULSE Hides Within PNG File Pixel Structure To Evade Detections
🕵️
Severe flaws in E2EE cloud storage platforms used by millions
🕵️
Anti-Bot Services Help Cybercrooks Bypass Google 'Red Page'
🕵️
Critical Vulnerabilities Expose mbNET.mini, Helmholz Industrial Routers to Attacks
🕵️
Beware Of Callback Phishing Attacks Google Groups That Steal Login Details
🕵️
Stream.Security Secures $30 Million Series B
🕵️
SecurityWeek’s 2024 ICS Cybersecurity Conference Kicks Off in Atlanta
🕵️
Cloud Security — Maturing Past the Awkward Teenage Years
🕵️
CyberheistNews Vol 14 #43 North Korean IT Worker Threat: 10 Critical Updates to Your Hiring Process
🕵️
What level of tool rationalization does your company do and why? - LaLisha Hurt - CSP #197
🕵️
Threat actors increasingly using malicious virtual hard drives in phishing attacks
🕵️
US Police Detective Charged With Purchasing Stolen Credentials
🕵️
CEO Accountability as CISOs Concerned Over Demands and Measured by Profit/Cost - BSW #369
🕵️
SEC Charges Four Companies Over Misleading Disclosures on SolarWinds Hack
🕵️
INE Security Launches New Training Solutions to Enhance Cyber Hygiene for SMBs
🕵️
How much HTTP (not HTTPS) Traffic is Traversing Your Perimeter?, (Tue, Oct 22nd)
🕵️
Doom Brain, E2EE, OT, Adload, Cisco, VMware, internet archive, Josh Marpet ... - SWN #424
🕵️
Will the Real Satoshi Nakamoto Please Stand Up?
🕵️
Helping Medical Device Makers Meet Latest Cyber Expectations
🕵️
Regulator Urges UK Banks to 'Help Foot the Bill' for Fraud
🕵️
CEOs Levy, Thomas on Perks of $859M Sophos-Secureworks Deal
🕵️
Check Point, Mimecast Settle SEC Case From SolarWinds Hack
🕵️
Exploring the Latest Security Innovations at Hardwear.io
🌐
Malicious npm Packages Target Developers' Ethereum Wallets with SSH Backdoor
🌐
Pixel Perfect Ghostpulse Malware Loader Hides Inside PNG Image Files
🌐
Researchers link Polyfill supply chain attack to huge network of copycat gambling sites
🌐
SEC fines four companies $7 million for ‘misleading cyber disclosures’ regarding SolarWinds hack
🎙️
The AI Fix #21: Virtual Trump, barking mad AI, and a robot dog with a flamethrower
📡
A Comprehensive Guide to Finding Service Accounts in Active Directory
📡
Security considerations for mobile device deployments (ITSAP.70.002)
📡
NVIDIA Computer Finds Largest Known Prime, Blows Past Record By 16 Million Digits
📡
Detective Charged With Purchasing Stolen Credentials
📡
Researchers Discover Flaws In 5 End-To-End Encrypted Cloud Services
📡
AI chatbots can be tricked by hackers into helping them steal your private data
📡
Effective AI adoption for optimizing SOC analysts’ work
📡
Announcing the BlueHat 2024 Sessions
📡
Windows 10 KB5045594 update fixes multi-function printer bugs