125Articles
8Categories
2024-12-11Date
🚨
U.S. CISA adds Microsoft Windows CLFS driver flaw to its Known Exploited Vulnerabilities catalogsubmitted by kid to cybersecurity 1 points | 0 comments https://securityaffairs.com/171851/hacking/u-s-cisa-adds-microsoft-windows-clfs-driver-flaw-to-its-known-exploited-vulnerabilities-catalog.html
KEV
🐛
Patch Tuesday, December 2024 Edition
🐛
Ivanti Issues Critical Security Updates for CSA and Connect Secure Vulnerabilities
🐛
Vulnerability Symbiosis: vSphere?s CVE-2024-38812 and CVE-2024-38813 [Guest Diary], (Wed, Dec 11th)
🐛
US sanctions Chinese cybersecurity firm over global malware campaign
🐛
WPForms Vulnerability Let Users Issues Subscription Payments
🐛
Ivanti CSA Vulnerabilities Let Attackers Gain Admin Access
🐛
Researcher Details CVE-2024-44131 - A Critical TCC Bypass in macOS and iOS
🐛
Google Chrome Patches High-Severity Vulnerabilities - CVE-2024-12381 & CVE-2024-12382
🐛
Windows RDP Service Flaw let Hackers Execute Remote Code
🐛
Microsoft secretly stopped actors from snooping on your MFA codes
⚠️
ISO und ISMS: Darum gehen Security-Zertifizierungen schief
⚠️
Bug bounty programs can deliver significant benefits, but only if you’re ready
⚠️
Salt Typhoon poses a serious supply chain risk to most organizations
⚠️
U.S. Charges Chinese Hacker for Exploiting Zero-Day in 81,000 Sophos Firewalls
⚠️
Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS Vulnerability
KEV
⚠️
From PoC to Attacker Interest in Hours: Real-Time Insights into Mitel MiCollab Vulnerabilities
⚠️
Silent Push Unwraps the AIZ—Aggressive Inventory Zombies—Retail & Crypto Phishing Network Campaign
⚠️
Dell Warns of Critical Code Execution Vulnerability in Power Manager
⚠️
Chinese EagleMsgSpy Spyware Found Exploiting Mobile Devices Since 2017
⚠️
Cleo Vulnerability Exploitation Linked to Termite Ransomware Group
⚠️
Law enforcement shuts down 27 DDoS booters ahead of annual Christmas attacks
⚠️
FYI OpenCVE 2.0 Opensource Vulnerability Management Platform is out
⚠️
Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts
⚠️
Researchers uncover Chinese spyware used to target Android devices
⚠️
New Malware Technique Could Exploit Windows UI Framework to Evade EDR Tools
⚠️
US Charged Chinese Hackers for Exploiting Thousands of Firewall
⚠️
Krispy Kreme discloses cyberattack that is disrupting online orders
⚠️
Operation PowerOFF shuts down 27 DDoS-for-hire platforms
⚠️
Lookout Discovers New Chinese Surveillance Tool Used by Public Security
⚠️
New Malware Technique Could Exploit Windows UI Framework to Evade EDR Tools
⚠️
Oasis Security Research Team Discovers Microsoft Azure MFA Bypass
⚠️
Cardiac surgery device manufacturer falls prey to ransomware
⚠️
Vulnerability impacting all versions of Cleo VLTrader, Harmony, and LexiCom software
⚠️
Multiple Vulnerabilities in Ivanti Cloud Services Application (CSA) Could Allow for Remote Code Execution
⚠️
The imperative for governments to leverage genAI in cyber defense
⚠️
CISA Updates Toolkit with Seven New Resources to Promote Public Safety Communications and Cyber Resiliency
⚠️
Apple Updates Everything (iOS, iPadOS, macOS, watchOS, tvOS, visionOS), (Wed, Dec 11th)
⚠️
New EagleMsgSpy Android spyware used by Chinese police, researchers say
⚠️
Ransomware Hackers Exploiting Cleo Software Zero-Day
⚠️
Hunk Companion WordPress plugin exploited to install vulnerable plugins
⚠️
Risky Business #774 -- Cleo file transfer appliances under widespread attack
📋
Chrome Security Update, Patch For Multiple Vulnerabilities
📋
December Patch Tuesday arrives bearing 71 gifts
📋
ICS Patch Tuesday: Security Advisories Released by Siemens, Schneider, CISA, Others
📋
Is it a bad idea to go on with a pixel 4a?
📋
Apple Pushes Major iOS, macOS Security Updates
📢
Disclosure Rules Lead To Less Disclosure: Cyber Security Today for Wednesday, December 11, 2024
📢
Financial Sector Turning to Multi-Cloud Strategies
📢
Rumänien kommt digital weiterhin nicht zur Ruhe
📢
Researchers Uncover Espionage Tactics of China-Based APT Groups in Southeast Asia
📢
Microsoft security advisory – December 2024 monthly rollup (AV24–701)
📢
APT-C-60 Hackers Penetrate Org’s Network Using a Weapanized Google Drive link
📢
Adobe security advisory (AV24–702)
📢
Google Chrome security advisory (AV24-703)
📢
Ivanti security advisory (AV24-704)
📢
GitLab security advisory (AV24-706)
📢
Atlassian security advisory (AV24-705)
📢
[Control systems] Schneider Electric security advisory (AV24-707)
📢
Apache security advisory (AV24-708)
📢
Clearinghouse Pays $250K Settlement in Web Exposure Breach
📢
AI Meets Fraud Prevention in LexisNexis-IDVerse Acquisition
🔥
Holiday Season Cyber Threats (Part 2): Ransomware, Gift Cards, and Point-of-Sale breaches
🔥
446,000 Impacted by Center for Vein Restoration Data Breach
🔥
Hersteller von Geräten für die Herzchirurgie angegriffen
🔥
On holiday: Most important policies for reduced staff
🔥
Krispy Kreme cyberattack impacts online orders and operations
🔥
Reserachers Uncovered Zloader DNS Tunneling Tactics For Stealthy C2 Communication
🔥
Lynx ransomware behind Electrica energy supplier cyberattack
🔥
Krispy Kreme Discovers Cybersecurity Hole
🔥
Manufacturing vs. U.S. SLED: Cybersecurity Showdown!
🔥
No Doughnuts Today? Cyberattack Puts Krispy Kreme in a Sticky Situation
🔥
Chinese APT Groups Targets European IT Companies
🔥
Researchers Crack Microsoft Azure MFA in an Hour
🔥
Symmetrical Cryptography Pioneer Targets Post-Quantum Era
🔥
Microsoft Defender XDR demonstrates 100% detection coverage across all cyberattack stages in the 2024 MITRE ATT&CK® Evaluations: Enterprise​​
🕵️
ISC Stormcast For Wednesday, December 11th, 2024 https://isc.sans.edu/podcastdetail/9250, (Wed, Dec 11th)
🕵️
Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels
🕵️
US Charges, Sanctions Chinese Man Accused of Sophos Firewall Hacking
🕵️
Ivanti Patches Critical Flaws in Connect Secure, Cloud Services Application
🕵️
Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels
🕵️
Meeten Malware: A Cross-Platform Threat to Crypto Wallets on macOS and Windows
🕵️
Black Basta Gang Uses MS Teams, Email Bombing to Spread Malware
🕵️
Mitigating NTLM Relay Attacks by Default | MSRC Blog | Microsoft Security Response Center
🕵️
Jailbreaking LLM-Controlled Robots
🕵️
Google’s Willow Chip Signals the Urgency of Post-Quantum Cryptography Migration
🕵️
Atlassian, Splunk Patch High-Severity Vulnerabilities
🕵️
Analysis of Nova: A Snake Keylogger Fork
🕵️
Windows RDP Service Flaw let Hackers Execute Remote Code
🕵️
ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms
🕵️
Google Pays $55,000 for High-Severity Chrome Browser Bug
🕵️
Nearly Half a Billion Emails in 2024 Were Malicious
🕵️
From Silos to Synergy: Gen AI Aligns IT and Security Teams
🕵️
BadRAM Attack Uses $10 Equipment to Break AMD Processor Protections
🕵️
Hackers Deploy Weaponized LNK Files for Malicious Payload Delivery
🕵️
News alert: DMD Diamond invites developers to participate in open beta for its v4 blockchain
🕵️
Cortex XDR Delivers Unmatched 100% Detection in MITRE ATT&CK Round 6
🕵️
Evil ISPs, Deloitte, YOLO11, Microsoft, Gift Cards, Navix, Telegram, Josh Marpet... - SWN #436
🕵️
Likely China-based Attackers Target High-profile Organizations in Southeast Asia
🕵️
AuthQuake Flaw Allowed MFA Bypass Across Azure, Office 365 Accounts
🕵️
What are You Working on Wednesday
🕵️
Trust Hijacked: The Subtle Art of Phishing Through Familiar Facades
🕵️
Operation PowerOFF shuts down 27 DDoS-for-hire platforms
🕵️
Secret Blizzard Deploys Kazuar Backdoor in Ukraine Using Amadey Malware-as-a-Service
🕵️
Cybercriminals Impersonate Dubai Police to Defraud Consumers in the UAE - Smishing Triad in Action
🕵️
Resecurity introduces Government Security Operations Center (GSOC) at NATO Edge 2024
🕵️
DMD Diamond Launches Open Beta for v4 Blockchain Ahead of 2025 Mainnet
🕵️
Teaching an Old Framework New Tricks: The Dangers of Windows UI Automation
🕵️
Russian Turla hackers hit Starlink-connected devices in Ukraine
🕵️
Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine
🕵️
Black Hat Europe: Chaos Puts Cybersecurity in the Hot Seat
🕵️
Predictive AI and the Future of Fleet Maintenance
🕵️
Russian cyber spies hide behind other hackers to target Ukraine
🕵️
US Defense Bill Includes Major Focus on Tech, AI and Cyber
🕵️
Cheap Phone Scanner Shows Lots Of People Are Still Being Targeted By NSO Group Spyware
🕵️
Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine
📡
Keeping it real: Sophos and the 2024 MITRE ATT&CK Evaluations: Enterprise
📡
Enron’s Bold Move: Crypto & Energy Sustainability
📡
Russian government spies targeted Ukraine using tools developed by cybercriminals
📡
Why Most People FAIL at Attack Surface Management!
📡
Facebook, Instagram, WhatsApp hit by massive worldwide outage
📡
Microsoft lifts Windows 11 24H2 block on PCs with USB scanners
📡
How Cryptocurrency Turns to Cash in Russian Banks
📡
Cynet Delivers 100% Protection and 100% Detection Visibility in the 2024 MITRE ATT&CK Evaluation
📡
Cybersecurity Gadgets to Hack Your Holiday Gift List