68Articles
8Categories
2024-12-20Date
🚨
CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities ListThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploi…
KEV
🐛
Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools
🐛
Siemens UMC Vulnerability Allows Arbitrary Remote Code Execution
🐛
CISA Warns of BeyondTrust Privileged Remote Access Exploited in Wild
KEV
🐛
CISA Releases Eight New ICS Advisories to Defend Cyber Attacks
⚠️
Sophos discloses critical Firewall remote code execution flaw
⚠️
CISA Urges Immediate Patching of Exploited BeyondTrust Vulnerability
⚠️
Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation
KEV
⚠️
Fortinet Releases Security Updates for FortiManager
⚠️
Attackers Abuse HubSpot’s Free Form Builder to Craft Phishing Pages
⚠️
James Bond-Style Scamming Profits Explode
⚠️
Foxit PDF Editor Vulnerabilities Allows Remote Code Execution
⚠️
Windows 11 Privilege Escalation Vulnerability Lets Attackers Execute Code to Gain Access
⚠️
Why Apple sends spyware victims to this nonprofit security lab
⚠️
French Citizens - 28,445,106 breached accounts
⚠️
US order is a reminder that cloud platforms aren’t secure out of the box
⚠️
Enhance Microsoft security by ditching your hybrid setup for Entra-only join
⚠️
Die 10 besten API-Security-Tools
⚠️
Solana's Web3.js Library Was Backdoored! Here's How 🚨
⚠️
D3FEND 1.0: A Milestone in Cyber Ontology - Peter Kaloroumakis - ESW #388
⚠️
Lazarus targets nuclear-related organization with new malware
⚠️
Foxit PDF Editor Vulnerabilities Allows Remote Code Execution
⚠️
Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation
📢
Russia fires its biggest cyberweapon against Ukraine
📢
Risky Biz Soap Box: Cool compliance tricks with the Island enterprise browser
🔥
Last Pass Hack Impact Continues: Cyber Security Today for Friday, December 20, 2024
🔥
Malicious Rspack, Vant packages published using stolen NPM tokens
🔥
US charges Russian-Israeli as suspected LockBit ransomware coder
🔥
Krispy Kreme breach, data theft claimed by Play ransomware gang
🔥
Ascension: Health data of 5.6 million stolen in ransomware attack
🔥
Romanian Netwalker ransomware affiliate sentenced to 20 years in prison
🔥
Ransomware Group Claims Theft of Personal, Financial Data From Krispy Kreme
🔥
Another NetWalker Ransomware Affiliate Gets 20-Year Prison Sentence in US
🔥
Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack
🔥
NetWalker Ransomware Operator Sentenced to 20 Years in Prison
🔥
NotLockBit – Previously Unknown Ransomware Attack Windows & macOS
🔥
Third member of LockBit ransomware gang has been arrested
🔥
Ransomware attack on health giant Ascension hits 5.6 million patients
🔥
Hunting Hackers: Secrets of a Pro
🔥
Final fundings for 2024, Blackberry sells Cylance cheap, Product Testing Drama - ESW #388
🔥
United States Charges Dual Russian and Israeli National as Developer of LockBit Ransomware Group
🔥
Romanian National Sentenced to 20 Years in Prison in Connection with NetWalker Ransomware Attacks Resulting in the Payment of Millions of Dollars in Ransoms
🔥
Ransomware Attackers Target Industries with Low Downtime Tolerance
🕵️
Friday Squid Blogging: Squid Sticker
🕵️
In Other News: McDonald’s API Hacking, Netflix Fine, Malware Kills ICS Process
🕵️
Botnet of 190,000 BadBox-Infected Android Devices Discovered
🕵️
Rockwell PowerMonitor Vulnerabilities Allow Remote Hacking of Industrial Systems
🕵️
Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware
🕵️
Christmas "Gift" Delivered Through SSH, (Fri, Dec 20th)
🕵️
ISC Stormcast For Friday, December 20th, 2024 https://isc.sans.edu/podcastdetail/9264, (Fri, Dec 20th)
🕵️
Mobile Phishing Attacks Use New Tactic to Bypass Security Measures
🕵️
Threat Actors Selling Nunu Stealer On Hacker Forums
🕵️
How to craft a comprehensive data cleanliness policy
🕵️
Dysentery, TP-Link, Piracy, Calendar Scams, Tencent, TikTok, Aaran Leyland and More.. - SWN #439
🕵️
2024 End-of-Year News and Wrapup - ESW #388
🕵️
Kaspersky discovers C++ version of BellaCiao malware
🕵️
Off-Topic Friday
🕵️
Deobfuscation of Lumma Stealer
🕵️
Python-Based NodeStealer Version Targets Facebook Ads Manager
🕵️
Lazarus targets nuclear-related organization with new malware
🕵️
New Malware Can Kill Engineering Processes in ICS Environments
🕵️
Rising wave of cyber-attacks targeting YouTube content creators
🎙️
ESET Research Podcast: Telekopye, again
📡
Google Chrome uses AI to analyze pages in new scam detection feature
📡
Massive live sports piracy ring with 812 million yearly visits taken offline
📡
India’s Rapido exposed user and driver data through leaky website feedback form
📡
Hardware for SIEM systems | Kaspersky official blog
📡
Certs vs Experience: What CISOs Really Want 👀