> TODAY'S SUMMARY (109 articles)
Today's cybersecurity landscape reveals several critical developments. AWS AgentCore's security vulnerabilities, including weak VM isolation and excessive permissions, have been exposed, potentially facilitating attacks. In international law enforcement, Japan has extradited a Russian national linked to the Qilin ransomware gang to Germany, where further arrests have occurred, despite ongoing attacks by the group. The FBI has also arrested members of the ShinyHunters extortion group, underscoring the persistent threat of data breaches. Meanwhile, unpatched vulnerabilities in the AhsayCBS backup platform are being actively exploited for webshell deployment and cryptocurrency mining. A noticeable trend is the shift in ransomware tactics, with attackers increasingly opting for data theft rather than encryption. Lastly, the U.S. and allies have disrupted Chinese state-sponsored hacking tools, illustrating ongoing geopolitical cybersecurity tensions.
|
// AI-powered summary generated at 20:00
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in remote code execution, privilege escalation, denial of service or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 2.4.67-1~deb12u2.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Cisco Talos uncovers CloudZ RAT and Pheno plugin abusing Microsoft Phone Link to intercept SMS OTPs
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The company raised another $35 million as an extension to its previously announced Series C funding round.
The post Autonomous Offensive Security Firm XBOW Raises $35 Million appeared first on SecurityWeek.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in WebKitGTK.
The federal SECURE Data Act is not a serious consumer privacy bill, and its provisions—if enacted—would be a retreat from already insufficient state protections.
Republicans on the House Energy and Commerce Committee released a draft of the bill late last month without bipartisan support. The bill i...
Iran-linked APT MuddyWater used ransomware-style tactics to mask espionage, combining phishing, credential theft, data exfiltration, and extortion without encryption. A newly discovered cyber intrusion attributed to the Iran-linked APT MuddyWater (aka SeedWorm, TEMP.Zagros, Mango Sandstorm, TA450, a...
Backups don't fail because they're missing, they fail because attackers destroy them first. Acronis explains how ransomware targets backup systems before encryption, leaving no path to recovery. [...]
A new survey found that kids find it easy to bypass age checks, despite a rise in age verification laws around the world.
The startup will invest in expanding its training categories, optimizing video generation, and growing its partnership ecosystem.
The post Herd Security Raises $3 Million for AI-Powered Training Platform appeared first on SecurityWeek.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
ar...
CISA’s CI Fortify initiative aim for critical infrastructure operators to build isolation & recovery
Activists say ministers are targeting access rather than Big Tech's data-hungry business models
The MuddyWater Iranian hackers disguised their operations as a Chaos ransomware attack, relying on  Microsoft Teams social engineering to gain access and establish persistence. [...]