> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights several significant threats. A security researcher has identified a KVM guest-host escape flaw in Firecracker MicroVMs, potentially impacting AWS environments. Dell has released patches for 18 critical vulnerabilities in its Container Storage Modules (CSM), which could allow attackers to gain unauthorized access to storage and Kubernetes systems. Additionally, the hacking group ShinyHunters has exploited a zero-day vulnerability in PeopleSoft, raising alarms about increased risks for enterprises using the Oracle software. Organizations are advised to implement stringent security measures in response to these emerging threats.
|
// AI-powered summary generated at 04:00
US senators have accused the SEC of failing to properly secure its social media accounts after hackers comprised its X account and posted a fake Bitcoin announcement
Discovered by the SentinelLabs team, FBot targets web servers, cloud services and SaaS platforms
Trail of Bits cares about internet freedom, and one of our most valued partners in pursuit of that goal is the Open Technology Fund (OTF). Our core values involve focusing on high-impact work, including work with a positive social impact. The OTF’s Red Team Lab […]
Content delivery provider Cloudflare observed a staggering surge in DDoS attacks against environmental services during COP28
The main British Library catalogue will be back online on Monday, January 15, as the institution continues its technical rebuild following the ransomware attack last year
A few days ago Riley Goodside posted about an interesting discovery on how an LLM prompt injection can happen via invisible instructions in pasted text. This works by using a special set of Unicode code points from the Tags Unicode Block.
The proof-of-concept showed how a simple text contained invis...
A new Recorded Future report warns of growing abuse of GitHub and recommends blocking risky services
The ICO has fined HelloFresh £140,000 for breaking privacy laws with a spam marketing campaign
Le 15 janvier, la filiale de Foxconn spécialisée dans les équipements pour semi-conducteurs, Foxsemicon Integrated Technology Inc, a été victime d'une cyberattaque et les pirates informatiques ont demandé une rançon d'un million de dollars. Les pirates ont menacé de divulguer les données des clients...
Trois conseils du Kent, Canterbury City Council, Thanet District Council et Dover District Council, ont subi des perturbations de services suite à un incident cybernétique qui pourrait être une attaque de piratage organisée. Les autorités locales collaborent avec les experts du National Cyber Securi...
Australian Retailer Ransomware Breach, 15 January 2024: Qilin ransomware gang has shared 37.6 gigabytes of data belonging to Victorian print music company Hal Leonard Australia. Hal Leonard given a week to pay an undisclosed sum of money for ransom.
The post Incident: Victorian print music giant Hal...
Le cabinet d'avocats Constangy Brooks Smith & Prophete LLP a informé l'Attorney General du Maine, Aaron Frey, d'une faille de sécurité chez son client, Hardin, Kundla, McKeon & Poletto P.C. Cette faille a pu permettre l'accès non autorisé à des informations personnelles, notamment des noms, des date...
La bibliothèque du comté de Douglas a été victime d'une cyberattaque par un groupe criminel international nommé "Playcrypt", soupçonné d'avoir des liens avec la Russie. Le système de la bibliothèque a été paralysé, affectant le catalogue en ligne et les services de prêt, mais aucune information pers...
CISA’s advisory provides mitigations for vulnerabilities in ICS products used in critical infrastructure industries like energy, manufacturing and transportation
Sambr'Habitat, une société de logements publics située à Sambreville et Jemeppe-sur-Sambre, est contrainte de fonctionner au ralenti à la suite d'une cyberattaque. Les détails de l'attaque et son impact exact sur les opérations de l'entreprise ne sont pas entièrement divulgués dans le texte accessib...
La mairie de Calvia à Majorque a été victime d'une cyberattaque détectée tôt le samedi matin, ce qui a conduit à la formation d'un comité de crise incluant des spécialistes en informatique, des chefs de département et des conseillers municipaux. Une analyse judiciaire de l'attaque est en cours par l...
Semgrep, a static analysis tool for finding bugs and specific code patterns in more than 30 languages, is set apart by its ease of use, many built-in rules, and the ability to easily create custom rules. We consider it an essential automated tool for discovering security issues in a […]
Email security provider Cofense outlined some of the most common HR-related scams and phishing campaigns it has observed
Bitdefender researchers revealed the vulnerability allows an attacker to send commands to the thermostat and replace its firmware
\[Mise à jour du 29 janvier 2024\] Le 25 janvier 2024, l'éditeur a publié un avis de sécurité concernant plusieurs vulnérabilités affectant GitLab CE et EE. La vulnérabilité CVE-2024-0402 est considérée critique avec un score CVSSv3 de 9,9. Elle permet à un attaquant authentifié d'écrire des...