> TODAY'S SUMMARY (114 articles)
Today's cybersecurity landscape reveals several critical threats and trends. A member of the ShinyHunters hacking group has been detained in Jordan, cooperating with the FBI amid ongoing investigations into a significant data breach involving employee information. Meanwhile, vulnerabilities in Citrix NetScaler and Rejetto HFS have been actively exploited, with warnings from CISA regarding their severity and potential impact. Additionally, Denmark's population registry suffered a breach affecting 8.8 million individuals, raising concerns about data security in governmental databases. In the healthcare sector, IQVIA faced a hefty fine for inadequate data anonymization, underscoring the ongoing scrutiny over data protection practices. Lastly, Google has paused its open-source bug bounty program due to an influx of invalid AI-generated reports, reflecting challenges in managing AI vulnerabilities.
|
// AI-powered summary generated at 20:00
L'entreprise publique grecque Hellenic Public Properties Company (ETAD) a été victime d'une attaque par ransomware découverte le 8 novembre, où les pirates ont chiffré les systèmes de l'entreprise et exigé une rançon. ETAD, qui dispose d'une assurance contre les cyberattaques et effectue régulièreme...
La ville de Rawlins a subi une cyberattaque qui a été détectée et notifiée par le Département de la Sécurité Intérieure des États-Unis, mais aucune information sensible n'a été compromise ni de logiciel malveillant installé sur les serveurs de la ville. La divulgation publique de l'attaque a été ret...
The leaked data include personally identifiable information, such as customers’ names, email addresses, phone numbers and membership numbers
IBM found Gootloader group opting for GootBot over off-the-shelf tools for lateral movement
Le conseil écossais Comhairle nan Eilean Siar a subi une perturbation importante de ses services informatiques suite à une attaque présumée par rançongiciel. Le gouvernement écossais et la société Dell aident à identifier la cause de l'incident, tandis que la priorité des autorités est de restaurer...
Jamf Threat Labs found a Mach-O universal binary communicating with an identified malicious domain
Two flaws have near-maximum CVSS scores
Le Harris Center for Mental Health and IDD, un prestataire de services de santé mentale du comté de Harris, a été victime d'une attaque par ransomware le 6 novembre, entraînant l'indisponibilité de certains fichiers d'employés en raison de leur chiffrement. Les experts en cybersécurité ont conseillé...
Juniper Research warns telcos they need bilateral agreements in place
Attempts to deploy Cerber variant on Confluence servers
Le site web du Département des Transports de l'État de Washington a été mis hors service depuis mardi à la suite d'une cyberattaque visant à perturber la diffusion d'informations de voyage en ligne. Bien que le site web de base et l'application soient toujours accessibles, la plupart des information...
Zhdanova reportedly utilized cash, international money laundering associates and businesses fronts
The findings are part of Kaspersky’s latest investigation, spanning from July 2022 to July 2023
This is a joint post with Alpha-Omega—read their announcement post as well! We’re starting a new project in collaboration with Alpha-Omega and OpenSSF to improve the transparency and security of Homebrew. This six-month project will bring cryptographically verifiable build provenance to homebrew-cor...
The consultative body aims to tackle cyber-attacks used to fund Pyongyang’s weapons development, including its nuclear program
Many say it led to a subsequent data breach
Le grand magasin berlinois KaDeWe a été la cible d'une cyberattaque menée par le groupe de hackers russes "Play". Le KaDeWe a réussi à repousser l'attaque et a mis en place un "fonctionnement d'urgence hors ligne" dans ses magasins et bureaux, tout en assurant que les paiements par carte étaient séc...
NCSC wants to ease transition to quantum safety
Several suffered follow-on session hijacking attacks
Quotes and Memes: ""Expect the best, plan for the worst, and prepare to be surprised"- Denis Waitley
The post Quote: Denis Waitley “Expect the best, plan for the worst, and prepare….” appeared first on Australian Information Security Awareness and Advisory.