> TODAY'S SUMMARY (10 articles)
Today's cybersecurity news highlights several critical developments. Google has paused its Open Source Software Vulnerability Reward Program due to an influx of AI-generated, invalid vulnerability reports. In law enforcement news, an alleged leader of the ShinyHunters hacking group was arrested in Jordan and is aiding the FBI in identifying other members. Microsoft's official X account was compromised, promoting a crypto token, leading to an ongoing investigation. Additionally, a newly discovered zero-day vulnerability in Citrix NetScaler has been exploited shortly after previous flaws were patched. Finally, attackers are increasingly abusing legitimate remote monitoring and management (RMM) software, as indicated by a recent report showing it was involved in 45% of endpoint incidents.
|
// AI-powered summary generated at 08:00
Legitimate software used to deploy backdoor malware
Latest vulnerability affects Ivanti Sentry
Today, I published the following diary on isc.sans.edu: “Have You Ever Heard of the Fernet Encryption Algorithm?“: In cryptography, there is a gold rule that states to not develop your own algorithm because… it will be probably weak and broken! They are strong algorithms (like AES) that do a great j...
Two former employees shared information with German newspaper
Je suis désolé, mais l'extrait que vous avez fourni ne contient pas d'informations sur une cyberattaque à la Stadtbibliothek Weißwasser. Il semble plutôt être lié aux conditions d'un abonnement, probablement pour un service en ligne. Pourriez-vous fournir un extrait de l'article qui parle spécifique...
Leaseweb, un fournisseur d'hébergement, semble avoir été touché par une cyberattaque, causant des problèmes à ATPS Online, une entreprise qui fournit une solution de gestion du temps via un modèle SaaS. ATPS Online a déclaré qu'ils ont réussi à accéder à certains de leurs systèmes clés, y compris le...
ESET said Facebook promoted the download of what seemed to be Google’s Bard AI tool
The feature, called the “Safety Check,” is designed to address three specific scenarios
Today, I published the following diary on isc.sans.edu: “Quick Malware Triage With Inotify Tools“: When you handle a lot of malicious files, you must have a process and tools in place to speedup the analysis. It’s impossible to investigate all files and a key point is to find interesting files
The p...
Credit unions will be obligated to notify the NCUA about any cyber incident within 72 hours
An advisory by US intelligence provides guidance for space firms on how to identify an espionage campaign, report and mitigate it
L'hôpital municipal clinique "Sfânta Treime" de Chișinău a été la cible d'une cyberattaque. L'annonce a été faite par le maire Ion Ceban lors d'une réunion opérationnelle des services municipaux. Ion Ceban a également demandé au directeur de l'établissement de vérifier si les données personnelles de...
Over 50,000 have already signed up to program
Intelligence analyst posed a serious risk to Operation Venetic
Le Centre Public d'Action Sociale (CPAS) de Charleroi a été victime d'une attaque informatique. Suite à cette cyberattaque, l'ensemble du système informatique est désormais bloqué. Malgré cela, les services continuent de fonctionner, bien que cela soit avec de nombreuses difficultés. Pour l'instant,...
Russian gang operates comprehensive set of attack tools
Le conseil local de St Helens a été victime d'une cyberattaque présumée par ransomware, affectant ses systèmes et réseaux informatiques. L'incident a été identifié le lundi 21 août et des experts en cybersécurité ont été alertés pour enquêter. Le conseil a mis en place des mesures de sécurité pour p...
Le 21 août 2023, Hosteur se dit victime d'une cyberattaque avec cryptolocker. Sur Twitter, l'entreprise assure que ses équipes sont pleinement mobilisées et fait état de retours de congés en urgence pour faire face à la situation de crise.
Cofense said that over 29% of the malicious emails were directed at the energy sector giant
Le système informatique du comté de Carbon a récemment subi une cyberattaque. L'incident, une attaque par rançongiciel, a été détecté lundi matin et annoncé par le président des commissaires, Wayne Nothstein. Dès la découverte de la violation, les responsables ont commencé à enquêter, à restaurer le...