> TODAY'S SUMMARY (2 articles)
Today's cybersecurity news highlights ongoing trends in threat detection and data analysis. ISC Stormcast discusses recent vulnerabilities and emerging attack vectors, emphasizing the need for proactive security measures. Meanwhile, a recent experiment involving TTY logs reveals insights into actor and bot behavior following successful logins, underscoring the importance of monitoring command activities. The analysis of these logs can aid in identifying malicious actions and enhancing incident response strategies. Overall, there's a continued focus on improving threat intelligence and understanding attacker methodologies.
|
// AI-powered summary generated at 04:00
Australian Education Ransomware Attack, 19 July 2023: Australian Academy of Vocational Education and Trades trading as Academia, has been hit by the Windows ransomware group Lockbit 3.0. The attackers have given the organisation a deadline of 24 July to get in touch and presumably negotiate a ransom...
Le 18 juillet 2023, Citrix a publié un avis de sécurité concernant plusieurs vulnérabilités. La plus critique, dont l'identifiant CVE est CVE-2023-3519, permet à un attaquant non authentifié d'exécuter du code arbitraire à distance. L'équipement est vulnérable s'il est configuré en tant que...
Vers le 19 juillet 2023, le district scolaire d’Ellensburg a subi une perturbation réseau affectant certains systèmes. Dès la découverte, Ellensburg a pris des mesures immédiates et engagé des spécialistes externes pour enquêter sur la nature et l’étendue de l’incident. L’enquête approfondie a révél...
The Office of Science and Technology Policy (OSTP) has circulated a request for information (RFI) on how best to develop policies that support the responsible development of AI while minimizing risk to rights, safety, and national security. In our response, we highlight the following points: To ensu...
Rapid7 has observed that some vulnerabilities in Adobe ColdFusion were still being exploited several days after the patches were published
It mentions the CSET, SCuBAGear, Untitled Goose Tool, Decider and Memory Forensic on Cloud
Australian Mining Cyber Incident, 18 July 2023: Iron ore giant Fortescue Metals targeted by Russian ransomware group. Australian mining company confirms hack occurred on 28 May but data disclosed ‘was not confidential in nature’.
The post Incident: Fortescue Metals admits it suffered breach, Cl0p cl...
The web injects allow cyber-criminals to manipulate legitimate web pages' content in real time
The attack vector was identified as data injection into the firm's commands framework
Le système de dossiers médicaux électroniques d'Ortivus est actuellement indisponible pour certains clients basés au Royaume-Uni en raison d'une cyberattaque. Pour l'instant, aucun patient n'a été directement affecté et aucun autre système n'a été attaqué. Seuls les clients du centre de données hébe...
Ukrainian said to have caused victim losses of $70m
Wordfence claims over 157,000 sites have been hit so far
La société Estée Lauder Companies Inc. a identifié une cyberattaque, où un tiers non autorisé a eu accès à certains de ses systèmes. Suite à la découverte de l'incident, l'entreprise a désactivé certains de ses systèmes et a commencé une enquête avec l'aide d'experts en cybersécurité. L'entreprise p...
Hertfordshire man pleaded guilty in May
Le système de The Body Shop Japan a subi une cyberattaque par ransomware le 18 juillet, provoquant des retards de livraison et d'autres impacts sur les services. Aucune preuve n'a été trouvée que des données aient été transférées à l'extérieur du système de l'entreprise, mais l'incident est toujours...
Le district scolaire de Danbury a été victime d'une attaque par rançongiciel le 18 juillet 2023, entraînant des coûts de 202 274 dollars pour la sécurité réseau et la surveillance du crédit, sans payer de rançon. Le conseil municipal a approuvé une demande de financement de plus de 600 000 dollars p...
The guilty plea also covered a separate count of possession of child pornography
The group utilize malware like GAMMASTEEL to rapidly exfiltrate files within 30-50 minutes
For environments that are secure by design, a 'full-fat SOC' is not always required.
eSentire found the threat after detecting suspicious code in a manufacturing customer's network