> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights several key threats and trends. The suspected member of the ShinyHunters group, known as "Rey," has been detained in Jordan, aiding the FBI in identifying other group members involved in digital extortion. Meanwhile, a new China-aligned cyber espionage group, TA419, has been targeting U.S. AI policy experts through credential phishing campaigns tied to Microsoft. This indicates a rising trend in nation-state actors focusing on critical technology sectors. Additionally, ongoing analysis of User Agent Strings in honeypot logs reveals continued interest in understanding attacker behaviors. These developments underscore the persistent threats from both cybercriminal groups and state-sponsored actors in the evolving cybersecurity landscape.
|
// AI-powered summary generated at 08:00
The Wslink loader can reportedly serve other connecting clients and load additional payloads
ReversingLabs cybersecurity researchers spotted 41 malicious PyPI packages
In part one of this two-part series, we escaped Webviews in real-world misconfigured VSCode extensions. But can we still escape extensions if they are well-configured? In this post, we’ll demonstrate how I bypassed a Webview’s localResourceRoots by exploiting small URL parsing differences between th...
The malicious software employs DLL sideloading techniques to run its malicious components
A fifth of firms use accountants to help with compliance
Le Gaston College a été victime d'une attaque de ransomware en février. Le pirate a accédé à des fichiers contenant des informations personnelles des employés. Le président du collège a envoyé un e-mail interne pour informer les employés de la situation et les inciter à souscrire à une surveillance...
Fortinet detected a 50% increase in destructive attacks in H2 2022
Campaigns designed to steal card information and install malware
Analyzing ChatGPT's capabilities and various claims about how it will revolutionize cybercrime.
The figures come from Synopsys’ new Open Source Security and Risk Analysis report
The hackers appear to have a possible interest in industries connected with COVID-19 treatments
TL;DR: This two-part blog series will cover how I found and disclosed three vulnerabilities in VSCode extensions and one vulnerability in VSCode itself (a security mitigation bypass assigned CVE-2022-41042 and awarded a $7,500 bounty). We will identify the underlying cause of each vulnerability and...
The malicious packages were reportedly created using automated processes
Outage impacts Russian state media websites
Le Casino Del Sol dans la région de Tucson a été la cible d'une tentative de cyberattaque le 21 février, entraînant une panne généralisée de ses systèmes, y compris les distributeurs automatiques, les systèmes de cartes de crédit et les jeux de table qui ne pouvaient accepter que du liquide. Le 27 f...
Extortion found to be most common impact from cyber-attacks in 2022
Security researchers say hackers successfully exfiltrated content
L'entité Mercy Home for Children, une organisation de santé basée à Brooklyn, New York, a subi une cyberattaque le 21 février 2023, affectant les données personnelles de 356 personnes, dont un résident du Maine. L'incident a été découvert le jour même et impliquait une fuite de numéros de sécurité s...
The new class of privilege escalation bugs is based on the ForcedEntry attack
The flaw is triggered using the Race Condition between temporary file creation and deletion