[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 08:00

> WinorDLL64 Backdoor Linked to Lazarus Group
The Wslink loader can reportedly serve other connecting clients and load additional payloads
> Dozens of Malicious 'HTTP' Libraries Found on PyPI
ReversingLabs cybersecurity researchers spotted 41 malicious PyPI packages
> Escaping well-configured VSCode extensions (for profit)
In part one of this two-part series, we escaped Webviews in real-world misconfigured VSCode extensions. But can we still escape extensions if they are well-configured? In this post, we’ll demonstrate how I bypassed a Webview’s localResourceRoots by exploiting small URL parsing differences between th...
> Hackers Use S1deload Stealer to Target Facebook, YouTube Users
The malicious software employs DLL sideloading techniques to run its malicious components
> ICO Calls on Accountants to Improve SME Data Protection
A fifth of firms use accountants to help with compliance
> Gaston College
Le Gaston College a été victime d'une attaque de ransomware en février. Le pirate a accédé à des fichiers contenant des informations personnelles des employés. Le président du collège a envoyé un e-mail interne pour informer les employés de la situation et les inciter à souscrire à une surveillance...
> Russian Invasion Sparks Global Wiper Malware Surge
Fortinet detected a 50% increase in destructive attacks in H2 2022
> Phishing Sites and Apps Use ChatGPT as Lure
Campaigns designed to steal card information and install malware
> A Realistic Look at Implications of ChatGPT for Cybercrime
Analyzing ChatGPT's capabilities and various claims about how it will revolutionize cybercrime.
> Open Source Flaws Found in 84% of Codebases
The figures come from Synopsys’ new Open Source Security and Risk Analysis report
> Hydrochasma Group Targets Asian Medical and Shipping Sectors
The hackers appear to have a possible interest in industries connected with COVID-19 treatments
> Escaping misconfigured VSCode extensions
TL;DR: This two-part blog series will cover how I found and disclosed three vulnerabilities in VSCode extensions and one vulnerability in VSCode itself (a security mitigation bypass assigned CVE-2022-41042 and awarded a $7,500 bounty). We will identify the underlying cause of each vulnerability and...
> Npm Packages Used to Distribute Phishing Links
The malicious packages were reportedly created using automated processes
> Putin Speech Interrupted by DDoS Attack
Outage impacts Russian state media websites
> Casino Del Sol
Le Casino Del Sol dans la région de Tucson a été la cible d'une tentative de cyberattaque le 21 février, entraînant une panne généralisée de ses systèmes, y compris les distributeurs automatiques, les systèmes de cartes de crédit et les jeux de table qui ne pouvaient accepter que du liquide. Le 27 f...
> Time Taken to Deploy Ransomware Drops 94%
Extortion found to be most common impact from cyber-attacks in 2022
> Call of Duty Developer Confirms Phishing Attempt but Not Breach
Security researchers say hackers successfully exfiltrated content
> Mercy Home for Children
L'entité Mercy Home for Children, une organisation de santé basée à Brooklyn, New York, a subi une cyberattaque le 21 février 2023, affectant les données personnelles de 356 personnes, dont un résident du Maine. L'incident a été découvert le jour même et impliquait une fuite de numéros de sécurité s...
> New Privilege Escalation Bug Class Found on macOS and iOS
The new class of privilege escalation bugs is based on the ForcedEntry attack
> Hackers Exploit Privilege Escalation Flaw on Windows Backup Service
The flaw is triggered using the Race Condition between temporary file creation and deletion