> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights several key threats and trends. The suspected member of the ShinyHunters group, known as "Rey," has been detained in Jordan, aiding the FBI in identifying other group members involved in digital extortion. Meanwhile, a new China-aligned cyber espionage group, TA419, has been targeting U.S. AI policy experts through credential phishing campaigns tied to Microsoft. This indicates a rising trend in nation-state actors focusing on critical technology sectors. Additionally, ongoing analysis of User Agent Strings in honeypot logs reveals continued interest in understanding attacker behaviors. These developments underscore the persistent threats from both cybercriminal groups and state-sponsored actors in the evolving cybersecurity landscape.
|
// AI-powered summary generated at 08:00
Richland Community College a été victime d'une cyberattaque le 17 février, entraînant des perturbations importantes de ses systèmes, notamment la mise hors service des serveurs réseau, des téléphones et de certains e-mails départementaux. Bien que les cours en personne se poursuivent et que l'accès...
Le département du Gers en France a connu une augmentation des cyberattaques, comme en témoigne l'infection par un virus du serveur informatique de la mairie de Cazaubon. Le vice-amiral d’escadre Arnaud Coustillière souligne la structuration quasi industrielle des cyberattaquants et l'importance de l...
Combined, the two groups have launched BEC campaigns in at least 13 different languages
Le district scolaire de Minneapolis a été victime d'une cyberattaque en février 2023, lors de laquelle des hackers ont volé des informations sensibles sur les élèves et les enseignants. Les responsables du district ont caché l'ampleur de la violation de données aux familles et aux élèves, en dépit d...
Core functions are intact, but the city has taken certain non-emergency systems offline
The phishing email warned users that there had been fraud on the account
I discovered a logic bug in the readline dependency that partially reveals file information when parsing the file specified in the INPUTRC environment variable. This could allow attackers to move laterally on a box where sshd is running, a given user is able to login, and the user’s private key […]
Scammers made an estimated $30m in profits in 2022
The average malware variant now utilizes 11 TTPs
Last year we published UnZiploc, our research into Huawei’s OTA update implementation. Back then, we have successfully identified logic vulnerabilities in the implementation of the Huawei recovery image that allowed root privilege code execution to be achieved by remote or local attackers. After Hua...
Security and ethical concerns raised by surveillance commissioner
We have identified a new Toc-ToU race condition vulnerability in Huawei’s recovery image implementation of SD-card based firmware updates. The vulnerability can be exploited to achieve arbitrary code execution in recovery mode, enabling unauthentic firmware updates, firmware downgrades to a known vu...
La municipalité de Marechal Floriano a été victime d'une cyberattaque qui a crypté les données de la préfecture, rendant les services publics et le site officiel inaccessibles. Un rapport a été déposé auprès de la police civile et les techniciens ont isolé la menace, mais une grande partie des donné...
It is an initiative designed to limit user data sharing in digital advertising
It shows the threat actor trying to convince Royal Mail to pay the ransom using various techniques
In fall 2022, Trail of Bits audited cURL, a widely-used command-line utility that transfers data between a server and supports various protocols. The project coincided with a Trail of Bits maker week, which meant that we had more manpower than we usually do, allowing us to take a nonstandard approac...
The attacks mainly targeted victims in the US but also in the UK, Turkey, and the Philippines
Recorded Future analyzed how threat actors have been exploiting VMware ESXi vulnerabilities over the past three years
Le district scolaire Sweetwater Union a confirmé qu'une cyberattaque avait causé une panne de système de plusieurs jours en février. Les données personnelles des employés, des étudiants et des familles ont été compromises. L'attaque a été découverte en mai et le district a mis en place des mesures d...
February Patch Tuesday contains updates for over 70 CVEs