> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Avanan spots campaign leveraging Dynamic 365 Customer Voice
ALMA suspends astronomical observations
The news comes from the social media giant’s head of privacy in Europe, Elaine Fox
The EU cybersecurity agency released its 10th annual threat landscape report on November 3, 2022
Le groupe aéronautique Satys, sous-traitant d'Airbus, a été victime d'une cyberattaque massive qui a nécessité la mise en place d'une cellule de crise et la restauration de ses systèmes informatiques. L'attaque a impliqué le ransomware Dagon, une évolution de MountLocker et de Quantum.
The discovery comes from the BlackBerry Research & Intelligence Team
The parties have mutually resolved the matter, but details of the settlement were not provided
Trail of Bits is publicly disclosing CVE-2022-35737, which affects applications that use the SQLite library API. CVE-2022-35737 was introduced in SQLite version 1.0.12 (released on October 17, 2000) and fixed in release 3.39.2 (released on July 21, 2022). CVE-2022-35737 is exploitable on 64-bit syst...
Automated threats accounted for 62% of attacks last year
NCSC wants to determine "the vulnerability of the UK"
Des données médicales d'étudiants de San Diego ont été compromises lors d'une cyberattaque en octobre. Les noms et informations médicales des étudiants ont été compromis. Les responsables ont rapidement sécurisé le réseau, lancé une enquête et informé les autorités. Des mesures de sécurité supplémen...
More than 30 organizations compromised by off-the-shelf tools
The group banded together to engage in a sophisticated cybercrime and tax fraud scheme
Une cyberattaque sur ses systèmes d’informations mettant au ralenti les opérations comptables durant une période de trois semaines environ. En date du 31 décembre 2022, l’ensemble des opérations ont pu être faite normalement sans aucune conséquence sur la clôture de l’année 2022.
Chrome tabs remained open in the background, even while the smartphone was locked
Dropbox believes the actors behind the attack are the same that targeted GitHub users in September
Great news!
An article about ropci is in the latest free issue of the Pentest Magazine!
The article has a lot more info then my ropci blog post or the info on the ropci Github repo.
Get your copy and check it out! It also has an article about Nuclei, one of my favorite tools.
Cheers.
Link: https://p...
Lookout report finds over-reliance on unmanaged devices
Elon Musk’s arrival has opened the door for fraudsters