[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> Everything you need to know about the OpenSSL 3.0.7 Patch (CVE-2022-3602 & CVE-2022-3786)
> FTC Takes Enforcement Action Against EdTech Giant Chegg
Regulator’s order requires firm to improve data security practices
> Fraudulent Instruction Losses Spike in 2022
Insurer says claimants have risen in nearly every sector
> Satys
Le groupe aéronautique Satys, sous-traitant d'Airbus, a été victime d'une cyberattaque massive qui a nécessité la mise en place d'une cellule de crise et la restauration de ses systèmes informatiques. L'attaque a impliqué le ransomware Dagon, une évolution de MountLocker et de Quantum.
> CISA, FBI, MS-ISAC Publish Guidelines For Federal Agencies on DDoS Attacks
The guidance is for network defenders and leaders to understand and respond to DDoS attacks
> Data Breach of Missile Maker MBDA May Have Been Real: CloudSEK
The researchers were able to obtain the ZIP file containing the samples for the data breach
> Stranger Strings: An exploitable flaw in SQLite
Trail of Bits is publicly disclosing CVE-2022-35737, which affects applications that use the SQLite library API. CVE-2022-35737 was introduced in SQLite version 1.0.12 (released on October 17, 2000) and fixed in release 3.39.2 (released on July 21, 2022). CVE-2022-35737 is exploitable on 64-bit syst...
> Hackers Target Australian Defense Communications Platform With Ransomware
The firm is one of the defense department's external providers employed to run one of its websites
> Europe's Biggest Copper Producer Hit by Cyber-Attack
Aurubis forced to take IT systems offline
> San Diego Unified School District
Des données médicales d'étudiants de San Diego ont été compromises lors d'une cyberattaque en octobre. Les noms et informations médicales des étudiants ont été compromis. Les responsables ont rapidement sécurisé le réseau, lancé une enquête et informé les autorités. Des mesures de sécurité supplémen...
> Most Online Shoppers Would Leave Retailer Following Breach
Akamai study finds low levels of trust among consumers
> Russia Suspected in Truss Phone Hacking Scandal
One year’s worth of messages reportedly downloaded from former PM’s device
> SOMDIAA
Une cyberattaque sur ses systèmes d’informations mettant au ralenti les opérations comptables durant une période de trois semaines environ. En date du 31 décembre 2022, l’ensemble des opérations ont pu être faite normalement sans aucune conséquence sur la clôture de l’année 2022.
> CISA Unveils Cybersecurity Goals For Critical Infrastructure Sectors
The document is the result of a July 2021 security memorandum signed by President Biden
> Cranefly Hackers Use Stealthy Techniques to Deliver and Control Malware
These attackers reportedly spent at least 18 months on victim networks
> PenTest Magazine Open Source Toolkit: ropci
Great news! An article about ropci is in the latest free issue of the Pentest Magazine! The article has a lot more info then my ropci blog post or the info on the ropci Github repo. Get your copy and check it out! It also has an article about Nuclei, one of my favorite tools. Cheers. Link: https://p...
> Raspberry Robin Worm Actors Linked to Clop, LockBit Ransomware Groups
Microsoft said the worm had alternate infection methods beyond its original USB drive spread
> Cloud and Hybrid Working Security Concerns Surge
IEEE report predicts biggest risks for 2023
> ROPC - So, you think you have MFA?
This post will highlight a pattern I have seen across multiple production Microsoft Azure Active Directory tenants which led to MFA bypasses using ROPC. The key take-away: Always enforce MFA! Sounds easy, but there are often misconfigurations and unexpected exceptions. So, test your own AAD tenant f...
> Twilio Reveals Further Security Breach
June vishing attack led to compromise of customer data