> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Regulator’s order requires firm to improve data security practices
Insurer says claimants have risen in nearly every sector
Le groupe aéronautique Satys, sous-traitant d'Airbus, a été victime d'une cyberattaque massive qui a nécessité la mise en place d'une cellule de crise et la restauration de ses systèmes informatiques. L'attaque a impliqué le ransomware Dagon, une évolution de MountLocker et de Quantum.
The guidance is for network defenders and leaders to understand and respond to DDoS attacks
The researchers were able to obtain the ZIP file containing the samples for the data breach
Trail of Bits is publicly disclosing CVE-2022-35737, which affects applications that use the SQLite library API. CVE-2022-35737 was introduced in SQLite version 1.0.12 (released on October 17, 2000) and fixed in release 3.39.2 (released on July 21, 2022). CVE-2022-35737 is exploitable on 64-bit syst...
The firm is one of the defense department's external providers employed to run one of its websites
Aurubis forced to take IT systems offline
Des données médicales d'étudiants de San Diego ont été compromises lors d'une cyberattaque en octobre. Les noms et informations médicales des étudiants ont été compromis. Les responsables ont rapidement sécurisé le réseau, lancé une enquête et informé les autorités. Des mesures de sécurité supplémen...
Akamai study finds low levels of trust among consumers
One year’s worth of messages reportedly downloaded from former PM’s device
Une cyberattaque sur ses systèmes d’informations mettant au ralenti les opérations comptables durant une période de trois semaines environ. En date du 31 décembre 2022, l’ensemble des opérations ont pu être faite normalement sans aucune conséquence sur la clôture de l’année 2022.
The document is the result of a July 2021 security memorandum signed by President Biden
These attackers reportedly spent at least 18 months on victim networks
Great news!
An article about ropci is in the latest free issue of the Pentest Magazine!
The article has a lot more info then my ropci blog post or the info on the ropci Github repo.
Get your copy and check it out! It also has an article about Nuclei, one of my favorite tools.
Cheers.
Link: https://p...
Microsoft said the worm had alternate infection methods beyond its original USB drive spread
IEEE report predicts biggest risks for 2023
This post will highlight a pattern I have seen across multiple production Microsoft Azure Active Directory tenants which led to MFA bypasses using ROPC.
The key take-away: Always enforce MFA! Sounds easy, but there are often misconfigurations and unexpected exceptions. So, test your own AAD tenant f...
June vishing attack led to compromise of customer data