[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> GitHub Bug Exposed Repositories to Hijacking
Checkmarx warns over 10,000 popular packages could be vulnerable
> Medibank Backtracks: All Customer Data Was Exposed to Hackers
Insurer’s incident response processes under fire
> Stranger Strings: An exploitable flaw in SQLite
Trail of Bits is publicly disclosing CVE-2022-35737, which affects applications that use the SQLite library API. CVE-2022-35737 was introduced in SQLite version 1.0.12 (released on October 17, 2000) and fixed in release 3.39.2 (released on July 21, 2022). CVE-2022-35737 is exploitable on 64-bit syst...
> Vice Society Ransomware Campaigns Continue to Impact US Education Sector
In several cases, the group did not deploy ransomware and performed extortion using stolen data
> Typosquat Campaign Targeting Android, Windows Users Now Counts 600+ Domains
The list of suspicious domains grew to more than 600, with 9 of these created in the last week
> San Diego Unified School District
Des données médicales d'étudiants de San Diego ont été compromises lors d'une cyberattaque en octobre. Les noms et informations médicales des étudiants ont été compromis. Les responsables ont rapidement sécurisé le réseau, lancé une enquête et informé les autorités. Des mesures de sécurité supplémen...
> Hive Ransomware Group Leaks Data Stolen in Tata Power Cyber-Attack
The leak reportedly affected several of Tata’s 12 million customers and included various PII
> London's New Cyber Resilience Centre Set to Fight Cybercrime in the Capital
This is the latest of a network of nine cybersecurity centers spread across England and Wales to supper SMEs against cybercrime
> SOMDIAA
Une cyberattaque sur ses systèmes d’informations mettant au ralenti les opérations comptables durant une période de trois semaines environ. En date du 31 décembre 2022, l’ensemble des opérations ont pu être faite normalement sans aucune conséquence sur la clôture de l’année 2022.
> Supply Chain Attacks or Vulnerabilities Experienced by 80% of Orgs, BlackBerry Finds
The report highlighted the enormous business costs of supply chain software attacks
> Ransomware Threat Shifts from US to EMEA and APAC
SonicWall figures show overall attacks trending down
> PenTest Magazine Open Source Toolkit: ropci
Great news! An article about ropci is in the latest free issue of the Pentest Magazine! The article has a lot more info then my ropci blog post or the info on the ropci Github repo. Get your copy and check it out! It also has an article about Nuclei, one of my favorite tools. Cheers. Link: https://p...
> See Tickets Discloses Major Card Data Breach
Unspecified number of customers impacted over 2.5 years
> ICO Warns of "Immature" Biometric Tech
UK privacy regulator says vulnerable people may be at risk
> ROPC - So, you think you have MFA?
This post will highlight a pattern I have seen across multiple production Microsoft Azure Active Directory tenants which led to MFA bypasses using ROPC. The key take-away: Always enforce MFA! Sounds easy, but there are often misconfigurations and unexpected exceptions. So, test your own AAD tenant f...
> Data Breaches Rise By 70% Globally in Q3 2022
Russia had the most breaches overall and France had the highest breach density
> Apple Fixes Actively Exploited iOS and iPadOS Zero-Day Vulnerability
The out-of-bounds write issue in the kernel could be exploited to execute arbitrary code
> TTP Diaries: SSH Agent Hijacking
There are some neat TTPs that I don’t use frequently, and if the time arises, I need to dig up details again. So, I figured to write some of them down, starting with SSH Agent Hijacking. What is SSH Agent Hijacking? Short story, if you have keys added to an SSH Agent an adversary with root permissio...
> POS Malware Used to Steal Details of Over 167,000 Credit Cards
The operators could make over $3m if they decide to sell the card dumps on underground forums
> Ukraine Warns of Cuba Ransomware Campaign
Financially motivated affiliate appears to be to blame