> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Checkmarx warns over 10,000 popular packages could be vulnerable
Insurer’s incident response processes under fire
Trail of Bits is publicly disclosing CVE-2022-35737, which affects applications that use the SQLite library API. CVE-2022-35737 was introduced in SQLite version 1.0.12 (released on October 17, 2000) and fixed in release 3.39.2 (released on July 21, 2022). CVE-2022-35737 is exploitable on 64-bit syst...
In several cases, the group did not deploy ransomware and performed extortion using stolen data
The list of suspicious domains grew to more than 600, with 9 of these created in the last week
Des données médicales d'étudiants de San Diego ont été compromises lors d'une cyberattaque en octobre. Les noms et informations médicales des étudiants ont été compromis. Les responsables ont rapidement sécurisé le réseau, lancé une enquête et informé les autorités. Des mesures de sécurité supplémen...
The leak reportedly affected several of Tata’s 12 million customers and included various PII
This is the latest of a network of nine cybersecurity centers spread across England and Wales to supper SMEs against cybercrime
Une cyberattaque sur ses systèmes d’informations mettant au ralenti les opérations comptables durant une période de trois semaines environ. En date du 31 décembre 2022, l’ensemble des opérations ont pu être faite normalement sans aucune conséquence sur la clôture de l’année 2022.
The report highlighted the enormous business costs of supply chain software attacks
SonicWall figures show overall attacks trending down
Great news!
An article about ropci is in the latest free issue of the Pentest Magazine!
The article has a lot more info then my ropci blog post or the info on the ropci Github repo.
Get your copy and check it out! It also has an article about Nuclei, one of my favorite tools.
Cheers.
Link: https://p...
Unspecified number of customers impacted over 2.5 years
UK privacy regulator says vulnerable people may be at risk
This post will highlight a pattern I have seen across multiple production Microsoft Azure Active Directory tenants which led to MFA bypasses using ROPC.
The key take-away: Always enforce MFA! Sounds easy, but there are often misconfigurations and unexpected exceptions. So, test your own AAD tenant f...
Russia had the most breaches overall and France had the highest breach density
The out-of-bounds write issue in the kernel could be exploited to execute arbitrary code
There are some neat TTPs that I don’t use frequently, and if the time arises, I need to dig up details again. So, I figured to write some of them down, starting with SSH Agent Hijacking.
What is SSH Agent Hijacking? Short story, if you have keys added to an SSH Agent an adversary with root permissio...
The operators could make over $3m if they decide to sell the card dumps on underground forums
Financially motivated affiliate appears to be to blame