> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
It is due partly to a major phishing attack DHL warned about before the quarter started
The UK Cyber Security Council has announced a pilot program designed to create the country’s first chartered cyber professionals
Une cyberattaque sur ses systèmes d’informations mettant au ralenti les opérations comptables durant une période de trois semaines environ. En date du 31 décembre 2022, l’ensemble des opérations ont pu être faite normalement sans aucune conséquence sur la clôture de l’année 2022.
Google forced to remove over a dozen malicious apps
Interserve slammed by regulator after employee data breach
Great news!
An article about ropci is in the latest free issue of the Pentest Magazine!
The article has a lot more info then my ropci blog post or the info on the ropci Github repo.
Get your copy and check it out! It also has an article about Nuclei, one of my favorite tools.
Cheers.
Link: https://p...
Cops also identify opportunities to enhance law enforcement
The campaigns are set up to provide fake services to the citizens and steal their credentials
This post will highlight a pattern I have seen across multiple production Microsoft Azure Active Directory tenants which led to MFA bypasses using ROPC.
The key take-away: Always enforce MFA! Sounds easy, but there are often misconfigurations and unexpected exceptions. So, test your own AAD tenant f...
GUAC aims to bring together many different sources of software security metadata
JFrog scanned over eight million artifacts in the most common open-source software registries
There are some neat TTPs that I don’t use frequently, and if the time arises, I need to dig up details again. So, I figured to write some of them down, starting with SSH Agent Hijacking.
What is SSH Agent Hijacking? Short story, if you have keys added to an SSH Agent an adversary with root permissio...
Lindy Cameron argues that smart cities are becoming an attractive target for threat actors, including nation states
Tim Brown, CISO and VP of security at SolarWinds shared his experiences remediating a major cyber-attack during Mandiant’s mWISE event on October 18, 2022
With ECR permissions you can easily distribute a backdoor to production servers, developer's laptops, or CI/CD pipelines and own the environment by gaining privileged permissions.
Interpol study warns that many threats are expected to increase
Ransom demands soar to $17m, according to new report
Andrew Haberlandt During my summer internship at Trail of Bits, I worked on the fork of the RBPF JIT compiler that is used to execute Solana smart contracts. The RBPF JIT compiler plays a critical role on the Solana blockchain, as it facilitates the execution of contracts on validator nodes by defa...
Spanish police apprehend suspect in Tenerife
The data also shows ransomware groups continuing to grow in volume and sophistication