> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Black Axe syndicate responsible for multimillion-dollar losses
There are some neat TTPs that I don’t use frequently, and if the time arises, I need to dig up details again. So, I figured to write some of them down, starting with SSH Agent Hijacking.
What is SSH Agent Hijacking? Short story, if you have keys added to an SSH Agent an adversary with root permissio...
The multi-vector, 2.5Tbps attack consisted of UDP and TCP floods
The data breach saw Zoetop allegedly trying to keep the real impact of the leak quiet
With ECR permissions you can easily distribute a backdoor to production servers, developer's laptops, or CI/CD pipelines and own the environment by gaining privileged permissions.
An average of 2297 attacks against organizations were recorded every week
Jake Moore, global cybersecurity advisor at ESET, shared at DTX Europe 2022 how he used a fake social media profile to hack employees of a company
Andrew Haberlandt During my summer internship at Trail of Bits, I worked on the fork of the RBPF JIT compiler that is used to execute Solana smart contracts. The RBPF JIT compiler plays a critical role on the Solana blockchain, as it facilitates the execution of contracts on validator nodes by defa...
Consumers should protect themselves by using least-privilege principles
Consultancy firm Booz Allen has published a comprehensive report on Chinese-sponsored threat
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in August and September.
Articles
AuthPoint ADFS agent installation fails on secondary server
AuthPoint Gateway status is Not Installed or Not Connected after upgrade to...
The group is characterized by the use of a stolen digital certificate issued by DEEPSoft
YoWhatsApp v2.22.11.75 was distributed via ads on Android apps like Snaptube and VidMate
Earlier this year, I successfully completed my internship at Trail of Bits and secured a full-time position as a Blockchain Security Analyst. This post is not intended to be a technical description of the work I did during my internship. Rather, it is intended to describe my general experience as a...
Budworm leveraged the Log4j vulnerabilities to compromise the Apache Tomcat service on servers
Warning to orgnaizations to be aware of risky devices across IT, IoT, OT and IoMT
tl;dr: Our publicly available Semgrep ruleset now has 11 rules dedicated to the misuse of machine learning libraries. Try it out now! Picture this: You’ve spent months curating images, trying out different architectures, downloading pretrained models, messing with Kubernetes, and you’re finally read...
The NCSC guidance has been issued amid a significant increase in supply chain attacks in recent years
The Russia-Ukraine conflict highlights the value of defensive cybersecurity, says Dr Alexi Drew
Vidar, an infostealer, has entered the top 10 list in eighth place for the first time