> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Star failed to disclose payment for promotional content
Dalke reportedly requested $85,000 in return for additional information in his possession
tl;dr: Our publicly available Semgrep ruleset now has 11 rules dedicated to the misuse of machine learning libraries. Try it out now! Picture this: You’ve spent months curating images, trying out different architectures, downloading pretrained models, messing with Kubernetes, and you’re finally read...
Payment details of some of the victims were successfully stolen by the attackers
ESET said the vulnerability was exploited at least twice via a specific user-mode module
La Commission des valeurs mobilières de Hong Kong (SFC) a blâmé et sanctionné Six Fook Securities (ou Luk Fook Securities) pour des lacunes importantes dans ses mesures de cybersécurité. L'incident, une attaque par ransomware survenue en septembre 2022, a causé des perturbations majeures aux infrast...
Marketers made over 820,000 illegal calls
School district is investigating authenticity of the trove
All about the new look for Hacking The Cloud v2.
Duo paid bribes and kickbacks to patient marketers
The group continued to use the LookBack backdoor, but also several new types of malware
On a network and need credentials? Try password spraying the domain controller directly.
A few years ago, I wrote this password spray tool called gospray that was used succesfully in a couple of engagements since. It does an LDAP bind directly against the domain controller to validate credentials. T...
The behavior of the actors was reportedly identical to what was described by Minerva Labs in 2021
The advisory suggests Zinc has targeted media, defense and aerospace, and IT services
In October 2019, a security researcher found a devastating vulnerability in Tornado.cash, a decentralized, non-custodial mixer on the Ethereum network. Tornado.cash uses zero-knowledge proofs (ZKPs) to allow its users to privately deposit and withdraw funds. The proofs are supposed to guarantee that...
The vulnerabilities were first discovered by Vietnamese cybersecurity firm GTSC
NCSC CEO, Lindy Cameron, outlines the UK's observations of the cyber dimension of the Russia-Ukraine conflict
The liability rules allow for compensation for damage when manufacturers fail to address cybersecurity vulnerabilities
The tool was written in Chinese and seemed China-based due to its C2 infrastructure
Cisco Talos discovered the malicious campaign in August 2022