[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 16:01

> Vulnerabilities Found in Airplane WiFi Devices, Passengers' Data Exposed
The flaws affected the Flexlan FX3000 and FX2000 series wireless LAN devices made by Contec
> SparklingGoblin APT Targeted Hong Kong University With New Linux Backdoor
Eset also said the same university was targeted during student protests in May 2020
> Toulouse INP
En septembre 2022, Toulouse INP a été victime d'une cyberattaque avec le ransomware AvosLocker. L'attaque a été déclenchée via un compte étudiant compromis et a bloqué l'annuaire, les mécanismes d'authentification et les capacités d'accès physique aux bâtiments. Des mesures ont été prises pour rétab...
> FormBook Knocks Off Emotet As Most Used Malware in August
The report also suggested the Android spyware Joker took third place in the mobile index
> Four-Fifths of Firms Hit by Critical Cloud Security Incident
Data leaks, breaches and intrusions caused headaches over past year
> Malicious Python Packages and Code Execution via pip download
This week I learned about a design flaw with pip download, which allows an adversary to run arbitrary code. I assumed that running pip install means anything could happen, but pip download seems a bit surprising. Both seem useful for red teaming though. Background This post from Yehuda Gelb named Au...
> DDoS Attacks on UK Firms Surge During Ukraine War
Overall incidents fell in H1 2022, according to FOI data
> Microsoft Fixes Two Zero-Days This Patch Tuesday
Redmond passes 1000 CVEs for the year already
> Stealing Data with Zix - Bypassing Data Loss Prevention Policies
Background If you haven’t done so yet, read my first Zix exploitation article: Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT, which established baselines to abuse the native organizational trust that Zix provides to perform spear phishing on the affected company. Shortly...
> iOS 16 Launches With Lockdown Mode, Spyware Protection, Safety Check
iOS 16 supports iPhone devices starting from the iPhone 8
> ShadowPad-Associated Hackers Targeted Asian Governments
The attacks have been underway since early 2021 and appear focused on intelligence gathering
> Stealing Data with Zix - Bypassing Data Loss Prevention Policies
Background If you haven’t done so yet, read my first Zix exploitation article: Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT, which established baselines to abuse the native organizational trust that Zix provides to perform spear phishing on the affected company. Shortly...
> Hackers Steal Steam Credentials With 'Browser-in-the-Browser' Technique
Some of the Steam accounts stolen were reportedly valued between $100,000 and $300,000
> Ransomware Gang Hacks VoIP for Initial Access
Mitel MiVoice appliance bug exploited in sophisticated attack
> Student Loan Breach Exposes 2.5M Records
2.5 million people were affected, in a breach that could spell more trouble down the line.
> Iranian Hackers Launch Renewed Attack on Albania
Prime Minister warns of disruption at border crossings
> Researchers Warn of 674% Surge in Deadbolt Ransomware
Malware continues to infect QNAP devices
> Watering Hole Attacks Push ScanBox Keylogger
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
> US Treasury Sanctions Iranian Minister Over Hacking of Govt and Allies
Iran would have directed several networks of cyber threat actors in support of its political goals
> High Severity Vulnerabilities Found in HP Enterprise Devices
The flaws affect HP EliteBook devices and have CVSS scores between 7.5 and 8.2