> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights significant threats and trends. A vulnerability under attack, traced to a China-hosted IP, underscores the need for robust bug-hunting tools like Anthropic's Mythos. The Warlock group, also linked to China, is exploiting Microsoft SharePoint vulnerabilities to deploy ransomware, while the Technical University of Denmark has suffered a breach exposing data for 200,000 users. Additionally, critical vulnerabilities in Fortra's BoKS and GitLab's AI Gateway have been patched, emphasizing ongoing security challenges. New developments in AI, such as doxx.net's platform to prevent AI misadventures, indicate a growing focus on managing AI risks.
|
// AI-powered summary generated at 16:01
En septembre 2022, Toulouse INP a été victime d'une cyberattaque avec le ransomware AvosLocker. L'attaque a été déclenchée via un compte étudiant compromis et a bloqué l'annuaire, les mécanismes d'authentification et les capacités d'accÚs physique aux bùtiments. Des mesures ont été prises pour rétab...
Wordfence claimed to have blocked 4,948,926 attacks targeting this vulnerability
The report also found that 89% of them experienced an average of 43 attacks in the past 12 months
This week I learned about a design flaw with pip download, which allows an adversary to run arbitrary code.
I assumed that running pip install means anything could happen, but pip download seems a bit surprising.
Both seem useful for red teaming though.
Background This post from Yehuda Gelb named Au...
Figure is more than 10% higher than cross-sector average
We are deeply saddened by the passing of Her Majesty Queen Elizabeth II. We send our sincerest condolences to the Royal Family.
Background If you havenât done so yet, read my first Zix exploitation article: Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT, which established baselines to abuse the native organizational trust that Zix provides to perform spear phishing on the affected company. Shortly...
The vulnerabilities, now fixed, allowed for a potential man in the middle attack
The document analyzes data aggregated from visibility into more than 500,000 IT assets
Background If you havenât done so yet, read my first Zix exploitation article: Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT, which established baselines to abuse the native organizational trust that Zix provides to perform spear phishing on the affected company. Shortly...
DEV-0270 leverages exploits for newly disclosed vulnerabilities to gain access to devices
The buyout fell through hours before the UK company said that millions of pounds in revenue had been wrongly recognized in this year's accounts instead of last year's
2.5 million people were affected, in a breach that could spell more trouble down the line.
Group has been active since at least 2015
Apparel giant detects unusual activity on accounts
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Tehran denied any link, claiming Tiranaâs action was âbased on such baseless claimsâ
Facilities used to spread Russian disinformation
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
The campaign relied on spearphishing techniques to initiate infection chains