> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights significant threats and trends. A vulnerability under attack, traced to a China-hosted IP, underscores the need for robust bug-hunting tools like Anthropic's Mythos. The Warlock group, also linked to China, is exploiting Microsoft SharePoint vulnerabilities to deploy ransomware, while the Technical University of Denmark has suffered a breach exposing data for 200,000 users. Additionally, critical vulnerabilities in Fortra's BoKS and GitLab's AI Gateway have been patched, emphasizing ongoing security challenges. New developments in AI, such as doxx.net's platform to prevent AI misadventures, indicate a growing focus on managing AI risks.
|
// AI-powered summary generated at 16:01
Roughly 50% of all the apps analyzed were seen using the same AWS tokens found in other apps
The malware can also check if specific products are installed, particularly security software
2.5 million people were affected, in a breach that could spell more trouble down the line.
The flaw would allow the processing of maliciously crafted web content and arbitrary code execution
Document will help testers create benchmarks for security products
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Trend Micro warns of Linux-based ransomware
Vulnerability impacted social media firm’s Android app
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Initial infection begins with a phishing email containing a Microsoft Office attachment
The firm said the tools used to attack Cisco were also deployed to compromise one of its clients
Recently I read this excellent post by Evan Sultanik about exploiting pickle files on Trail of Bits. There was also a DefCon30 talk about backdooring pickle files by ColdwaterQ.
This got me curious to try out backdooring a pickle file myself.
Pickle files - the surprises Surprisingly Python pickle f...
Ofcom will be able to issue fines for non-compliance of up to 10% of turnover
IoT device manufacturers can now incorporate security at the start of the product life-cycle
GCP Goat is the Vulnerable application for learning the GCP Security
National Cybersecurity Alliance launches HBCU career program
Scammers spoofed legitimate banks’ phone numbers
GCP themed CTF
Data protection regulator begins criminal proceedings
The association between the three apparently unrelated campaigns was made by Cisco Talos