> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
The malware was first released for sale on January 26, 2022 as an HVNC implant, but later evolved
The malware is reportedly capable of server takedown, Wi-Fi attacks and application layer attacks
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
New campaign disguised as fake Cloudflare pop-up
General Bytes confirms serious attack last week
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Holdcroft Motor Group says most systems back online now
The majority of the attacks spotted relied primarily on SQL injections on targeted domains
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
Cryptojackers take advantage of legitimate system binaries on more than 200,000 devices daily
The vulnerability gave hackers the ability to infiltrate WebKit, the engine that powers Safari
Improving static analysis tools can be hard; once you’ve implemented a good tool based on a useful representation of a program and added a large number of rules to detect problems, how do you further enhance the tool’s bug-finding power? One (necessary) approach to coming up with new rules […]
The UK government report found that many leaders only review cybersecurity practices following an incident
Tiny Baltic nation riles Russia by removing monuments
Finding talent is hard, especially in the blockchain security industry. The space is new, so you won’t find engineers with decades of experience with smart contracts. Training is difficult, as the technology evolves constantly, and online content quickly becomes outdated. There are also a lot of mis...
EE says AI tech is stopping international scams
PwC report finds execs are paying more attention to risk management
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in June and July (note that previously published June Knowledge Base digest was incomplete):
Articles
Why do I see a "failed to connect B channel" Firebox log message?
Ho...
Most Bumblebee infections started by end-users executing LNK files
ATMZOW infected at least 483 websites across four continents since the beginning of 2019