> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
Man allegedly handled over $400,000 in Ryuk proceeds
The advisory was compiled by CISA with the Multi-State Information Sharing & Analysis Center
Improving static analysis tools can be hard; once you’ve implemented a good tool based on a useful representation of a program and added a large number of rules to detect problems, how do you further enhance the tool’s bug-finding power? One (necessary) approach to coming up with new rules […]
The package manager started enforcing MFA on owners of gems with over 180 million total downloads
The study queries more than 950 IT and security professionals across the Americas, EMEA and APAC
Finding talent is hard, especially in the blockchain security industry. The space is new, so you won’t find engineers with decades of experience with smart contracts. Training is difficult, as the technology evolves constantly, and online content quickly becomes outdated. There are also a lot of mis...
Non-profit says Google Voice scams were the most reported threat
Manufacturing was most exposed to OT threats in 2021
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in June and July (note that previously published June Knowledge Base digest was incomplete):
Articles
Why do I see a "failed to connect B channel" Firebox log message?
Ho...
Zero Day Initiative says incomplete or faulty patches now commonplace
The new packages were masquerading as one of the most popular open-source packages on PyPI
Début août 2022, une attaque sophistiquée a visé les systèmes de l'organisation allemande IHK, incitant son fournisseur de services, IHK-GfI, à déconnecter ses 79 chambres de commerce de l'internet pour limiter les dégâts. Des experts du BSI et de la ZAC NRW soupçonnent des motivations d'espionnage...
The leak was caused by incorrect configurations of an online tracking tool from Meta
The research resulted in proof-of-concept exploits against seven market-leading automation firms
L'attaque a conduit à l'arrêt de tous les équipements informatiques et au redémarrage sur une nouvelle infrastructure IT. Tous les départements de l'entreprise ont été affectés et la société a eu recours à l'activité partielle afin de compenser.
Electron-based desktop application including Discord, Microsoft Teams and VScode were at risk from a series of vulnerabilities
American teenager explains how he was able to hack his local high school district
Agari warns of multi-stage phishing threat
APT group focused on classic data theft via email accounts
South Staffordshire Water admits it was compromised