> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
Jen Easterly discusses the progress and challenges at CISA
Nigerian nationals accused of targeting US universities
Finding talent is hard, especially in the blockchain security industry. The space is new, so you won’t find engineers with decades of experience with smart contracts. Training is difficult, as the technology evolves constantly, and online content quickly becomes outdated. There are also a lot of mis...
Most companies do not have enough coverage to recover from ransomware
Researchers find many deployments have authentication disabled
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in June and July (note that previously published June Knowledge Base digest was incomplete):
Articles
Why do I see a "failed to connect B channel" Firebox log message?
Ho...
Meta is also introducing an encrypted backup feature called Secure Storage
The devices were powered by MediaTek chips and susceptible to two kinds of attacks
Début août 2022, une attaque sophistiquée a visé les systèmes de l'organisation allemande IHK, incitant son fournisseur de services, IHK-GfI, à déconnecter ses 79 chambres de commerce de l'internet pour limiter les dégâts. Des experts du BSI et de la ZAC NRW soupçonnent des motivations d'espionnage...
20% of the earned profit from the distribution of the ransomware will be paid to the affiliates
Katie Moussouris explains why simply having a bug bounty program isn't enough to fix security problems
L'attaque a conduit à l'arrêt de tous les équipements informatiques et au redémarrage sur une nouvelle infrastructure IT. Tous les départements de l'entreprise ont été affectés et la société a eu recours à l'activité partielle afin de compenser.
The UK Ministry of Defence is actively training staff to confront individuals that are engaged in risky behaviours
Investigative journalist Kim Zetter explains that Stuxnet continues to serves as a precedent for attacks happening now
You think you’ve found a critical bug in a Solidity smart contract that, if exploited, could drain a widely used cryptocurrency exchange’s funds. To confirm that it’s really a bug, you need to figure out the value at an obscure storage slot that has no getter method. Adrenaline courses […]
State Department offers $10m reward for info on notorious group
CISA issues new alert about RaaS variant
Jon L provides an update on the NCSC's guidance on the 'WannaCry' ransomware.
Managed service provider Advanced publishes update on recent cyber incident
The toolkit protects election infrastructure targeted by phishing, ransomware and DDoS attacks