> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
New open source project set to reduce operational pain for SecOps analysts
Accenture warns that stolen data is flooding the cybercrime underground
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in June and July (note that previously published June Knowledge Base digest was incomplete):
Articles
Why do I see a "failed to connect B channel" Firebox log message?
Ho...
Interpol warns of growing role of money mules
The campaign is not only ongoing, the threat actors increased its efforts to compromise targets using VileRAT
Début août 2022, une attaque sophistiquée a visé les systèmes de l'organisation allemande IHK, incitant son fournisseur de services, IHK-GfI, à déconnecter ses 79 chambres de commerce de l'internet pour limiter les dégâts. Des experts du BSI et de la ZAC NRW soupçonnent des motivations d'espionnage...
The report shows an 11% rise in archive files containing malware, including LNK files
The Emotet botnet continues to evolve and now includes a credit card stealer module
L'attaque a conduit à l'arrêt de tous les équipements informatiques et au redémarrage sur une nouvelle infrastructure IT. Tous les départements de l'entreprise ont été affectés et la société a eu recours à l'activité partielle afin de compenser.
West Sussex man blackmailed his victims
Malware and botnet detections also soar
You think you’ve found a critical bug in a Solidity smart contract that, if exploited, could drain a widely used cryptocurrency exchange’s funds. To confirm that it’s really a bug, you need to figure out the value at an obscure storage slot that has no getter method. Adrenaline courses […]
August Patch Tuesday addresses over 120 vulnerabilities
Some of these packages were capable of stealing user credentials and environment variables
Jon L provides an update on the NCSC's guidance on the 'WannaCry' ransomware.
Tornado Cash would have been used to launder more than $7b in virtual currency since its foundation
The report extends CISA's “first seen” date and the geolocation of the target to other countries
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to learn the value of randomized kernel pointers. The vulnerability can be used to defeat KASLR mitigation.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlo...
Former NHS employee ordered to pay victims compensation
Firm tight-lipped on how many customers are affected