[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 12:00

> #BHUSA: New Open Source Group Set to Streamline Threat Detection
New open source project set to reduce operational pain for SecOps analysts
> Ransomware Data Theft Epidemic Fuelling BEC Attacks
Accenture warns that stolen data is flooding the cybercrime underground
> Knowledge Base Digest - July 2022
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in June and July (note that previously published June Knowledge Base digest was incomplete): Articles Why do I see a "failed to connect B channel" Firebox log message? Ho...
> Suspected $3m Romance Scammer Extradited to Japan
Interpol warns of growing role of money mules
> DeathStalker's VileRAT Continues to Target Foreign and Crypto Exchanges
The campaign is not only ongoing, the threat actors increased its efforts to compromise targets using VileRAT
> IHK Kassel-Marburg
Début août 2022, une attaque sophistiquée a visé les systèmes de l'organisation allemande IHK, incitant son fournisseur de services, IHK-GfI, à déconnecter ses 79 chambres de commerce de l'internet pour limiter les dégâts. Des experts du BSI et de la ZAC NRW soupçonnent des motivations d'espionnage...
> Cyber-criminals Shift From Macros to Shortcut Files to Hack Business PCs, HP Reports
The report shows an 11% rise in archive files containing malware, including LNK files
> Emotet Tops List of July's Most Widely Used Malware
The Emotet botnet continues to evolve and now includes a credit card stealer module
> Semikron
L'attaque a conduit à l'arrêt de tous les équipements informatiques et au redémarrage sur une nouvelle infrastructure IT. Tous les départements de l'entreprise ont été affectés et la société a eu recours à l'activité partielle afin de compenser.
> Predator Pleads Guilty After Targeting Thousands of Girls Online
West Sussex man blackmailed his victims
> Exploit Activity Surges 150% in Q2 Thanks to Log4Shell
Malware and botnet detections also soar
> Shedding smart contract storage with Slither
You think you’ve found a critical bug in a Solidity smart contract that, if exploited, could drain a widely used cryptocurrency exchange’s funds. To confirm that it’s really a bug, you need to figure out the value at an obscure storage slot that has no getter method. Adrenaline courses […]
> Surge in CVEs as Microsoft Fixes Exploited Zero Day Bugs
August Patch Tuesday addresses over 120 vulnerabilities
> New Malicious Python Libraries Found on PyPI Repository
Some of these packages were capable of stealing user credentials and environment variables
> 'WannaCry' ransomware: guidance updates
Jon L provides an update on the NCSC's guidance on the 'WannaCry' ransomware.
> US Treasury Sanctions Virtual Currency Mixer For Connections With Lazarus Group
Tornado Cash would have been used to launder more than $7b in virtual currency since its foundation
> Report Provides Updates on July's Maui Ransomware Incident
The report extends CISA's “first seen” date and the geolocation of the target to other countries
> CVE-2022-22256: Huawei HWLog KASLR Leak
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to learn the value of randomized kernel pointers. The vulnerability can be used to defeat KASLR mitigation. Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlo...
> Health Adviser Fined After Illegally Accessing Medical Records
Former NHS employee ordered to pay victims compensation
> Smishing Attack Led to Major Twilio Breach
Firm tight-lipped on how many customers are affected