> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
Over five million accounts were exposed
Digital supplier hit by suspected ransomware
Début août 2022, une attaque sophistiquée a visé les systèmes de l'organisation allemande IHK, incitant son fournisseur de services, IHK-GfI, à déconnecter ses 79 chambres de commerce de l'internet pour limiter les dégâts. Des experts du BSI et de la ZAC NRW soupçonnent des motivations d'espionnage...
The malware was detected in campaigns targeting firms in the industrial and pharmaceutical space
The new feature enables access to a site before it is accessible globally
L'attaque a conduit à l'arrêt de tous les équipements informatiques et au redémarrage sur une nouvelle infrastructure IT. Tous les départements de l'entreprise ont été affectés et la société a eu recours à l'activité partielle afin de compenser.
North Korea stole millions of dollars in crypto assets in at least one major hack
ExtraHop study finds sensitive protocols are not being managed securely
You think you’ve found a critical bug in a Solidity smart contract that, if exploited, could drain a widely used cryptocurrency exchange’s funds. To confirm that it’s really a bug, you need to figure out the value at an obscure storage slot that has no getter method. Adrenaline courses […]
Think tank claims British consumers suffer the highest losses
Inauthentic internet assets used to improve China’s image abroad
Jon L provides an update on the NCSC's guidance on the 'WannaCry' ransomware.
The TA likely used RAR and 7zip to archive files and folders from multiple directories
The standard is designed to provide buyers of application security assessment services with high levels of assurance
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to learn the value of randomized kernel pointers. The vulnerability can be used to defeat KASLR mitigation.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlo...
The US was the main target of attackers, followed by Switzerland, India, Japan and the UK
Thousands of hot wallets drained in latest crypto blow
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to disclose sensitive information from the kernel.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that facilitate better s...
Over one million bots used to spread disinformation, says Kyiv
Fraudsters set to ramp up efforts as Premier League season approaches