[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 12:00

> LockBit Ransomware Exploits Windows Defender to Sideload Cobalt Strike Payload
The attackers modified the Blast Secure Gateway component of the application using PowerShell code
> Google Patches Critical Android Bluetooth Flaw in August Security Bulletin
The Bluetooth vulnerability has been patched on Android 10, 11, 12 and 12L
> Semikron
L'attaque a conduit à l'arrêt de tous les équipements informatiques et au redémarrage sur une nouvelle infrastructure IT. Tous les départements de l'entreprise ont été affectés et la société a eu recours à l'activité partielle afin de compenser.
> Dark Web Research Suggests 87% of Ransomware Brands Exploit Malicious Macros
The findings uncovered 475 web pages of elaborate ransomware products and services
> US Indicts Russian Accused of Promoting California’s Secession
Moscow man allegedly conducted years-long influence campaign
> Shedding smart contract storage with Slither
You think you’ve found a critical bug in a Solidity smart contract that, if exploited, could drain a widely used cryptocurrency exchange’s funds. To confirm that it’s really a bug, you need to figure out the value at an obscure storage slot that has no getter method. Adrenaline courses […]
> Thousands of Apps Leaking Twitter API Keys
Security oversight could enable account takeovers
> UK’s Top 10 Universities Failing on DMARC
Leading US and Aussie unis also sub-par on email security
> 'WannaCry' ransomware: guidance updates
Jon L provides an update on the NCSC's guidance on the 'WannaCry' ransomware.
> Credential Stealer Malware Raccoon Updated to Obtain Passwords More Efficiently
Raccoon Stealer 2.0 features a new back-end and front-end, and other additional features
> North Korean Hackers Use Browser Extension to Spy on Gmail and AOL Accounts
Volexity said it observed SharpTongue targeting individuals in the US, Europe and South Korea
> CVE-2022-22256: Huawei HWLog KASLR Leak
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to learn the value of randomized kernel pointers. The vulnerability can be used to defeat KASLR mitigation. Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlo...
> Austrian Investigation Reveals Spyware Targeting Law Firms, Finance Institutions
The news comes days after Microsoft found malware called Subzero made by an Austrian company
> Countdown Clock Puts Pressure on Phishing Targets
New campaign is a masterclass in social engineering
> CVE-2022-22252: Huawei HWLog Vmalloc Use-After-Free
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to disclose sensitive information from the kernel. Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that facilitate better s...
> Aussie Allegedly Built Notorious RAT When He Was 15
Man facing six charges for Imminent Monitor malware
> Giant Investment Scam Network Targets Victims with Phone Calls
Over 11,000 fake domains used in major campaign
> CVE-2022-22253: Huawei HWLog Memory Corruption Via Race Condition
In this advisory we are disclosing a memory corruption vulnerability in the Huawei log device that allows any unprivileged process to trigger a kernel crash and reboot the device. Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that fac...
> Ransomware Bill Passes House
The law is designed to make it easier for the US to respond to ransomware attacks from foreign adversaries
> Congress Warns of US Court Records System Breach
A cyber-attack on the US justice system has compromised a public document management system, lawmakers revealed this week