> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
The attackers modified the Blast Secure Gateway component of the application using PowerShell code
The Bluetooth vulnerability has been patched on Android 10, 11, 12 and 12L
L'attaque a conduit à l'arrêt de tous les équipements informatiques et au redémarrage sur une nouvelle infrastructure IT. Tous les départements de l'entreprise ont été affectés et la société a eu recours à l'activité partielle afin de compenser.
The findings uncovered 475 web pages of elaborate ransomware products and services
Moscow man allegedly conducted years-long influence campaign
You think you’ve found a critical bug in a Solidity smart contract that, if exploited, could drain a widely used cryptocurrency exchange’s funds. To confirm that it’s really a bug, you need to figure out the value at an obscure storage slot that has no getter method. Adrenaline courses […]
Security oversight could enable account takeovers
Leading US and Aussie unis also sub-par on email security
Jon L provides an update on the NCSC's guidance on the 'WannaCry' ransomware.
Raccoon Stealer 2.0 features a new back-end and front-end, and other additional features
Volexity said it observed SharpTongue targeting individuals in the US, Europe and South Korea
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to learn the value of randomized kernel pointers. The vulnerability can be used to defeat KASLR mitigation.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlo...
The news comes days after Microsoft found malware called Subzero made by an Austrian company
New campaign is a masterclass in social engineering
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to disclose sensitive information from the kernel.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that facilitate better s...
Man facing six charges for Imminent Monitor malware
Over 11,000 fake domains used in major campaign
In this advisory we are disclosing a memory corruption vulnerability in the Huawei log device that allows any unprivileged process to trigger a kernel crash and reboot the device.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that fac...
The law is designed to make it easier for the US to respond to ransomware attacks from foreign adversaries
A cyber-attack on the US justice system has compromised a public document management system, lawmakers revealed this week