> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
The Hive ransomware group claims it has home addresses, bank details, medical records and even students’ psychological reviews
Under the agreement, the two organizations will exchange information and best practices relating to cyber incidents
You think you’ve found a critical bug in a Solidity smart contract that, if exploited, could drain a widely used cryptocurrency exchange’s funds. To confirm that it’s really a bug, you need to figure out the value at an obscure storage slot that has no getter method. Adrenaline courses […]
Successful applicants will work with experts from within the NCSC to develop, adapt or pilot technology
Microsoft announcement forced threat actors to adapt once again
Jon L provides an update on the NCSC's guidance on the 'WannaCry' ransomware.
UK police urge users to switch on two-factor authentication
Invoice fraud ring targeted state-owned organizations
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to learn the value of randomized kernel pointers. The vulnerability can be used to defeat KASLR mitigation.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlo...
The seller advertised the data on the Breached Forums site and demanded at least $30,000 for it
Lawmakers introduced the bill because they’re worried about the potential for quantum computers to easily crack current cryptographic algorithms
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to disclose sensitive information from the kernel.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that facilitate better s...
Cyber-criminals are using the Telegram and Discord messaging apps as command and control mechanisms
State Department hopes financial inducement will unmask threat actors
In this advisory we are disclosing a memory corruption vulnerability in the Huawei log device that allows any unprivileged process to trigger a kernel crash and reboot the device.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that fac...
European initiative celebrates sixth birthday
Most impacted companies raise product prices following incident
Introduction You probably have read about my recent swamp of CVEs affecting a WordPress plugin called Transposh Translation Filter, which resulted in more than $30,000 in bounties: [CVE-2021-24910] Transposh <= 1.0.7 “tp_tp” Unauthenticated Reflected Cross-Site Scripting [CVE-2021-24911] Transpos...
The report found Microsoft was the most impersonated brand overall
Over a third (36%) of employees consider security training boring