> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical developments. Doxx.net has secured $38 million to enhance its platform aimed at preventing AI-related misadventures. Fortra has patched significant vulnerabilities in its BoKS product that could lead to severe security breaches. GitLab also addressed a critical flaw in its AI Gateway that allowed unauthorized command execution. In terms of threats, the Antino backdoor has been linked to a China-based group conducting espionage through Microsoft 365. Additionally, a new ransomware group, N0n, has emerged, quickly making its mark in the cyber extortion realm. As the cyber landscape evolves, organizations must prioritize tracking these emerging threats and vulnerabilities.
|
// AI-powered summary generated at 12:00
Tens of millions were impacted by 2021 incident
The updated document provides more actionable measures for healthcare organizations
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to disclose sensitive information from the kernel.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that facilitate better s...
The company claims that "no significant customer data was exposed" in the incident
The Cyber Advisor service will certify individual consultants who can provide practical advice to help secure businesses
In this advisory we are disclosing a memory corruption vulnerability in the Huawei log device that allows any unprivileged process to trigger a kernel crash and reboot the device.
Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that fac...
Investigators trumpet money laundering crackdown
Biotronik accused of engaging in kickback scheme
Introduction You probably have read about my recent swamp of CVEs affecting a WordPress plugin called Transposh Translation Filter, which resulted in more than $30,000 in bounties: [CVE-2021-24910] Transposh <= 1.0.7 “tp_tp” Unauthenticated Reflected Cross-Site Scripting [CVE-2021-24911] Transpos...
Surge in threats coming from eastern Europe
It is easier than ever to launch cyber-attacks due to the rise of malware-as-a-service
L'autorité de contrôle des ports de Tokyo MOU a révélé que ses données ont été compromises pendant des mois après avoir été victime d'une cyberattaque en juillet dernier. Cette attaque a causé des problèmes avec les données de contrôle des navires, ce qui a pu créer des difficultés pour la prise de...
The Android Developers team said it reversed the decision due to customer feedback
The so-far unidentified hackers broadcasted reports that Zelensky was hospitalized “in an intensive care ward”
Une coopérative agricole a été victime d'une cyberattaque en juillet 2022, plusieurs de ses machines ont été infectées par un logiciel malveillant. Le procès de l'auteur présumé de ces attaques, Ilia D., s'ouvre le 11 février devant la 13e chambre correctionnelle du tribunal judiciaire de Paris. Les...
Many left in the dark due to immature approaches
Threat actors combine techniques to trick users
🇫🇷 Le CERT-FR met à disposition un feed MISP public regroupant des indicateurs de compromission marqués TLP:CLEAR dont la diffusion est libre. Il est accessible à l'adresse https://misp.cert.ssi.gouv.fr/feed-misp. La documentation du projet MISP, plateforme open-source de partage d'indicateurs de...
Firm urges password reset despite claims attacker has live access
The fine was issued for violating the country’s network security law, data security law and personal information protection law