> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities. A major incident involved hackers hijacking Microsoft's official X account to promote a cryptocurrency scheme, showcasing the ongoing risks of social media exploitation. Additionally, a critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent action from users and inclusion in the U.S. CISA's Known Exploited Vulnerabilities catalog. On the espionage front, a China-aligned group has been phishing AI policy experts by impersonating US officials, emphasizing the trend of targeting high-profile individuals. Meanwhile, AI agents are increasingly being linked to SQL injection attacks against government sites, raising concerns about the security of AI applications. Lastly, law enforcement has made arrests in the KillSec ransomware group, reflecting ongoing efforts to combat cybercrime.
|
// AI-powered summary generated at 12:00
Alleged Twitter hacker “PlugwalkJoe” accused of stealing $784K from Manhattan-based crypto company
Impersonation attack uses legitimate Amazon links to steal financial credentials from end-users
🇫🇷 Les marqueurs techniques suivants sont associés au groupe cybercriminel Lockean (voir la publication CERTFR-2021-CTI-008). Ils peuvent être utilisés à des fins de recherche de compromission dans des journaux historiques ou de détection. 🇬🇧 The following indicators of compromise are associated...
Consumers are increasingly being targeted by sophisticated call center scams
Cyber-criminal called on rivals to unite against the US
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in October:
Articles
Certificate warnings when you browse to websites that use Let's Encrypt certificates through HTTPS proxies with content inspection
Firebox compatibil...
Hundreds of thousands of Israelis affected by ransom breach
Israeli firm threatened rules-based international order, US claims
Le département américain de la Santé et des Services sociaux (HHS) a conclu un accord de règlement de 90 000 dollars avec Virtual Private Network Solutions (VPN Solutions) pour une violation potentielle de la règle de sécurité HIPAA suite à une attaque de ransomware en 2021. L'enquête a révélé que V...
Security incident leaves “significant quantity” of Labour Party membership data inaccessible
Small Business Development Center Cyber Training Act and Small Business Administration Cyber Awareness Act approved
Information about the data an attacker can access via GCP's API endpoints
New directive attempts to reduce the risk of known exploited vulnerabilities
The founder of Black Hat and Defcon details what hacking is all about
This post is part of a series about Offensive BPF to learn how BPFs use will impact offensive security, malware, and detection engineering.
Click the “ebpf” tag to see all relevant posts.
Building advanced BPF programs So far in this Offensive BPF series the focus was on bpftrace to build and run BP...
Malicious cyber activity could compound supply chain issues
Freedom of Information request reveals staff accessed friends’ accounts
Appeals process can take years to resolve
New research explores impact of identity theft and fraud that targets America’s children
Financial institutions told exactly how they must secure their customers’ financial data