> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Malicious updates were responsible for recent Russian attacks
Eight universities named by NCSC as Dundee sees major investment in local cyber-infrastructure
Zero-knowledge proofs, once a theoretical curiosity, have recently seen widespread deployment in blockchain systems such as Zcash and Monero. However, most blockchain applications of ZK proofs make proof size and performance tradeoffs that are a poor fit for other use-cases. In particular, these pro...
No sharp increase worldwide despite COVID-19 effect
Number of vulnerabilities in US NVD is now 17,447
Today FireEye shared that they were victim of a cyberattack and internal red teaming tooling was accessed by adversaries. More details in this NYT article.
This reminded me that I wanted to do a post on actively protecting pen testers and pen testing assets for a while.
Against persistent adversarie...
Husband of researcher who sold hospital’s secrets to China admits his part in conspiracy
October cyber-attack may have exposed data belonging to 67k patients of Sonoma Valley Hospital
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in November:
Articles
Firebox Cloud supports accelerated networking in Azure
Known Issues
IKEv2 profile import fails on macOS Big Sur 11.0.1
DHCPv6 server restarts repe...
Violating EU data protection rules has costly repercussions for social media giant
72% of businesses admit tracking of customer data happens
On 1 December 2020, the TDR EU AWS environment suffered from an intermittent outage which resulted in some Host Sensors being unable to contact ThreatSync. This seems to be linked to the deployment of new TDR infrastructure on the night of 30 November 2020. Despite Engineering's extensive efforts, t...
Cybercrime is becoming easier to conduct and successful attacks more consequential
Sensitive medical images including X-rays and CT scans are readily available
Government agencies issue advice after apparent nation state attacks
Microsoft outlines the changing tactics being employed
Breach went undetected for seven months
UK’s Online Safety Bill set to cause controversy
Company also reveals fewer than 18,000 customers affected by nation state attack
Adult website deletes unverified content in an effort to combat child sexual abuse