> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Researchers show results of their IoT threat huntng framework
Transputec will provide security for WFS’ aviation cargo and ground handling operations
Today FireEye shared that they were victim of a cyberattack and internal red teaming tooling was accessed by adversaries. More details in this NYT article.
This reminded me that I wanted to do a post on actively protecting pen testers and pen testing assets for a while.
Against persistent adversarie...
Website Planet research reveals misconfigured CMS to blame
Individual pleads guilty to making botnet and launching DDoS attacks that lost Sony $2.7m in revenue
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in November:
Articles
Firebox Cloud supports accelerated networking in Azure
Known Issues
IKEv2 profile import fails on macOS Big Sur 11.0.1
DHCPv6 server restarts repe...
Patient data exposed following cyber-attack on Dental Care Alliance
MySQL servers hit by double extortion ransomware campaign PLEASE_READ_ME
On 1 December 2020, the TDR EU AWS environment suffered from an intermittent outage which resulted in some Host Sensors being unable to contact ThreatSync. This seems to be linked to the deployment of new TDR infrastructure on the night of 30 November 2020. Despite Engineering's extensive efforts, t...
Funds will be used to help increasing numbers of cybercrime victims in the UK
Gershon assumes leadership of email security firm’s global sales and marketing activities
[Mise à jour du 26 février 2021] 🇬🇧 The following indicators are new network indicators associated with the Ryuk ransomware described in the CERTFR-2021-CTI-006 report. These technical elements are provided to help detecting malicious activities in logs or inside live network trafic. Every...
Finding the balance between security and usability is crucial in developing an access management policy
North Korea’s offensive cyber-program has grown in strength and sophistication
Junior colleagues are more risk-averse with passwords and devices
Researchers find major internet fraud operation in central Asia
European Medicines Agency tight-lipped on details of the breach
Texan charged with cyber-stalking realtors is indicted for capital murder of two women
Critical vulnerabilities detected in over 100 GE radiological devices
UK’s IT leaders expect to lose their jobs to artificial intelligence within the next decade