https://www.bleepingcomputer.com/news/apple/apple-releases-emergency-update-to-fix-zero-day-exploited-in-attacks/ #infosec
BleepingComputer
Apple releases emergency update to fix zero-day exploited in attacks
Apple has issued a new round of Rapid Security Response (RSR) updates to address a new zero-day bug exploited in attacks and impacting fully-patched iPhones, Macs, and iPads.
https://www.securityweek.com/microsoft-warns-of-office-zero-day-attacks-no-patch-available/ #infosec
SecurityWeek
Microsoft Warns of Office Zero-Day Attacks, No Patch Available
Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.
WINRAR FLAW ENABLES REMOTE CODE EXECUTION OF ARBITRARY CODE
https://securityaffairs.com/149670/hacking/winrar-rce.html #infosec
https://securityaffairs.com/149670/hacking/winrar-rce.html #infosec
Security Affairs
WinRAR flaw enables remote code execution of arbitrary code
A flaw impacting the file archiver utility for Windows WinRAR can allow the execution of commands on a computer by opening an archive.
MGM casino's ESXi servers allegedly encrypted in ransomware attack
https://www.bleepingcomputer.com/news/security/mgm-casinos-esxi-servers-allegedly-encrypted-in-ransomware-attack/ #infosec
https://www.bleepingcomputer.com/news/security/mgm-casinos-esxi-servers-allegedly-encrypted-in-ransomware-attack/ #infosec
BleepingComputer
MGM casino's ESXi servers allegedly encrypted in ransomware attack
An affiliate of the BlackCat ransomware group, also known as APLHV, is behind the attack that disrupted MGM Resorts' operations, forcing the company to shut down IT systems.
YouTube ordered to reveal the identities of video viewers
https://www.malwarebytes.com/blog/news/2024/03/youtube-ordered-to-reveal-the-identities-of-video-viewers #infosec
https://www.malwarebytes.com/blog/news/2024/03/youtube-ordered-to-reveal-the-identities-of-video-viewers #infosec
Malwarebytes
YouTube ordered to reveal the identities of video viewers
Federal authorities have asked Google to reveal the identities of people that watched certain videos in at least two investigations.
OpenAI's GPT-4 can exploit real vulnerabilities by reading security advisories
https://www.theregister.com/2024/04/17/gpt4_can_exploit_real_vulnerabilities/ #infosec
https://www.theregister.com/2024/04/17/gpt4_can_exploit_real_vulnerabilities/ #infosec
The Register
OpenAI's GPT-4 can exploit real vulnerabilities by reading security advisories
While some other LLMs appear to flat-out suck
βLightSpy Hackers Target Indian Apple Device Users To Steal Sensitive Data
https://gbhackers.com/lightspy-hackers-target-indian-apple-users/ #infosec
https://gbhackers.com/lightspy-hackers-target-indian-apple-users/ #infosec
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
LightSpy Hackers Target Indian Apple Device Users To Steal Sensitive Data
The reason why hackers target users of Apple devices is that they are perceived to be of higher social classes, leading to targets that are
Stop Using Your Face or Thumb to Unlock Your Phone
https://gizmodo.com/stop-using-your-face-or-thumb-to-unlock-your-phone-1851438205 #infosec
https://gizmodo.com/stop-using-your-face-or-thumb-to-unlock-your-phone-1851438205 #infosec
Gizmodo
Stop Using Your Face or Thumb to Unlock Your Phone
The laws surrounding 5th Amendment protections and biometric passwords are still undecided, so just turn it off.
Fake job interviews target developers with new Python backdoor
https://www.bleepingcomputer.com/news/security/fake-job-interviews-target-developers-with-new-python-backdoor/ #infosec
https://www.bleepingcomputer.com/news/security/fake-job-interviews-target-developers-with-new-python-backdoor/ #infosec
BleepingComputer
Fake job interviews target developers with new Python backdoor
A new campaign tracked as "Dev Popper" is targeting software developers with fake job interviews in an attempt to trick them into installing a Python remote access trojan (RAT).
The Bandit wargame is aimed at absolute beginners. It will teach the basics needed to be able to play other wargames.
https://overthewire.org/wargames/bandit/ #infosec
https://overthewire.org/wargames/bandit/ #infosec
41+ Cybersecurity Interview Questions and Answers to Help You Ace Your Next Interview
https://cybertalents.com/blog/41-questions-to-help-you-prepare-for-a-cybersecurity-interview #infosec
https://cybertalents.com/blog/41-questions-to-help-you-prepare-for-a-cybersecurity-interview #infosec
CyberTalents Blog
41+ Questions to Help you Prepare for a Cybersecurity Interview
41+ Cybersecurity Interview Questions and Answers to Help You Ace Your Next Interview
The job market has come a long way in the past two years with some segments witnessing higher demand than other...
The job market has come a long way in the past two years with some segments witnessing higher demand than other...
Exploiting an Android Device Using MSFvenom and Metasploit Framework: A Comprehensive Guide
https://medium.com/@eminimoeghosa/exploiting-an-android-device-using-msfvenom-and-metasploit-framework-a-comprehensive-guide-8e1a8d071b62 #infosec
https://medium.com/@eminimoeghosa/exploiting-an-android-device-using-msfvenom-and-metasploit-framework-a-comprehensive-guide-8e1a8d071b62 #infosec
Medium
Exploiting an Android Device Using MSFvenom and Metasploit Framework: A Comprehensive Guide
Disclaimer: The content provided here is solely for educational purposes aimed at increasing awareness and understanding of cybersecurityβ¦
Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History
https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak #infosec #ai
https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak #infosec #ai
wiz.io
Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History | Wiz Blog
A publicly accessible database belonging to DeepSeek allowed full control over database operations, including the ability to access internal data. The exposure includes over a million lines of log streams with highly sensitive information.
DeepSeek Data Leak β 12,000 Hardcoded Live API keys and Passwords Exposed
https://cybersecuritynews.com/deepseek-data-leak-api-keys-and-passwords/ #infosec
https://cybersecuritynews.com/deepseek-data-leak-api-keys-and-passwords/ #infosec
Cyber Security News
DeepSeek Data Leak β 12,000 Hardcoded Live API keys and Passwords Exposed
A recent analysis uncovered 11,908 live DeepSeek API keys, passwords, and authentication tokens embedded in publicly scraped web data.
DeepSeek Data Leak β 12,000 Hardcoded Live API keys and Passwords Exposed. #infosec
-
https://www.instagram.com/share/BAOOmnHHwJ
-
https://x.com/alienroom/status/1896777016676077785
-
https://www.linkedin.com/posts/alienroom_deepseek-data-leak-12000-hardcoded-live-activity-7302542942089433089-1Uzj
-
https://www.instagram.com/share/BAOOmnHHwJ
-
https://x.com/alienroom/status/1896777016676077785
-
https://www.linkedin.com/posts/alienroom_deepseek-data-leak-12000-hardcoded-live-activity-7302542942089433089-1Uzj
Linkedin
AlienRoom on LinkedIn: DeepSeek Data Leak β 12,000 Hardcoded Live API keys and Passwords Exposed.