βAuthorities Warns Of North Korean Attackers Stealing Military Technologies
https://cybersecuritynews.com/north-korean-attack-military-technologies/
https://cybersecuritynews.com/north-korean-attack-military-technologies/
Cyber Security News
Authorities Warns Of North Korean Attackers Stealing Military Technologies
Threat actors target military technologies to gain a strategic advantage, access classified information, and compromise national security.
π1
βUrgent Notice: Creates Online Shop Breach Exposes Customer Data
https://securityonline.info/urgent-notice-creates-online-shop-breach-exposes-customer-data/
https://securityonline.info/urgent-notice-creates-online-shop-breach-exposes-customer-data/
Cybersecurity News
Urgent Notice: Creates Online Shop Breach Exposes Customer Data
Creates, a popular online retailer of hair styling tools, has suffered a significant data breach that exposed credit card details
π1
βBiden executive order gives Coast Guard added authority over maritime cyber threats
https://cyberscoop.com/biden-executive-order-coast-guard-cyber/
https://cyberscoop.com/biden-executive-order-coast-guard-cyber/
CyberScoop
Biden signs executive order to give Coast Guard added authority over maritime cyber threats
National security officials have been sounding the alarm over a China-linked hacking group thatβs been targeting critical infrastructure.
βCVE-2024-21678: High-Severity Atlassian Confluence XSS β Act Now
https://securityonline.info/cve-2024-21678-high-severity-atlassian-confluence-xss-act-now/
https://securityonline.info/cve-2024-21678-high-severity-atlassian-confluence-xss-act-now/
Cybersecurity News
CVE-2024-21678: High-Severity Atlassian Confluence XSS β Act Now
Atlassian has released a security update addressing CVE-2024-21678 (CVSS 8.5), a high-severity stored cross-site scripting vulnerability
βSpeedyTest - Command-Line Tool For Measuring Internet Speed
http://www.kitploit.com/2024/02/speedytest-command-line-tool-for.html
http://www.kitploit.com/2024/02/speedytest-command-line-tool-for.html
KitPloit - PenTest & Hacking Tools
SpeedyTest - Command-Line Tool For Measuring Internet Speed
βCVE-2024-22243: Spring Framework Flaw Opens Doors to Redirects and SSRF Attacks
https://securityonline.info/cve-2024-22243-spring-framework-flaw-opens-doors-to-redirects-and-ssrf-attacks/
https://securityonline.info/cve-2024-22243-spring-framework-flaw-opens-doors-to-redirects-and-ssrf-attacks/
Cybersecurity News
CVE-2024-22243: Spring Framework Flaw Opens Doors to Redirects and SSRF Attacks
The Spring Framework, a cornerstone of countless enterprise Java applications, recently revealed a significant vulnerability (CVE-2024-22243)
βVMware Urges to Remove Enhanced EAP Plugin to Stop Auth & Session Hijack Attacks
https://gbhackers.com/vmware-urges-remove-eap-plugin/
https://gbhackers.com/vmware-urges-remove-eap-plugin/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
VMware Urges to Remove EAP Plugin to Stop Hijack Attacks
VMware has issued an urgent advisory to administrators to remove a deprecated authentication plugin vulnerable to severe security threats.
βMicrosoft Exchange flaw CVE-2024-21410 could impact up to 97,000 servers
https://securityaffairs.com/159424/hacking/28000-vulnerable-microsoft-exchange-servers.html
https://securityaffairs.com/159424/hacking/28000-vulnerable-microsoft-exchange-servers.html
Security Affairs
Microsoft Exchange flaw CVE-2024-21410 could impact up to 97,000 servers
Researchers from Shadowserver Foundation identified roughly 28,000 internet-facing Microsoft Exchange servers vulnerable to CVE-2024-21410.
βScreenConnect Security Flaw Let Attackers Bypass Authentication
https://cybersecuritynews.com/screenconnect-security-flaw/
https://cybersecuritynews.com/screenconnect-security-flaw/
Cyber Security News
ScreenConnect Security Flaw Let Attackers Bypass Authentication
ConnectWise has alerted users of its ScreenConnect remote access software to patch their systems immediately due to two severe vulnerabilities.
βSqliSniper β Enhancing Web Security By Detecting SQL Injection Vulnerabilities With Python
https://kalilinuxtutorials.com/sqlisniper/
https://kalilinuxtutorials.com/sqlisniper/
Kali Linux Tutorials
SqliSniper - Enhancing Web Security By Detecting SQL Injection
SqliSniper is a robust Python tool designed to detect time-based blind SQL injections in HTTP request headers.
βCloudMiner β Unleashing Free Computing Power Within Azure Automation
https://kalilinuxtutorials.com/cloudminer/
https://kalilinuxtutorials.com/cloudminer/
Kali Linux Tutorials
CloudMiner - Unleashing Free Computing Power Within Azure
CloudMiner represents a groundbreaking approach to leveraging Azure Automation service without incurring any costs.
βRussian-Linked Operation Texonto Targets Ukraine, Dissidents
https://securityonline.info/russian-linked-operation-texonto-targets-ukraine-dissidents/
https://securityonline.info/russian-linked-operation-texonto-targets-ukraine-dissidents/
Cybersecurity News
Russian-Linked Operation Texonto Targets Ukraine, Dissidents
Domains associated with Operation Texonto were found linked to potential influence operations aimed at Russian citizens
βUnderstanding GDPR and the Importance of Employee Training
https://latesthackingnews.com/2024/02/21/understanding-gdpr-and-the-importance-of-employee-training/
https://latesthackingnews.com/2024/02/21/understanding-gdpr-and-the-importance-of-employee-training/
LHN
Understanding GDPR and the Importance of Employee Training
The General Data Protection Regulation (GDPR) has significantly impacted how European businesses collect, store, use, and share personal data. Implemented in 2018, the GDPR has ushered in a new era of data privacy rights and
βSignal Messenger Introduces Usernames to Hide Phone Numbers
https://restoreprivacy.com/signal-messenger-introduces-usernames-to-hide-phone-numbers/
https://restoreprivacy.com/signal-messenger-introduces-usernames-to-hide-phone-numbers/
CyberInsider
Signal Messenger Introduces Usernames to Hide Phone Numbers
The Signal messenger app will soon begin rolling out usernames to replace phone numbers, making them the default option from now on.
βUS offers $15 million bounty for info on LockBit ransomware gang
https://www.bleepingcomputer.com/news/security/us-offers-15-million-bounty-for-info-on-lockbit-ransomware-gang/
https://www.bleepingcomputer.com/news/security/us-offers-15-million-bounty-for-info-on-lockbit-ransomware-gang/
BleepingComputer
US offers $15 million bounty for info on LockBit ransomware gang
The U.S. State Department is now also offering rewards of up to $15 million to anyone who can provide information about LockBit ransomware gang members and their associates.
βScreenConnect critical bug now under attack as exploit code emerges
https://www.bleepingcomputer.com/news/security/screenconnect-critical-bug-now-under-attack-as-exploit-code-emerges/
https://www.bleepingcomputer.com/news/security/screenconnect-critical-bug-now-under-attack-as-exploit-code-emerges/
BleepingComputer
ScreenConnect critical bug now under attack as exploit code emerges
Both technical details and proof-of-concept exploits are available for the two vulnerabilities ConnectWise disclosed earlier this week for ScreenConnect, its remote desktop and access software.
βUS govt shares cyberattack defense tips for water utilities
https://www.bleepingcomputer.com/news/security/us-govt-shares-cyberattack-defense-tips-for-water-utilities/
https://www.bleepingcomputer.com/news/security/us-govt-shares-cyberattack-defense-tips-for-water-utilities/
BleepingComputer
US govt shares cyberattack defense tips for water utilities
CISA, the FBI, and the Environmental Protection Agency (EPA) shared a list of defense measures U.S. water utilities should implement to better defend their systems against cyberattacks
βNew SSH-Snake malware steals SSH keys to spread across the network
https://www.bleepingcomputer.com/news/security/new-ssh-snake-malware-steals-ssh-keys-to-spread-across-the-network/
https://www.bleepingcomputer.com/news/security/new-ssh-snake-malware-steals-ssh-keys-to-spread-across-the-network/
BleepingComputer
New SSH-Snake malware steals SSH keys to spread across the network
A threat actor is using an open-source network mapping tool named SSH-Snake to look for private keys undetected and move laterally on the victim infrastructure.
βFraudsters tried to scam Apple out of 5,000 iPhones worth over $3 million
https://www.bleepingcomputer.com/news/security/fraudsters-tried-to-scam-apple-out-of-5-000-iphones-worth-over-3-million/
https://www.bleepingcomputer.com/news/security/fraudsters-tried-to-scam-apple-out-of-5-000-iphones-worth-over-3-million/
BleepingComputer
Fraudsters tried to scam Apple out of 5,000 iPhones worth over $3 million
Two Chinese nationals face 20 years in prison after being caught and convicted of submitting over 5,000 fake iPhones worth more than $3 million to Apple with the goal of having them replaced with genuine devices.
βMicrosoft rolls out expanded logging six months after Chinese breach
https://cyberscoop.com/microsoft-logging-cisa-omb/
https://cyberscoop.com/microsoft-logging-cisa-omb/
CyberScoop
Microsoft rolls out expanded logging six months after Chinese breach
The technology giant has come under heavy criticism for not making robust logging features available by default.
βHackers abuse Google Cloud Run in massive banking trojan campaign
https://www.bleepingcomputer.com/news/security/hackers-abuse-google-cloud-run-in-massive-banking-trojan-campaign/
https://www.bleepingcomputer.com/news/security/hackers-abuse-google-cloud-run-in-massive-banking-trojan-campaign/
BleepingComputer
Hackers abuse Google Cloud Run in massive banking trojan campaign
Security researchers are warning of hackers abusing the Google Cloud Run service to distribute massive volumes of banking trojans like Astaroth, Mekotio, and Ousaban.