π΅οΈββοΈ Dark Reading Confidential: Pen Test Arrests, Five Years Later π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Episode 3 On September 11, 2019, two cybersecurity professionals were arrested in Dallas County, Iowa and forced to spend the night in jail just for doing their jobs. Gary De Mercurio and Justin Wynn. Despite the criminal charges against them eventually being dropped, the saga that night five years ago continues to haunt De Mercurio and Wynn personally and professionally. In this episode, the pair and Coalfire's CEO Tom McAndrew share how the arrest and fallout has shaped their lives and careers as well as how it has transformed physical penetration tests for the cybersecurity industry as a whole.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
Cybersecurity Pen-Test Arrests: 5 Years Later
Two cybersecurity pros were arrested five years ago for doing their jobs and share how the incident has shaped their lives and the industry.
π΅οΈββοΈ Gallup Poll Bugs Open Door to Election Misinformation π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Researchers flagged a pair of Gallup polling site XSS vulnerabilities that could have allowed malicious actors to execute arbitrary code, access sensitive data, or take over a victim account.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
Gallup Addresses XSS Bugs in Website
Researchers flagged a pair of Gallup site XSS vulnerabilities.
π΅οΈββοΈ Chinese Tag Team APTs Keep Stealing Asian Gov't Secrets π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
A PRC threat cluster known as "Crimson Palace" is demonstrating the benefits of having specialized units carry out distinct stages of a wider attack chain.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
Chinese Tag Team APTs Keep Stealing Asian Gov't Secrets
A PRC threat cluster known as "Crimson Palace" is demonstrating the benefits of having specialized units carry out distinct stages of a wider attack chain.
π¦Ώ Microsoft Is Disabling Default ActiveX Controls in Office 2024 to Improve Security π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Microsoft has been on the warpath against legacy Office features that are providing entry points for bad actors since 2018.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Microsoft Is Disabling Default ActiveX Controls in Office 2024 to Improve Security
Microsoft will disable ActiveX controls by default in the Office suite, starting in October with the release of Office 2024.
π Proxmark3 4.18994 Custom Firmware π
π Read more.
π Via "Packet Storm - Tools"
----------
ποΈ Seen on @cibsecurity
This is a custom firmware written for the Proxmark3 device. It extends the currently available firmware. This release is nicknamed "Backdoor".π Read more.
π Via "Packet Storm - Tools"
----------
ποΈ Seen on @cibsecurity
packetstorm.news
Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers
π§ ChatGPT 4 can exploit 87% of one-day vulnerabilities: Is it really that impressive? π§
π Read more.
π Via "Security Intelligence"
----------
ποΈ Seen on @cibsecurity
After reading about the recent cybersecurity research by Richard Fang, Rohan Bindu, Akul Gupta and Daniel Kang, I had questions. While initially impressed that ChatGPT 4 can exploit the vast majority of oneday vulnerabilities, I started thinking about what the results really mean in the grand scheme of cybersecurity. Most importantly, I wondered how a The post ChatGPT 4 can exploit 87 of oneday vulnerabilities Is it really that impressive? appeared first on Security Intelligence.π Read more.
π Via "Security Intelligence"
----------
ποΈ Seen on @cibsecurity
Security Intelligence
ChatGPT 4 can exploit 87% of one-day vulnerabilities: Is it really that impressive?
Some research suggests the catastrophic cybersecurity risks that large language models could pose. But are they really that dangerous?
ποΈ CosmicBeetle Deploys Custom ScRansom Ransomware, Partnering with RansomHub ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The threat actor known as CosmicBeetle has debuted a new custom ransomware strain called ScRansom in attacks targeting small and mediumsized businesses SMBs in Europe, Asia, Africa, and South America, while also likely working as an affiliate for RansomHub. "CosmicBeetle replaced its previously deployed ransomware, Scarab, with ScRansom, which is continually improved," ESET researcher Jakub.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Experts Identify 3 Chinese-Linked Clusters Behind Cyberattacks in Southeast Asia ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A trio of threat activity clusters linked to China has been observed compromising more government organizations in Southeast Asia as part of a renewed statesponsored operation codenamed Crimson Palace, indicating an expansion in the scope of the espionage effort. Cybersecurity firm Sophos, which has been monitoring the cyber offensive, said it comprises three intrusion sets tracked as Cluster.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Shining a Light on Shadow Apps: The Invisible Gateway to SaaS Data Breaches ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Shadow apps, a segment of Shadow IT, are SaaS applications purchased without the knowledge of the security team. While these applications may be legitimate, they operate within the blind spots of the corporate security team and expose the company to attackers. Shadow apps may include instances of software that the company is already using. For example, a dev team may onboard their own.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ New PIXHELL Attack Exploits Screen Noise to Exfiltrates Data from Air-Gapped Computers ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A new sidechannel attack dubbed PIXHELL could be abused to target airgapped computers by breaching the "audio gap" and exfiltrating sensitive information by taking advantage of the noise generated by the pixels on the screen. "Malware in the airgap and audiogap computers generates crafted pixel patterns that produce noise in the frequency range of 0 22 kHz," Dr. Mordechai Guri, the head of.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The threat actor tracked as Mustang Panda has refined its malware arsenal to include new tools in order to facilitate data exfiltration and the deployment of nextstage payloads, according to new findings from Trend Micro. The cybersecurity firm, which is monitoring the activity cluster under the name Earth Preta, said it observed "the propagation of PUBLOAD via a variant of the worm HIUPAN.".π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Highline Public Schools Forced to Close By Cyber-Attack π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Highline Public Schools in Washington State have now been closed for two days following the incident.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Highline Public Schools Forced to Close By Cyber-Attack
Highline Public Schools in Washington State have now been closed for two days following the incident
π China-Linked Threat Actors Target Taiwan Military Industry π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
TIDRONE group targets military, drone and satellite industries in Taiwan.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
China-Linked Threat Actors Target Taiwan Military Industry
TIDRONE group targets military, drone and satellite industries in Taiwan
π DoJ Distributes $18.5m to Western Union Fraud Victims π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The Justice Department has begun the latest round of fraud reimbursement from the Western Union Remission Fund.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
DoJ Distributes $18.5m to Western Union Fraud Victims
The Justice Department has begun the latest round of fraud reimbursement from the Western Union Remission Fund
π Critical SonicWall SSLVPN Bug Exploited By Ransomware Actors π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Researchers have warned that a critical SonicWall vulnerability is being exploited in ransomware attacks.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Critical SonicWall SSLVPN Bug Exploited By Ransomware Actors
Researchers have warned that a critical SonicWall vulnerability is being exploited in ransomware attacks
π1
π Senior Python Developer π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
The post Senior Python Developer appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Senior Python Developer - UnderDefense
π SOC Automation: Streamlining Security Operations (+CISOβs Checklist) π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Are you sure your SOC is invincible armor? How often do you hear about the burnout of inhouse SOC analysts? I will not bore you with dry statistics proving that security operation centers SOCs are swamped with tasks, most of which do not require any actions yet missed out on critical. The solution is clear The post SOC Automation Streamlining Security Operations CISOs Checklist appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
SOC Automation: How to Optimize Your Security Operations
Learn how SOC Automation works, its benefits, and how to maximize its potential. We'll also provide a checklist to assess your current level of automation.
π¦
CISA Adds Three Critical Vulnerabilities to Known Exploited Vulnerabilities Catalog π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Key Takeaways CISA has updated its Known Exploited Vulnerabilities KEV Catalog with three critical vulnerabilities CVE20163714, CVE20171000253, and CVE202440766. These vulnerabilities are being actively exploited by cybercriminals, posing significant risks to both federal and private sector organizations. CISA urges all organizations to prioritize the remediation of these vulnerabilities to strengthen their cybersecurity defenses. Organizations should update software with the latest patches, implement multifactor authentication MFA, and continuously monitor for unusual activities. For detailed information and support, organizations should consult CISAs advisories and the relevant vendor resources. Overview The Cybersecurity and Infrastructure Security Agency CISA...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble
CISA Adds 3 Critical Vulnerabilities To Exploited List
CISA updates its KEV Catalog with three critical vulnerabilities. Organizations must prioritize remediation to enhance cybersecurity defenses.
π¦
The Re-Emergence of CVE-2024-32113: How CVE-2024-45195 has amplified Exploitation Risks π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Overview On September 7, 2024, Cyble Global Sensor Intelligence CGSI identified the active exploitation of CVE202432113, a critical path traversal vulnerability in the Apache OFBiz opensource enterprise resource planning ERP system. This flaw was initially addressed on April 12, 2024, with a formal patch released on May 8, 2024. CVE202432113 allows Threat Actors TAs to execute arbitrary commands by sending specially crafted requests, enabling them to gain unauthorized access and execute arbitrary commands. On September 4, 2024, the identification of CVE202445195 reignited concerns surrounding Apache OFBiz by revealing a bypass for several previously addressed vulnerabilities, notably CVE202432113. This development has intensified the exploitation of CVE202432113, as attackers expl...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble
CVE-2024-32113's Re-Emergence And Amplified Risks
Discover critical CVE-2024-32113 in Apache OFBiz, enabling remote code execution. Learn mitigation strategies and upgrade recommendations.
π΅οΈββοΈ Cyber Staffing Shortages Remain CISOs' Biggest Challenge π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Besides operational issues connected to a talent shortage, the cost of running security platforms and their training costs also keeps CISOs up at night.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
Cyber Staffing Shortages Remain CISOs' Biggest Challenge
Besides operational issues connected to a talent shortage, the cost of running security platforms β and their training costs β also keeps CISOs up at night.
π΅οΈββοΈ How a Centuries-Old Company Reached Security Maturity π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
In this case study, a 180yearold life and pension insurer brought its security infrastructure into the modern age.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
How a Centuries-Old Company Reached Security Maturity
In this case study, a 180-year-old life and pension insurer brought its security infrastructure into the modern age.