πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ Experts Identify 3 Chinese-Linked Clusters Behind Cyberattacks in Southeast Asia πŸ–‹οΈ

A trio of threat activity clusters linked to China has been observed compromising more government organizations in Southeast Asia as part of a renewed statesponsored operation codenamed Crimson Palace, indicating an expansion in the scope of the espionage effort. Cybersecurity firm Sophos, which has been monitoring the cyber offensive, said it comprises three intrusion sets tracked as Cluster.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Shining a Light on Shadow Apps: The Invisible Gateway to SaaS Data Breaches πŸ–‹οΈ

Shadow apps, a segment of Shadow IT, are SaaS applications purchased without the knowledge of the security team. While these applications may be legitimate, they operate within the blind spots of the corporate security team and expose the company to attackers.  Shadow apps may include instances of software that the company is already using. For example, a dev team may onboard their own.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ New PIXHELL Attack Exploits Screen Noise to Exfiltrates Data from Air-Gapped Computers πŸ–‹οΈ

A new sidechannel attack dubbed PIXHELL could be abused to target airgapped computers by breaching the "audio gap" and exfiltrating sensitive information by taking advantage of the noise generated by the pixels on the screen. "Malware in the airgap and audiogap computers generates crafted pixel patterns that produce noise in the frequency range of 0 22 kHz," Dr. Mordechai Guri, the head of.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments πŸ–‹οΈ

The threat actor tracked as Mustang Panda has refined its malware arsenal to include new tools in order to facilitate data exfiltration and the deployment of nextstage payloads, according to new findings from Trend Micro. The cybersecurity firm, which is monitoring the activity cluster under the name Earth Preta, said it observed "the propagation of PUBLOAD via a variant of the worm HIUPAN.".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Highline Public Schools Forced to Close By Cyber-Attack πŸ“”

Highline Public Schools in Washington State have now been closed for two days following the incident.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” China-Linked Threat Actors Target Taiwan Military Industry πŸ“”

TIDRONE group targets military, drone and satellite industries in Taiwan.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” DoJ Distributes $18.5m to Western Union Fraud Victims πŸ“”

The Justice Department has begun the latest round of fraud reimbursement from the Western Union Remission Fund.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Critical SonicWall SSLVPN Bug Exploited By Ransomware Actors πŸ“”

Researchers have warned that a critical SonicWall vulnerability is being exploited in ransomware attacks.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
🌊 Senior Python Developer 🌊

The post Senior Python Developer appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 SOC Automation: Streamlining Security Operations (+CISO’s Checklist) 🌊

Are you sure your SOC is invincible armor? How often do you hear about the burnout of inhouse SOC analysts? I will not bore you with dry statistics proving that security operation centers SOCs are swamped with tasks, most of which do not require any actions yet missed out on critical.  The solution is clear The post SOC Automation Streamlining Security Operations CISOs Checklist appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… CISA Adds Three Critical Vulnerabilities to Known Exploited Vulnerabilities Catalog πŸ¦…

Key Takeaways CISA has updated its Known Exploited Vulnerabilities KEV Catalog with three critical vulnerabilities CVE20163714, CVE20171000253, and CVE202440766. These vulnerabilities are being actively exploited by cybercriminals, posing significant risks to both federal and private sector organizations. CISA urges all organizations to prioritize the remediation of these vulnerabilities to strengthen their cybersecurity defenses. Organizations should update software with the latest patches, implement multifactor authentication MFA, and continuously monitor for unusual activities. For detailed information and support, organizations should consult CISAs advisories and the relevant vendor resources. Overview The Cybersecurity and Infrastructure Security Agency CISA...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ¦… The Re-Emergence of CVE-2024-32113: How CVE-2024-45195 has amplified Exploitation Risks πŸ¦…

Overview On September 7, 2024, Cyble Global Sensor Intelligence CGSI identified the active exploitation of CVE202432113, a critical path traversal vulnerability in the Apache OFBiz opensource enterprise resource planning ERP system. This flaw was initially addressed on April 12, 2024, with a formal patch released on May 8, 2024. CVE202432113 allows Threat Actors TAs to execute arbitrary commands by sending specially crafted requests, enabling them to gain unauthorized access and execute arbitrary commands. On September 4, 2024, the identification of CVE202445195 reignited concerns surrounding Apache OFBiz by revealing a bypass for several previously addressed vulnerabilities, notably CVE202432113. This development has intensified the exploitation of CVE202432113, as attackers expl...

πŸ“– Read more.

πŸ”— Via "CYBLE"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Cyber Staffing Shortages Remain CISOs' Biggest Challenge πŸ•΅οΈβ€β™‚οΈ

Besides operational issues connected to a talent shortage, the cost of running security platforms and their training costs also keeps CISOs up at night.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ How a Centuries-Old Company Reached Security Maturity πŸ•΅οΈβ€β™‚οΈ

In this case study, a 180yearold life and pension insurer brought its security infrastructure into the modern age.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Air-Gapped Networks Vulnerable to Acoustic Attack via LCD Screens πŸ•΅οΈβ€β™‚οΈ

Sound waves generated by pixels on a screen can transmit information across seemingly impenetrable air gaps.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 Patch Tuesday for September 2024: Microsoft Catches Four Zero-Day Vulnerabilities 🦿

A Mark of the Web security alert vulnerability and three others have been exploited in the wild and are now covered by Redmonds monthly patch batch.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Microsoft Discloses 4 Zero-Days in September Update πŸ•΅οΈβ€β™‚οΈ

This month's Patch Tuesday contains a total of 79 vulnerabilities the fourth largest of the year.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
β™ŸοΈ Bug Left Some Windows PCs Dangerously Unpatched β™ŸοΈ

Microsoft Corp. today released updates to fix at least 79 security vulnerabilities in its Windows operating systems and related software, including multiple flaws that are already showing up in active attacks. Microsoft also corrected a critical bug that has caused some Windows 10 PCs to remain dangerously unpatched against actively exploited vulnerabilities for several months this year.

πŸ“– Read more.

πŸ”— Via "Krebs on Security"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ India Needs Better Cybersecurity for Space, Critical Infrastructure πŸ•΅οΈβ€β™‚οΈ

As attacks on satellites rise with nationstate conflicts, the South Asian nation joins other spacecapable countries in doubling down on cybersecurity.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ”₯1
πŸ•΅οΈβ€β™‚οΈ Wiz Launches Wiz Code Application Security Tool πŸ•΅οΈβ€β™‚οΈ

Wiz Code identifies and flags cloud risks in code to help improve collaboration between security and development teams.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Microsoft Issues Patches for 79 Flaws, Including 3 Actively Exploited Windows Flaws πŸ–‹οΈ

Microsoft on Tuesday disclosed that three new security flaws impacting the Windows platform have come under active exploitation as part of its Patch Tuesday update for September 2024. The monthly security release addresses a total of 79 vulnerabilities, of which seven are rated Critical, 71 are rated Important, and one is rated Moderate in severity. This is aside from 26 flaws that the tech.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity