Menu

Monthly Archives: October 2023

Calls for Visual Studio security tweak fall on deaf ears despite one-click RCE exploit
After hackers distribute malware in game updates, Steam adds SMS-based security check for developers
Squid games: 35 security holes still unpatched in proxy after 2 years, now public

security update

security update

Virus Bulletin – building digital armies

Security researchers, global organizations, law enforcement and other government agencies need to have the right conversations and test potential scenarios without the pressure of an actual attack

Virus Bulletin PUA – a love letter

Late nights at VB2023 featured intriguing interactions between security experts and the somewhat enigmatic world of grayware purveyors

6 steps to getting the board on board with your cybersecurity program

How CISOs and their peers can better engage with boards to get long-term buy-in for strategic initiatives

Everest cybercriminals offer corporate insiders cold, hard cash for remote access
Building cyber resilience with data vaults
DISA STIG for Red Hat Enterprise Linux 9 is now available
US construction giant unearths concrete evidence of cyberattack
HM Government has partnered with SANS to train cyber security experts
Smashing Security podcast #343: Four-legged girlfriends, LoveGPT, and a military intelligence failure

security update

security update

security update

US Navy sailor admits selling secret military blueprints to China for $15K
CISOs’ salary growth slows – with pay gap widening
That day you find you’re suddenly in charge of Facebook’s official UK account
From chaos to cadence: Celebrating two decades of Microsoft’s Patch Tuesday
Securing the future of Industry 4.0: WALLIX white paper reveals key strategies – get your copy today!
curl vulnerabilities ironed out with patches after week-long tease
What to expect when the UK-US Data Bridge comes into force this week

security update

It’s 2023 and Microsoft WordPad can be exploited to hijack vulnerable systems
SBF on trial: The Python code that allegedly let Alameda hedge fund spend people’s FTX deposits
HTTP/2 ‘Rapid Reset’ zero-day exploited in biggest DDoS deluge seen yet
Mirai reloads exploit arsenal as botnet embarks on another expansion drive
Researcher bags two-for-one deal on Linux bugs while probing GNOME component
Hacktivists send fake nuclear attack warning via Israeli Red Alert app
Fresh curl tomorrow will patch ‘worst’ security flaw in ages
Ransomware attacks register record speeds thanks to success of infosec industry
Exercise Cyber Star tests Singapore response
DoJ: Ex-soldier tried to pass secrets to China after seeking a ‘subreddit about spy stuff’
Hacktivist attacks erupt in Middle East following Hamas assault on Israel
Datacenter cabling biz Volex confirms digital break-in
Learning from Let’s Encrypt’s 10 years of success
Chinese smart TV boxes infected with malware in PEACHPIT ad fraud campaign

security update

DinodasRAT used against governmental entity in Guayana – Week in security with Tony Anscombe

The backdoor can exfiltrate files, manipulate Windows registry keys, and execute commands that are capable of performing various actions on a victim’s machine

Fake friends and followers on social media – and how to spot them

One of the biggest threats to watch out for on social media is fraud perpetrated by people who aren’t who they claim to be. Here’s how to recognize them.

security update

security update

security update

CISA reveals ‘Admin123’ as top security threat in cyber sloppiness chart
MGM Resorts attackers hit personal data jackpot, but house lost $100M
Revealed! The top 10 cybersecurity misconfigurations, as determined by CISA and the NSA
CDW data to be leaked next week after negotiations with LockBit break down
How to stop ransomware thieves WORMing their way into your data
Google promises Germany to creep on users less after market power probe
GoldDigger Android trojan targets Vietnamese banking apps, code contains hints of wider targets

security update

Cisco warns of critical flaw in Emergency Responder code
Another security update, Apple? You’re really keeping up with your tech rivals
Playing your part in building a safer digital world: Why cybersecurity matters

In an increasingly complex and interconnected digital landscape, personal cybersecurity empowers you to protect your data, privacy and digital well-being

Smashing Security podcast #342: Royal family attacked, keyless car theft, and a deepfake Tom Hanks
Lorenz ransomware crew bungles blackmail blueprint by leaking two years of contacts
South Korea accuses North of Phish and Ships attack
IT networks under attack via critical Confluence zero-day. Patch now
Make-me-root ‘Looney Tunables’ security hole on Linux needs your attention

security update

security update

‘Gay furry hackers’ brag of second NATO break-in, steal and leak more data
Red Cross lays down hacktivism law as Ukraine war rages on
CISA barred from coordinating with social media sites to police misinformation
Red Hat OpenShift Service on AWS assessed to process Australian Government Data at PROTECTED level
Trio of TorchServe flaws means PyTorch users need an urgent upgrade
US v Sam Bankman-Fried trial begins … as imploded crypto-biz boss sues his insurer

security update

CISA adds latest Chrome zero-day to Known Exploited Vulnerabilities Catalog
Co-founder of collapsed crypto biz Three Arrows cuffed at airport

security update

Security researchers believe mass exploitation attempts against WS_FTP have begun
AWS stirs the MadPot – busting bot baddies and eastern espionage since 2010
Linux distros need to take more responsibility for security
Yes, Singapore immigration plans to scan your face instead of your passport
Now MOVEit maker Progress patches holes in WS_FTP
How Lazarus impersonated Meta to attack a target in Spain – Week in security with Tony Anscombe

During the attack, the group deployed several tools, most notably a newly-discovered sophisticated backdoor that ESET named LightlessCan