Aggregator
State-backed attackers and commercial surveillance vendors repeatedly use the same exploits
Corona Mirai botnet spreads via AVTECH CCTV zero-day
Automattic 将 Tumblr 后端搬到 WordPress
Большое обновление Wireshark: что нового в версии 4.4.0?
一名 Rust Linux 维护者辞职
Dragos Expands Asset Visibility in Latest Platform Update
CISA and Partners Release Advisory on RansomHub Ransomware
Today, CISA—in partnership with the Federal Bureau of Investigation (FBI), Multi-State Information Sharing and Analysis Center (MS-ISAC), and Department of Health and Human Services (HHS)—released a joint Cybersecurity Advisory, #StopRansomware: RansomHub Ransomware. This advisory provides network defenders with indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with RansomHub activity identified through FBI investigations and third-party reporting as recently as August 2024.
RansomHub is a ransomware-as-a-service variant—formerly known as Cyclops and Knight—which has recently attracted high-profile affiliates from other prominent variants such as LockBit and ALPHV.
CISA encourages network defenders to review this advisory and apply the recommended mitigations. See #StopRansomware and the #StopRansomware Guide for additional guidance on ransomware protection, detection, and response. Visit CISA’s Cross-Sector Cybersecurity Performance Goals for more information on the CPGs, including added recommended baseline protections.
CISA encourages software manufacturers to take ownership of improving the security outcomes of their customers by applying secure by design methods. For more information on Secure by Design, see CISA’s Secure by Design webpage and joint guide Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software.
CISA Releases Three Industrial Control Systems Advisories
CISA released three Industrial Control Systems (ICS) advisories on August 29, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-24-242-01 Rockwell Automation ThinManager ThinServer
- ICSA-24-242-02 Delta Electronics DTN Soft
- ICSA-24-226-06 Rockwell Automation FactoryTalk View Site Edition (Update A)
CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.
Surge in New Scams as Pig Butchering Dominates
U.S. AI Safety Institute Signs Agreements Regarding AI Safety Research, Testing and Evaluation With Anthropic and OpenAI
CVE-2024-5623 | B&R Industrial Automation B&R APROL up to R 4.4-00P3 untrusted search path
CVE-2024-5624 | B&R Industrial Automation B&R APROL up to R 4.4-00P3 cross site scripting
CVE-2024-43986 | MagePeople Team Taxi Booking Manager for WooCommerce Plugin up to 1.0.9 on WordPress cross site scripting
CVE-2024-5622 | B&R Industrial Automation B&R APROL up to R 4.2-07P3/R 4.4-00P3 unnecessary privileges
U.S. Agencies Warn of Iranian Hacking Group's Ongoing Ransomware Attacks
Answering Your Webinar Questions: Email Security with EasyDMARC
During our recent webinar, “From Setup to Success: ...
The post Answering Your Webinar Questions: Email Security with EasyDMARC appeared first on EasyDMARC.
The post Answering Your Webinar Questions: Email Security with EasyDMARC appeared first on Security Boulevard.