Aggregator
CVE-2008-6636 | Geody Dagger dir_edge_skins code injection (EDB-5916 / SA30771)
漏洞盒子SRC:「基因」优势打赢漏洞收集持久战
谛听 | “谛听”团队牵头编制的《工业网络安全态势感知技术规范》标准正式发布
В 10 раз компактнее: новая реализация CRC32C в ядре Linuх
CVE-2003-0759 | IBM DB2 Universal Database up to 7.1 db2licm memory corruption (EDB-106 / XFDB-13217)
SatDump 1.2.0 Released
Notorious WrnRAT Delivered Mimic As Gambling Games
WrnRAT is a new malware attack that cybercriminals have deployed by using popular gambling games like Badugi, Go-Stop, and Hold’em to disguise itself as a malicious program. The attackers created a fraudulent gambling website that, when accessed, prompts users to download a game launcher. Instead of initiating the game, the launcher installs the malicious WrnRAT […]
The post Notorious WrnRAT Delivered Mimic As Gambling Games appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
New Windows Downgrade Attack Let Hackers Downgrade Patched Systems To Exploits
The researcher discovered a vulnerability in the Windows Update process that allowed them to downgrade critical system components, including DLLs, drivers, and the NT kernel. This enabled the attacker to bypass security measures like Secure Boot and expose previously patched vulnerabilities. There are many ways to disable VBS, including Credential Guard and HVCI, even with […]
The post New Windows Downgrade Attack Let Hackers Downgrade Patched Systems To Exploits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2007-6110 | htdig 3.2.0b6 sort cross site scripting (EDB-30818 / Nessus ID 67618)
Hackers Use Fog Ransomware To Attack SonicWall VPNs And Breach Corporate Networks
Recent cyberattacks involving Akira and Fog threat actors have targeted various industries, exploiting a vulnerability (CVE-2024-40766) in SonicWall SSL VPN devices, where these attacks, initiated early in the kill chain, leverage malicious VPN logins from VPS-hosted IP addresses. The rapid escalation from initial access to ransomware encryption, often within the same day, highlights the urgency […]
The post Hackers Use Fog Ransomware To Attack SonicWall VPNs And Breach Corporate Networks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Preparing for the future: Apple’s 45-Day certificate lifespan proposal
The digital certificate lifecycle is undergoing significant changes, with a push towards shorter validity periods for SSL/TLS certificates. Currently, the lifespan of certificates is about 398 days, but companies like Google and Apple are advocating for much shorter terms, with Apple proposing to reduce lifespans to just 45 days by 2027. This shift aims to enhance security by limiting the time a compromised key can be exploited, but it poses challenges for IT teams accustomed to longer renewal periods. Organizations must prepare for this transition by adopting automated certificate management solutions to manage the increased administrative burden effectively.
The post Preparing for the future: Apple’s 45-Day certificate lifespan proposal appeared first on Security Boulevard.
Forced offline: the Q3 2024 Internet disruption summary
Russian charged by U.S. for creating RedLine infostealer malware
Cyber Security Readiness
Cyber Security Readiness Goals: Securing Our Most Critical Systems
Aviatrix unveils features to simplify network security management
Aviatrix unveiled new features and functionality designed to fill critical cloud network security gaps in cloud environments. With its latest software release and introduction of new features, including the Hybrid Cloud Transit and Distributed Cloud Firewall (DCF) integration with enhanced threat intelligence capabilities, Aviatrix is equipping enterprises to secure their cloud egress and hybrid-cloud connectivity, areas that have long posed challenges for cloud-first organizations. As enterprises migrate more workloads and modernize on cloud workloads, they … More →
The post Aviatrix unveils features to simplify network security management appeared first on Help Net Security.