Aggregator
Dark Skippy: одна транзакция может стоить всех ваших криптоактивов
#BHUSA: DARPA's AI Cyber Challenge Heats Up as Healthcare Sector Watches
Roundcube Webmail Flaws Allow Hackers to Steal Emails and Passwords
Hackers Leveraging OneDrive & Google Drive To Hide Malicious Traffic
Attackers, including nation-state actors, increasingly leverage legitimate cloud services for espionage operations, exploiting their low-profile and cost-effective nature. The services, such as Microsoft OneDrive and Google Drive, evade detection by masquerading as trusted entities, thereby enabling covert data exfiltration and tool development. Researchers discovered a novel Go-based backdoor, GoGra, deployed against a South Asian media […]
The post Hackers Leveraging OneDrive & Google Drive To Hide Malicious Traffic appeared first on Cyber Security News.
G.O.S.S.I.P 阅读推荐 2024-08-07 ESem
1Password Vulnerability Let Attackers Exfiltrate Vault Items
A critical vulnerability, designated as CVE-2024-42219, has been identified in 1Password 8 for Mac. This flaw allows malicious actors to exfiltrate vault items by bypassing the app’s platform security protections. Robinhood’s Red Team responsibly disclosed the issue following an independent security assessment of 1Password for Mac. CVE-2024-42219 – The Vulnerability The vulnerability affects the inter-process […]
The post 1Password Vulnerability Let Attackers Exfiltrate Vault Items appeared first on Cyber Security News.
More From Our Main Blog: Defusing AD-Based Risks | Best Practices for Securing Modern Directory Services
Learn how to safeguard AD data risks and how to harden the AD attack surface to reduce the risk of a successful attack.
The post Defusing AD-Based Risks | Best Practices for Securing Modern Directory Services appeared first on SentinelOne.
谛听 工控安全月报 | 7月
So Many Tools, So Many Apps, So Little Visibility!
Ashok:一款多功能开源网络侦查OSINT工具
Nvidia поможет компаниям создавать самых продвинутых роботов-гуманоидов
RHADAMANTHYS Stealer Weaponizing RAR Archive To Steal Login Credentials
A newly surfaced cybercampaign targeting Israeli users has thrust the sophisticated RHADAMANTHYS information stealer into the spotlight. Originating from Russian-speaking cybercriminals and offered as a Malware-as-a-Service, RHADAMANTHYS excels at data exfiltration. Recent samples and in-depth analysis reveal a complex infection chain and extensive payload capabilities, highlighting the evolving threat landscape and underscoring the need for […]
The post RHADAMANTHYS Stealer Weaponizing RAR Archive To Steal Login Credentials appeared first on Cyber Security News.
Researchers Proposed MME Framework To Enhance API Sequence-Based Malware Detection
Deep learning models analyzing API sequences for Windows malware detection face challenges due to evolving malware variants. A group of researchers recently proposed the MME framework, which enhances the existing detectors by leveraging API knowledge graphs and system resource encodings. Utilizing contrastive learning, MME captures similar malicious semantics in evolved malware samples. MME Framework Experimental […]
The post Researchers Proposed MME Framework To Enhance API Sequence-Based Malware Detection appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-7266 | EZD RP up to 15.83/16.14/17.1 User incorrect user management
CVE-2024-7267 | EZD RP up to 19.5 IP Infrastructure unknown vulnerability
CVE-2024-7265 | EZD RP up to 15.83/16.14/17.1 Password incorrect user management
CVE-2024-7553 | MongoDB Server/Driver/PHP Driver on Windows access control
Вредоносные расширения массово захватывают Chrome и Edge
Apache Cloudstack Vulnerability Exposes API & Secret Keys to Admin Accounts
The Apache CloudStack project has announced the release of long-term support (LTS) security updates, versions 4.18.2.3 and 4.19.1.1, which address two critical vulnerabilities, CVE-2024-42062 and CVE-2024-42222. These vulnerabilities pose significant risks to the integrity, confidentiality, and availability of CloudStack-managed infrastructure. CVE-2024-42062: User Key Exposure to Domain Admins CVE-2024-42062 is a critical vulnerability that affects Apache […]
The post Apache Cloudstack Vulnerability Exposes API & Secret Keys to Admin Accounts appeared first on Cyber Security News.