#CyberSecurityNews
Citizens Bank of West Virginia Hit by LockBit Cyberattack, Deadline Looms https://thecyberexpress.com/citizens-bank-of-west-virginia-cyberattack/ #CitizensBankofWestVirginiaCyberattack #TheCyberEpressNews #cybersecuritynews #CyberattackNews #TheCyberExpress #DataBreachNews #FirewallDaily
Spying through Push Notifications – Source: www.schneier.com https://ciso2ciso.com/spying-through-push-notifications-source-www-schneier-com/ #rssfeedpostgeneratorecho #nationalsecuritypolicy #SchneierOnSecurity #SchneieronSecurity #CyberSecurityNews #Uncategorized #surveillance #transparency #metadata #privacy #Spyware
OCR Resolves First HIPAA Phishing Case: Lafourche Medical Group Settles for US$480000 https://thecyberexpress.com/lafourche-medical-group-settles-with-hhs/ #CybersecurityMeasures #LafourcheMedicalGroup #TheCyberExpressNews #CybersecurityNews #cybersecuritynews #TheCyberExpress #Phishingattack #FirewallDaily
TA422 Hackers Attack Organizations Using Outlook & WinRAR Vulnerabilities https://gbhackers.com/ta422-hackers-attack-organizations/ #CyberSecurityNews #cybersecurity
TA422 Hackers Attack Organizations Using Outlook & WinRAR Vulnerabilities https://gbhackers.com/ta422-hackers-attack-organizations/ #CyberSecurityNews #cybersecurity
Russian military hackers target NATO fast reaction corps – Source: www.bleepingcomputer.com https://ciso2ciso.com/russian-military-hackers-target-nato-fast-reaction-corps-source-www-bleepingcomputer-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #BLEEPINGCOMPUTER #BleepingComputer #Security
23andMe updates user agreement to prevent data breach lawsuits – Source: www.bleepingcomputer.com https://ciso2ciso.com/23andme-updates-user-agreement-to-prevent-data-breach-lawsuits-source-www-bleepingcomputer-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #BLEEPINGCOMPUTER #BleepingComputer #Security
Windows 11 Notepad gets a built-in character counter, finally – Source: www.bleepingcomputer.com https://ciso2ciso.com/windows-11-notepad-gets-a-built-in-character-counter-finally-source-www-bleepingcomputer-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #BLEEPINGCOMPUTER #BleepingComputer #Microsoft
Russian pleads guilty to running crypto-exchange used by ransomware gangs – Source: www.bleepingcomputer.com https://ciso2ciso.com/russian-pleads-guilty-to-running-crypto-exchange-used-by-ransomware-gangs-source-www-bleepingcomputer-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #BLEEPINGCOMPUTER #BleepingComputer #cryptocurrency #Security
WordPress fixes POP chain exposing websites to RCE attacks – Source: www.bleepingcomputer.com https://ciso2ciso.com/wordpress-fixes-pop-chain-exposing-websites-to-rce-attacks-source-www-bleepingcomputer-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #BLEEPINGCOMPUTER #BleepingComputer #Security
UK and allies expose Russian FSB hacking group, sanction members – Source: www.bleepingcomputer.com https://ciso2ciso.com/uk-and-allies-expose-russian-fsb-hacking-group-sanction-members-source-www-bleepingcomputer-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #BLEEPINGCOMPUTER #BleepingComputer #Security
Meta rolls out default end-to-end encryption on Messenger, Facebook – Source: www.bleepingcomputer.com https://ciso2ciso.com/meta-rolls-out-default-end-to-end-encryption-on-messenger-facebook-source-www-bleepingcomputer-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #BLEEPINGCOMPUTER #BleepingComputer #Security
Krasue RAT malware hides on Linux servers using embedded rootkits – Source: www.bleepingcomputer.com https://ciso2ciso.com/krasue-rat-malware-hides-on-linux-servers-using-embedded-rootkits-source-www-bleepingcomputer-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #BLEEPINGCOMPUTER #BleepingComputer #Security #LINUX
Widespread Windows and Linux Vulnerabilities Could Let Attackers Sneak in Malicious Code Before Boot – Source: www.techrepublic.com https://ciso2ciso.com/widespread-windows-and-linux-vulnerabilities-could-let-attackers-sneak-in-malicious-code-before-boot-source-www-techrepublic-com/ #rssfeedpostgeneratorecho #SecurityonTechRepublic #SecurityTechRepublic #phoenixtechnologies #CyberSecurityNews #hardware #Security #Windows #insyde #lenovo #Intel #LINUX #Acer #AMI #arm #CXO #x86
Bitwarden vs LastPass 2023: Which Password Manager Is Best? – Source: www.techrepublic.com https://ciso2ciso.com/bitwarden-vs-lastpass-2023-which-password-manager-is-best-source-www-techrepublic-com/ #rssfeedpostgeneratorecho #SecurityonTechRepublic #SecurityTechRepublic #Passwordmanagement #CyberSecurityNews #passwordsecurity #passwordmanager #Bitwarden #LastPass #password #Security #Software
Norton Secure VPN Review (2023): Pricing, Features & Security – Source: www.techrepublic.com https://ciso2ciso.com/norton-secure-vpn-review-2023-pricing-features-security-source-www-techrepublic-com/ #rssfeedpostgeneratorecho #SecurityonTechRepublic #SecurityTechRepublic #CyberSecurityNews #CloudSecurity #NortonVPN #Security #VPN
Dashlane vs 1Password: Which password manager should you use in 2023? – Source: www.techrepublic.com https://ciso2ciso.com/dashlane-vs-1password-which-password-manager-should-you-use-in-2023-source-www-techrepublic-com/ #rssfeedpostgeneratorecho #SecurityonTechRepublic #SecurityTechRepublic #CyberSecurityNews #passwordmanager #CloudSecurity #1Password #Dashlane #Security
Securities and Exchange Commission Cyber Disclosure Rules: How to Prepare for December Deadlines – Source: www.techrepublic.com https://ciso2ciso.com/securities-and-exchange-commission-cyber-disclosure-rules-how-to-prepare-for-december-deadlines-source-www-techrepublic-com/ #SecuritiesandExchangeCommission #rssfeedpostgeneratorecho #SecurityonTechRepublic #SecurityTechRepublic #CyberSecurityNews #Cybersecurity #threatactors #Deloitte #Security #CXO
How Data Ingestion Works in SOAR – Source: securityboulevard.com https://ciso2ciso.com/how-data-ingestion-works-in-soar-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #SecurityAutomation #CyberSecurityNews #SecurityBoulevard #Endpointsecurity #IncidentResponse #NetworkSecurity #APIIntegration #Cybersecurity #DataIngestion #PullRequests #endpoint #Webhooks #DevOps #soar
Merry and Cyber Resilient: Are Holiday Bots Actually Helping Your Business? – Source: securityboulevard.com https://ciso2ciso.com/merry-and-cyber-resilient-are-holiday-bots-actually-helping-your-business-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #CyberSecurityNews #SecurityBoulevard #botmanagement #botdetection #botattacks
DEF CON 31 – Dan Petro’s, David Vargas’ ‘Badge Of Shame Breaking Into Secure Facilities With OSDP’ – Source: securityboulevard.com https://ciso2ciso.com/def-con-31-dan-petros-david-vargas-badge-of-shame-breaking-into-secure-facilities-with-osdp-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #cybersecurityeducation #InfosecurityEducation #SecurityArchitecture #InformationSecurity #SecurityConferences #CyberSecurityNews #SecurityBoulevard #DEFCONConference
News alert: Reflectiz adds AI-powered capabilities to its Smart Alerting web threat management system – Source: securityboulevard.com https://ciso2ciso.com/news-alert-reflectiz-adds-ai-powered-capabilities-to-its-smart-alerting-web-threat-management-system-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #CyberSecurityNews #SecurityBoulevard #Uncategorized #TopStories #SBNNews
CISA to Developers: Adopt Memory Safe Programming Languages – Source: securityboulevard.com https://ciso2ciso.com/cisa-to-developers-adopt-memory-safe-programming-languages-source-securityboulevard-com/ #SecurityBoulevard(Original) #rssfeedpostgeneratorecho #memorysafelanguage #CyberSecurityNews #IndustrySpotlight #SecurityBoulevard #NetworkSecurity #vulnerabilities #MobileSecurity #SocialFacebook #SocialLinkedIn #Cybersecurity #datasecurity #Spotlight #endpoint #FEATURED #SocialX #DevOps #CISA
Microsoft CISO, Deputy CISO Reassigned in Management Shakeup – Source: www.databreachtoday.com https://ciso2ciso.com/microsoft-ciso-deputy-ciso-reassigned-in-management-shakeup-source-www-databreachtoday-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DataBreachToday #DataBreachToday #Microsoft #Deputy
Israel-Hamas War: ‘We All Know Someone That Lost Someone’ – Source: www.databreachtoday.com https://ciso2ciso.com/israel-hamas-war-we-all-know-someone-that-lost-someone-source-www-databreachtoday-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DataBreachToday #DataBreachToday #IsraelHamas #Someone
Live Webinar | Integrating Splunk and Panther for Real-Time Alerting and Custom Dashboarding – Source: www.databreachtoday.com https://ciso2ciso.com/live-webinar-integrating-splunk-and-panther-for-real-time-alerting-and-custom-dashboarding-source-www-databreachtoday-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DataBreachToday #DataBreachToday #Integrating #Webinar
Feds Levy First-Ever HIPAA Fine for a Phishing Breach – Source: www.databreachtoday.com https://ciso2ciso.com/feds-levy-first-ever-hipaa-fine-for-a-phishing-breach-source-www-databreachtoday-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DataBreachToday #DataBreachToday #FirstEver #HIPAA
On Demand | Proverbial GRC: Navigating Stormy Seas with Strategic Parables – Source: www.databreachtoday.com https://ciso2ciso.com/on-demand-proverbial-grc-navigating-stormy-seas-with-strategic-parables-source-www-databreachtoday-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DataBreachToday #DataBreachToday #Proverbial #Demand
UK and US Accuse Russian FSB of ‘Hack and Leak’ Operation – Source: www.databreachtoday.com https://ciso2ciso.com/uk-and-us-accuse-russian-fsb-of-hack-and-leak-operation-source-www-databreachtoday-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DataBreachToday #DataBreachToday #Russian #accuse
The Joint Commission Unveils New Data Privacy Certification – Source: www.databreachtoday.com https://ciso2ciso.com/the-joint-commission-unveils-new-data-privacy-certification-source-www-databreachtoday-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DataBreachToday #DataBreachToday #Commission #Joint
Microsoft Warns of COLDRIVER’s Evolving Evading and Credential-Stealing Tactics – Source:thehackernews.com https://ciso2ciso.com/microsoft-warns-of-coldrivers-evolving-evading-and-credential-stealing-tactics-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #Microsoft #Warns
New Bluetooth Flaw Let Hackers Take Over Android, Linux, macOS, and iOS Devices – Source:thehackernews.com https://ciso2ciso.com/new-bluetooth-flaw-let-hackers-take-over-android-linux-macos-and-ios-devices-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #Bluetooth #hackers
Hacking the Human Mind: Exploiting Vulnerabilities in the ‘First Line of Cyber Defense’ – Source:thehackernews.com https://ciso2ciso.com/hacking-the-human-mind-exploiting-vulnerabilities-in-the-first-line-of-cyber-defense-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #hacking #Human
News alert: Reflectiz adds AI-powered capabilities to its Smart Alerting web threat management system – Source: www.lastwatchdog.com https://ciso2ciso.com/news-alert-reflectiz-adds-ai-powered-capabilities-to-its-smart-alerting-web-threat-management-system-source-www-lastwatchdog-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheLastWatchdog #Uncategorized #TopStories
A guide to avoiding 10 common holiday scams this season – Source: www.cybertalk.org https://ciso2ciso.com/a-guide-to-avoiding-10-common-holiday-scams-this-season-source-www-cybertalk-org/ #rssfeedpostgeneratorecho #CyberSecurityNews #socialengineering #grandparentscams #cybersecurity #Cybersecurity #MobileMalware #TRENDINGNOW #CyberTalk #holidays #Phishing #Scams #BEC
Researchers Show How to Use One LLM to Jailbreak Another – Source: www.darkreading.com https://ciso2ciso.com/researchers-show-how-to-use-one-llm-to-jailbreak-another-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #DARKReading #Researchers #Jailbreak
Proxy Trojan Targets macOS Users for Traffic Redirection – Source: www.darkreading.com https://ciso2ciso.com/proxy-trojan-targets-macos-users-for-traffic-redirection-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #DARKReading #Trojan #proxy
Ransomware, Data Breaches Inundate OT & Industrial Sector – Source: www.darkreading.com https://ciso2ciso.com/ransomware-data-breaches-inundate-ot-industrial-sector-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #DARKReading #ransomware #Breaches
Ransomware Attacks on Industrial Orgs Increasingly Impact OT Systems: Survey – Source: www.securityweek.com https://ciso2ciso.com/ransomware-attacks-on-industrial-orgs-increasingly-impact-ot-systems-survey-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #securityweekcom #securityweek #ransomware #ICS/OT #ICS #OT
Cisco intros AI to find firewall flaws, warns this sort of thing can’t be free – Source: go.theregister.com https://ciso2ciso.com/cisco-intros-ai-to-find-firewall-flaws-warns-this-sort-of-thing-cant-be-free-source-go-theregister-com/ #rssfeedpostgeneratorecho #TheRegisterSecurity #CyberSecurityNews #TheRegister #intros #Cisco
Dragos Offering Free OT Cybersecurity Technology to Small US Utilities – Source: www.securityweek.com https://ciso2ciso.com/dragos-offering-free-ot-cybersecurity-technology-to-small-us-utilities-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #securityweekcom #securityweek #Dragos #ICS/OT #ICS #OT
Supply-chain ransomware attack causes outages at over 60 credit unions – Source: www.tripwire.com https://ciso2ciso.com/supply-chain-ransomware-attack-causes-outages-at-over-60-credit-unions-source-www-tripwire-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #grahamcluleycom #Vulnerability #CitrixBleed' #Grahamcluley #DataBreach #ransomware #Guestblog #Dataloss #Malware
Steve Katz, World’s First CISO, Dies in Hospice Care – Source: www.databreachtoday.com https://ciso2ciso.com/steve-katz-worlds-first-ciso-dies-in-hospice-care-source-www-databreachtoday-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DataBreachToday #DataBreachToday #Worlds #Steve
North Korean Hackers Have Stolen Over $3 Billion in Cryptocurrency: Report – Source: www.securityweek.com https://ciso2ciso.com/north-korean-hackers-have-stolen-over-3-billion-in-cryptocurrency-report-source-www-securityweek-com/ #rssfeedpostgeneratorecho #ThreatIntelligence #CyberSecurityNews #securityweekcom #cryptocurrency #DataBreaches #securityweek #NationState #Cybercrime #NorthKorea #Kimsuky #Lazarus
The Guardian reports that the UK's nuclear site Sellafield has been hacked into by cyber groups closely linked to Russia and China. They do not identify which groups.
🔗 https://www.theguardian.com/business/2023/dec/04/sellafield-nuclear-site-hacked-groups-russia-china
#Sellafield #Russia #China #nuclear #cyberespionage #cybersecuritynews
Active Attacks Targeting Google Chrome & ownCloud Flaws: CISA Warns https://gbhackers.com/cisa-warns-google-chromflaws/ #CyberSecurityNews #cybersecurity #Vulnerability #Chrome #Google
The UK's NCSC concurs with CISA's security advisory "Exploitation of Unitronics PLCs used in Water and Wastewater Systems." This follows the 25 November 2023 reporting that Iran-backed Cyber Av3ngers compromised The Municipal Water Authority of Aliquippa, PA. If you own a Unitronics Vision PLC, please ensure that the default password "1111" is not in use.
🔗 https://www.ncsc.gov.uk/news/ncsc-statement-following-exploitation-of-unitronics-programmable-logic-controllers
#CISA #Unitronics #PLC #Aliquippa #CyberAv3ngers #Iran #cybersecuritynews
The Record: North Texas Municipal Water District (NTMWD), a water utility company serving 2 million, hit with cyberattack. Daixin Team claimed responsibility for the attack. This comes one day after the Municipal Water Authority of Aliquippa was attacked by the Iranian-backed hacking group Cyber Av3ngers.
🔗 https://therecord.media/north-texas-water-utility-cyberattack
These 7 items should be on your CISO checklist for 2024 – Source: www.cybertalk.org https://ciso2ciso.com/these-7-items-should-be-on-your-ciso-checklist-for-2024-source-www-cybertalk-org-2/ #rssfeedpostgeneratorecho #CitizenDevelopers #CyberSecurityNews #SecurityMaturity #CyberCriminals #CloudSecurity #cybersecurity #Cybersecurity #TRENDINGNOW #AIredteam #CyberTalk #zerotrust #CXOFILES #hackers #SaaS #ztna #AI
LummaC2 Malware Deploys New Trigonometry-Based Anti-Sandbox Technique – Source:thehackernews.com https://ciso2ciso.com/lummac2-malware-deploys-new-trigonometry-based-anti-sandbox-technique-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #Malware #LummaC
OpenAI Fires CEO Sam Altman for Lying to Board of Directors – Source: www.govinfosecurity.com https://ciso2ciso.com/openai-fires-ceo-sam-altman-for-lying-to-board-of-directors-source-www-govinfosecurity-com/ #rssfeedpostgeneratorecho #govinfosecuritycom #CyberSecurityNews #OpenAI #Fires
Apple warns Armenians of state-sponsored hacking attempts. The Record speculates that the spyware dropped is Pegasus and that the attacks are linked to Azerbaijan, which is a safe assumption given the ongoing Armenia-Azerbaijan conflicts.
Link: https://therecord.media/apple-warns-armenians-state-sponsored-hacking-attempts-azerbaijan
Microsoft published a new blog with an analysis of the TTPs of the Octo Tempest group (also known as 0ktapus or Scattered Spider), a financially motivated threat actor that relies heavily on #socialengineering for initial access.
This group is reportedly the one behind the Okta, MGM Resorts & Caesars this year, as well as the MailChimp & Twilio attacks last year.
"Octo Tempest commonly launches social engineering attacks targeting technical administrators, such as support and help desk personnel, who have permissions that could enable the threat actor to gain initial access to accounts. The threat actor performs research on the organization & identifies targets to effectively impersonate victims, mimicking idiolect on phone calls & understanding personal identifiable information to trick technical administrators into performing password resets & resetting MFA"
"Octo Tempest leverages tradecraft that many organizations don’t have in their typical threat models, such as SMS phishing, SIM swapping, and advanced social engineering techniques."
In reality, most organizations don't have a social engineering security protocol for most types of social engineering attacks beyond #phishing and *some* vishing attacks/tactics. There is a lot of work to be done...
The blog:
#cybersecurity #cybersecuritynews #threatintelligence #scatteredspider #threatactors #infosec
New BiBi-Linux wiper malware targets Israeli orgs in destructive attacks – Source: www.bleepingcomputer.com https://ciso2ciso.com/new-bibi-linux-wiper-malware-targets-israeli-orgs-in-destructive-attacks-source-www-bleepingcomputer-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #BLEEPINGCOMPUTER #BleepingComputer #Security #LINUX
🚨The ENISA Threat Landscape Report 2023 was released today!
It includes the top threats, major trends observed with respect to threats, threat actors & attack techniques, impact and motivation analysis.
It also describes relevant mitigation measures.
The top 3 threats that were identified and analyzed were:
🔹 Ransomware
🔹 Malware
🔹 Social Engineering
The report is a very insightful resource, especially for those who seek to make informed decisions for their cybersecurity strategy the coming year.
#cybersecurity #threatlandscape #cybersecurityawareness #cybersecuritynews #socialengineering #infosec #informationsecurity #ransomware #malware #enisa
https://www.enisa.europa.eu/topics/cyber-threats/threats-and-trends
Encrypted messaging app Signal has pushed back against "viral reports" of an alleged zero-day flaw in its software, stating it found no evidence to support the claim. "After responsible investigation *we have no evidence that suggests this vulnerability is real nor has any additional info been shared via our official reporting channels,"* it said in a series of messages posted on the deadbird site.
Link: https://thehackernews.com/2023/10/signal-debunks-zero-day-vulnerability.html
TBH I'm surprised this didn't happen sooner. Home routers are often thought of only when they fail in their purpose. APT and nationstate sponsored attacks can only be protected against only with concerted effort.
Resolving this problem is not simple. The ISP can't simply force updates to a wide array of devices that they may or may not own/control on the other end of the connection.
I haven't had consumer grade networking equipment in my house in years. The real issue with consumer grade tech, in my mind, is the lack of long term support. This leading to situations where updates aren't even flowing for those that take the time to periodically update!
#cybersecuritynews #homerouters #statesponsored #statesponsoredattack
Does anyone know any cybersecurity reporters who'd be interested in a potential data leak at a European airline? My dms are open. #infosec #cybersecuritynews
20 bits a second using high frequency audio. Clever way to target endpoints. The internal speaker seems almost pointless in a lot of machines... Perhaps buildings l vulnerabilities such as this will convince manufacturers to remove them?
It's about time! Five years is a long, long time, where cybersecurity is concerned. Looking forward to seeing the updated framework, down the line.
#cybersecurity #cybersec #cybersecuritynews #nist #nistcsf
https://portswigger.net/daily-swig/nist-plots-biggest-ever-reform-of-cybersecurity-framework
Circle City Con crew has been busy! Visit our new website! Not only is it redesigned; it has a list of speakers and the general schedule for CircleCityCon 10.0 #WhoDunit!
Check it out! https://circlecitycon.org
#indianapolis #CybersecurityNews #infosec #midwest #Conferences
Nice write-up and PoC for the "Not believed to be exploitable" recently patched double-free OpenSSH bug. Thanks jfrog!
#cybersecuritynews #PoC #doublefree #openssh #jfrog
https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/
The Psychology Behind Spear Phishing Scams
https://www.cyberdefensemagazine.com/the-psychology-behind-spear-phishing-scams/
#CyberSecurityNews
Glad most distros aren't enabling ksmbd by default! Another RCE has been discovered. Great breakdown of detection and mitigating here.
#cybersecuritynews #rce #KSMBD
https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/
This is a fantastic dissection of the #EvilESP TCP/IP RCE vulnerability that was patched by Microsoft. I don't have time to finish reading or follow along myself currently, but I definitely plan on playing with this later today after work!
Understanding the mechanisms that are abused to achieve the exploit is what helps me fully grasp the implications of the vulnerability.
#cybersecuritynews #rce #tcpip
https://securityintelligence.com/posts/dissecting-exploiting-tcp-ip-rce-vulnerability-evilesp/
Just another friendly reminder to not reuse credentials - ever! I use a self hosted instance of bitwarden, but there are plenty of tools to manage credentials.
#cybersecuritynews #paypal #credentialstuffing #credentialstuffingattack
I've heard about WiFi signal absorption being used to determine occupancy, but this is next level!
#cybersecuritynews #wifi #reconnaissance
https://www.tomshardware.com/news/wi-fi-routers-used-to-detect-human-locations-poses-within-a-room
Five months between the foothold and the pivot. This is some serious long-game technique. More reason than ever to stay on top of patching!
Well... I did it. I migrated (from https://nerfherders.io/@jack). Self-Hosting Mastodon was a blast but I'm changing roles professionally and won't have time for the work it takes. It's bittersweet. My old domain is currently dying a slow death, but trying to let the few users remaining migrate off of it.
I think I've found my new home though, this looks like an instance that is right up my alley.
Hi again, Fediverse! This is my re-#introduction post I suppose. I hope you're ready for more of my #cybersecuritynews and #cats posts!!
It's official! @seanmartin and I are covering #RSAC2023 - our 8th year in a row with @ITSPmagazine as official media partners for the event. Hope to see you all there! You can follow all of our shenanigans and adventures on the @ITSPmagazine coverage page at https://www.itspmagazine.com/rsac
Follow us and/or join us by sponsoring the coverage! There will be content created with organizers, keynotes, speakers, and all our many friends!
Let’s go! Is going to be a memorable adventure!
#infosec #conference #cybersecurity #cybersecuritynews #infosecjobs #podcasts #videos #livestream #tech #technology #society #ai #business #security