Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30122 bookmarks
Custom sorting
US hits senior North Korean officials with sanctions, $3 million bounties
US hits senior North Korean officials with sanctions, $3 million bounties
Kim Se Un, Jo Kyong Hun and Myong Chol Min are accused of helping North Korea evade U.S. and United Nations sanctions through an IT worker plot that involved tricking companies into hiring North Koreans using stolen identities.
·therecord.media·
US hits senior North Korean officials with sanctions, $3 million bounties
BlackSuit ransomware leak sites seized in Operation Checkmate
BlackSuit ransomware leak sites seized in Operation Checkmate
Law enforcement has seized the dark web leak sites of the BlackSuit ransomware operation, which has targeted and breached the networks of hundreds of organizations worldwide over the past several years.
·bleepingcomputer.com·
BlackSuit ransomware leak sites seized in Operation Checkmate
New Koske Linux malware hides in cute panda images
New Koske Linux malware hides in cute panda images
A new Linux malware named Koske may have been developed with artificial intelligence and is using seemingly benign JPEG images of panda bears to deploy malware directly into system memory.
·bleepingcomputer.com·
New Koske Linux malware hides in cute panda images
BRB, pausing for a "Sanctuary Moon" marathon
BRB, pausing for a "Sanctuary Moon" marathon
Get to know the real people behind cybersecurity’s front lines. In this week’s newsletter, sci-fi meets reality, humanity powers technology and a few surprises are waiting to be discovered.
·blog.talosintelligence.com·
BRB, pausing for a "Sanctuary Moon" marathon
Phishers Target Aviation Execs to Scam Customers
Phishers Target Aviation Execs to Scam Customers
KrebsOnSecurity recently heard from a reader whose boss's email account got phished and was used to trick one of the company's customers into sending a large payment to scammers. An investigation into the attacker's infrastructure points to a long-running Nigerian…
·krebsonsecurity.com·
Phishers Target Aviation Execs to Scam Customers
Hacker sneaks infostealer malware into early access Steam game
Hacker sneaks infostealer malware into early access Steam game
A threat actor called EncryptHub has compromised a game on Steam to distribute info-stealing malware to unsuspecting users downloading the title.
·bleepingcomputer.com·
Hacker sneaks infostealer malware into early access Steam game
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw
Mitel Networks has released security updates to patch a critical-severity authentication bypass vulnerability impacting its MiVoice MX-ONE enterprise communications platform.
·bleepingcomputer.com·
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw
Malware Campaign Masquerades as Dating Apps to Steal Data
Malware Campaign Masquerades as Dating Apps to Steal Data
A large-scale malware campaign known as SarangTrap has been observed using fake dating apps to steal personal data, targeting South Korean users
·infosecurity-magazine.com·
Malware Campaign Masquerades as Dating Apps to Steal Data
Bloomberg Comdb2 null pointer dereference and denial-of-service vulnerabilities
Bloomberg Comdb2 null pointer dereference and denial-of-service vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed five vulnerabilities in Bloomberg Comdb2.   Comdb2 is an open source, high-availability database developed by Bloomberg. It supports features such as clustering, transactions, snapshots, and isolation. The implementation of the database utilizes optimistic locking for concurrent operation. The vulnerabilities mentioned in this blog post have been patched by the vendor, all in adherence to Cisco’s third-party vulnerability
·blog.talosintelligence.com·
Bloomberg Comdb2 null pointer dereference and denial-of-service vulnerabilities
Ransomware Deployed in Compromised SharePoint Servers
Ransomware Deployed in Compromised SharePoint Servers
Microsoft said Chinese actor Storm-2603 is deploying Warlock ransomware following the exploitation of vulnerabilities in on-prem SharePoint systems
·infosecurity-magazine.com·
Ransomware Deployed in Compromised SharePoint Servers
How GenAI Is Reshaping GRC | Agentic Risk Intelligence | CSA
How GenAI Is Reshaping GRC | Agentic Risk Intelligence | CSA
As companies feel mounting pressure to document cybersecurity controls & demonstrate risk maturity, we are witnessing the latest GRC wave—the AI revolution.
·cloudsecurityalliance.org·
How GenAI Is Reshaping GRC | Agentic Risk Intelligence | CSA