Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30531 bookmarks
Custom sorting
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw
Mitel Networks has released security updates to patch a critical-severity authentication bypass vulnerability impacting its MiVoice MX-ONE enterprise communications platform.
·bleepingcomputer.com·
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw
Malware Campaign Masquerades as Dating Apps to Steal Data
Malware Campaign Masquerades as Dating Apps to Steal Data
A large-scale malware campaign known as SarangTrap has been observed using fake dating apps to steal personal data, targeting South Korean users
·infosecurity-magazine.com·
Malware Campaign Masquerades as Dating Apps to Steal Data
Bloomberg Comdb2 null pointer dereference and denial-of-service vulnerabilities
Bloomberg Comdb2 null pointer dereference and denial-of-service vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed five vulnerabilities in Bloomberg Comdb2.   Comdb2 is an open source, high-availability database developed by Bloomberg. It supports features such as clustering, transactions, snapshots, and isolation. The implementation of the database utilizes optimistic locking for concurrent operation. The vulnerabilities mentioned in this blog post have been patched by the vendor, all in adherence to Cisco’s third-party vulnerability
·blog.talosintelligence.com·
Bloomberg Comdb2 null pointer dereference and denial-of-service vulnerabilities
Ransomware Deployed in Compromised SharePoint Servers
Ransomware Deployed in Compromised SharePoint Servers
Microsoft said Chinese actor Storm-2603 is deploying Warlock ransomware following the exploitation of vulnerabilities in on-prem SharePoint systems
·infosecurity-magazine.com·
Ransomware Deployed in Compromised SharePoint Servers
How GenAI Is Reshaping GRC | Agentic Risk Intelligence | CSA
How GenAI Is Reshaping GRC | Agentic Risk Intelligence | CSA
As companies feel mounting pressure to document cybersecurity controls & demonstrate risk maturity, we are witnessing the latest GRC wave—the AI revolution.
·cloudsecurityalliance.org·
How GenAI Is Reshaping GRC | Agentic Risk Intelligence | CSA
How Solid Protocol Restores Digital Agency - Schneier on Security
How Solid Protocol Restores Digital Agency - Schneier on Security
The current state of digital identity is a mess. Your personal information is scattered across hundreds of locations: social media companies, IoT companies, government agencies, websites you have accounts on, and data brokers you’ve never heard of. These entities collect, store, and trade your data, often without your knowledge or consent. It’s both redundant and inconsistent. You have hundreds, maybe thousands, of fragmented digital profiles that often contain contradictory or logically impossible information. Each serves its own purpose, yet there is no central override and control to serve you—as the identity owner...
·schneier.com·
How Solid Protocol Restores Digital Agency - Schneier on Security
Stealth backdoor found in WordPress mu-Plugins folder
Stealth backdoor found in WordPress mu-Plugins folder
New stealth backdoor discovered in the WordPress mu-plugins folder, granting attackers persistent access and control over compromised sites
·securityaffairs.com·
Stealth backdoor found in WordPress mu-Plugins folder
Unmasking the new Chaos RaaS group attacks
Unmasking the new Chaos RaaS group attacks
Cisco Talos Incident Response (Talos IR) recently observed attacks by Chaos, a relatively new ransomware-as-a-service (RaaS) group conducting big-game hunting and double extortion attacks.
·blog.talosintelligence.com·
Unmasking the new Chaos RaaS group attacks
SonicWall urges admins to patch critical RCE flaw in SMA 100 devices
SonicWall urges admins to patch critical RCE flaw in SMA 100 devices
SonicWall urges customers to patch SMA 100 series appliances against a critical authenticated arbitrary file upload vulnerability that can let attackers gain remote code execution.
·bleepingcomputer.com·
SonicWall urges admins to patch critical RCE flaw in SMA 100 devices