Security Bulletin

30 Sep 2024
Biztonsági szemle
DCRat malware spread with HTML smuggling
Attacks involved the distribution of malicious Russian-language HTML files impersonating TrueConf and VK Messenger apps, which when opened stealthily downloads a password-protected ZIP file with a nested RarSFX archive that launches DCRat.

30 Sep 2024
Biztonsági szemle
US moves against Iranians allegedly behind Trump campaign breach
Bounties of up to $10 million have also been introduced by the U.S. State Department for any information about the hackers — who were noted by a joint federal statement to have shared stolen Trump campaign materials with individuals previously linked...

30 Sep 2024
Biztonsági szemle
Active Directory attack guidance issued by Five Eyes
With Microsoft AD being mostly targeted via Kerberoasting, AS-REP roasting, and password spraying attacks, as well as Microsoft Entra Connect, GPP password, MachineAccountQuota, and certificate service compromise, organizations should leverage...
30 Sep 2024
Biztonsági szemle
CISA’s VDP Platform 2023 Annual Report Showcases Success
Today, the Cybersecurity and Infrastructure Security Agency (CISA) released its Vulnerability Disclosure Policy (VDP) Platform 2023 Annual Report, highlighting the service’s remarkable success in 2023, its second full year of operation. Throughout...

30 Sep 2024
Biztonsági szemle
Shadow AI, Data Exposure Plague Workplace Chatbot Use
Productivity has a downside: A shocking number of employees share sensitive or proprietary data with the generational AI platforms they use, without letting their bosses know.
30 Sep 2024
Biztonsági szemle
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2023-25280 D-Link DIR-820 Router OS Command Injection Vulnerability CVE-2020-15415 DrayTek Multiple Vigor Routers OS...

30 Sep 2024
Biztonsági szemle
Why citizens and campaigns need to improve AI literacy in this very political year
Disinformation spread by deepfakes are rampant in this election cycle – and that’s why the industry needs to help foster AI literacy.

30 Sep 2024
Biztonsági szemle
ISC Stormcast For Monday, September 30th, 2024 https://isc.sans.edu/podcastdetail/9158, (Mon, Sep 30th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

28 Sep 2024
Biztonsági szemle
Gemini for Workspace susceptible to indirect prompt injection, researchers say
Gmail emails, Google Slides and Google Drive files could be used to manipulate the LLM.

27 Sep 2024
Biztonsági szemle
CUPS vulnerabilities put Linux systems at risk of remote code execution
Four vulnerabilities in the Common Unix Printing System (CUPS) could allow for RCE.

27 Sep 2024
Biztonsági szemle
Millions of Kia Vehicles Open to Remote Hacks via License Plate
The vulnerability is the latest discovered in connected vehicles in recent years, and it points out the cyber dangers lurking in automotive APIs.

27 Sep 2024
Biztonsági szemle
How Should CISOs Navigate the SEC Cybersecurity and Disclosure Rules?
Companies that commit to risk management have a strong cybersecurity foundation that makes it easier to comply with the SEC's rules. Here is what you need to know about 8K and 10K filings.
Pagination
- Previous page ‹‹
- Page 332
- Next page ››