Security Bulletin

10 Feb 2025
Biztonsági szemle
Analyst Burnout Is an Advanced Persistent Threat
For too long, we've treated our analysts as mere cogs in a machine, expecting them to conform to the limitations of our tools and processes. It's time to revolutionize security operations.

10 Feb 2025
Biztonsági szemle
Reminder: 7-Zip & MoW, (Mon, Feb 10th)
CVE-2025-0411 is a vulnerability in 7-zip that has been reported to be exploited in recent attacks. The problem is that Mark-of-Web (MoW) isn't propagated correctly: when extracted, a file inside a ZIP file inside another ZIP file will not...

10 Feb 2025
Biztonsági szemle
ISC Stormcast For Monday, February 10th, 2025 https://isc.sans.edu/podcastdetail/9316, (Mon, Feb 10th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

8 Feb 2025
Biztonsági szemle
Crypto Wallet Scam: Not For Free, (Sat, Feb 8th)
I did some research into multisig wallets (cfr " Crypto Wallet Scam"), and discovered that setting up such a wallet on the TRON network comes with a cost: about $23.

7 Feb 2025
Biztonsági szemle
Ransomware attackers turn to workers for data breach access
Ransomware operators are pitching victims to infect additional machines on their company network.

7 Feb 2025
Biztonsági szemle
AI Cheese, CISA, Scaryware, Kimsuky Returns, Backups, Encryption, Jason Wood... - SWN #449

7 Feb 2025
Biztonsági szemle
CISA warns Trimble Cityworks customers of actively exploited RCE flaw
Immediately patching is recommended due to the risk of RCE on Microsoft IIS web servers in critical infrastructure sectors.

7 Feb 2025
Biztonsági szemle
LLM Hijackers Quickly Incorporate DeepSeek API Keys
The secret use of other people's generative AI platforms, wherein hijackers gain unauthorized access to an LLM while someone else foots the bill, is getting quicker and stealthier by the month.

7 Feb 2025
Biztonsági szemle
SolarWinds to Go Private for $4.4B
Five years after a Russian APT infiltrated a software update to gain access to thousands of SolarWinds customers, the board has voted unanimously to sell at a top valuation and plans for uninterrupted operations.

7 Feb 2025
Biztonsági szemle
Microsoft: Thousands of Public ASP.NET Keys Allow Web Server RCE
Developers are pulling in publicly available ASP.NET keys into their environments, without realizing that cyberattackers can use them for clandestine code injection.

7 Feb 2025
Biztonsági szemle
3,000 exposed ASP.NET keys could perform code injection attacks
Microsoft worries the leaked keys could be pushed into development code without modification, leaving it open to security issues.

7 Feb 2025
Biztonsági szemle
Evolving cloud landscape leads to security challenges
To address these threats artificial intelligence-powered tools have been developed to enhance threat detection and response, while zero-trust architecture has become a widely accepted framework for cloud security thanks to its strict identity...
Pagination
- Previous page ‹‹
- Page 292
- Next page ››