Biztonsági szemle

2024. Júl. 29.
Biztonsági szemle
Third-party breach impacts Gemini
Infiltration of the third-party provider's systems between June 3 and 7 allowed threat actors to exfiltrate the customers' certain banking details, including full names, bank account numbers, and routing numbers leveraged for ACH fund transfers.

2024. Júl. 29.
Biztonsági szemle
CrowdStrike outage exploited in new spear-phishing campaign
The campaign lured targets into downloading a fraudulent CrowdStrike Crash Reporter tool as a ZIP file with a trojanized InnoSetup installer.
2024. Júl. 29.
Biztonsági szemle
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-4879 ServiceNow Improper Input Validation Vulnerability CVE-2024-5217 ServiceNow Incomplete List of Disallowed...

2024. Júl. 29.
Biztonsági szemle
Three ways to mitigate AI-based supply chain attacks
Security teams have to face that the attackers also have AI – here are three ways to more effectively operate in this new environment.

2024. Júl. 29.
Biztonsági szemle
China-Backed Phishing Attack Targets India Postal System Users
A large text-message phishing attack campaign attributed to the China-based Smishing Triad employs malicious iMessages.

2024. Júl. 29.
Biztonsági szemle
ISC Stormcast For Monday, July 29th, 2024 https://isc.sans.edu/podcastdetail/9072, (Mon, Jul 29th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

2024. Júl. 29.
Biztonsági szemle
CrowdStrike Outage Themed Maldoc, (Mon, Jul 29th)
I found a malicious Word document with VBA code using the CrowdStrike outage for social engineering purposes. It's an .ASD file (AutoRecover file). My tool oledump.py can analyze it:

2024. Júl. 29.
Biztonsági szemle

Quickie: Password Cracking & Energy, (Sun, Jul 28th)
When Johannes talked about my diary entry " Protected OOXML Spreadsheets" on his StormCast podcast, he mentioned that I privately shared data on the power consumption of my desktop with a NVIDIA GeForce RTX 3080 GPU when running Hashcat.

2024. Júl. 27.
Biztonsági szemle
Create Your Own BSOD: NotMyFault, (Sat, Jul 27th)
With all the Blue Screen Of Death screenshots we saw lately, I got the idea to write about Sysinternals' tool NotMyFault.

2024. Júl. 26.
Biztonsági szemle
PKFail bug puts firmware security at risk
Researchers say that a years-old security leak is putting a number of production model PCs at risk of persistent remote takeover.

2024. Júl. 26.
Biztonsági szemle
Millions of Devices Vulnerable to 'PKFail' Secure Boot Bypass Issue
Several vendors for consumer and enterprise PCs share a compromised crypto key that should never have been on the devices in the first place.

2024. Júl. 26.
Biztonsági szemle
CrowdStrike Outage Losses Estimated at a Staggering $5.4B
Researchers track the healthcare sector as experiencing the biggest financial losses, with banking and transportation following close behind.
Oldalszámozás
- Előző oldal ‹‹
- 625. oldal
- Következő oldal ››