0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

โž ๐Ÿ”“ Support Portal Exposed Customer Device Info
โž ๐Ÿ”“ ๐Ÿ‡น๐Ÿ‡ญ Major in Exposes Personal Data of 20 Million Elderly Citizens
โž ๐Ÿ”“ ๐Ÿ‡ซ๐Ÿ‡ท Millions at risk of fraud after massive health data hack in
โž ๐Ÿ”“ ๐Ÿ‡บ๐Ÿ‡ธ employee inadvertently leaks data of 63 thousand colleagues
โž ๐Ÿ”“ ๐Ÿ–ฅ๏ธ Hacked: Revokes Passwords, Certificates in Response
โž ๐Ÿ”“ ๐Ÿ‡บ๐Ÿ‡ธ says caused $49 million in expenses
โž ๐Ÿ’ธ ๐Ÿ“ˆ Payments Exceed $1 Billion in 2023, Hitting Record High After 2022 Decline
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ’ฐ US offers $10 million for tips on ransomware leadership
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡บ๐Ÿ‡ธ -backed Volt Typhoon hackers have lurked inside US for โ€˜at least five yearsโ€™
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡ณ๐Ÿ‡ฑ Chinese Hackers Exploited Flaw to Breach Dutch Network
โž ๐Ÿ‡ฎ๐Ÿ‡ท ๐Ÿ‡ฎ๐Ÿ‡ฑ accelerates cyber ops against from chaotic start
โž ๐Ÿ‡ง๐Ÿ‡พ ๐Ÿ‡บ๐Ÿ‡ธ Belarusian National Linked to BTC-e Faces 25 Years for $4 Billion Money Laundering
โž ๐Ÿ‡ญ๐Ÿ‡ฐ ๐Ÿ’ธ worker pays out $25 million after video call with โ€˜chief financial officerโ€™
โž ๐Ÿ‡บ๐Ÿ‡ฆ is Creating a โ€˜Cyber Diplomatโ€™ Post
โž ๐Ÿ‡ฉ๐Ÿ‡ฐ orders schools to stop sending student data to
โž ๐Ÿ‡ช๐Ÿ‡บ โš–๏ธ proposes criminalizing AI-generated child sexual abuse and deepfakes
โž ๐Ÿ‡ณ๐Ÿ‡ฑ ๐Ÿ’ฐ Fined 10 Million Euros by Dutch Data Regulator
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ›‚ US to Roll Out Visa Restrictions on People Who Misuse to Target Journalists, Activists
โž ๐Ÿฆ  ๐Ÿ’ฌ Raspberry Robin Upgrades with Spread and New Exploits
โž ๐Ÿฆ  ๐ŸŽ New Backdoor Linked to Prominent Ransomware Groups
๐Ÿฆ  ๐Ÿชฅ Surprising 3 Million Hacked Story Goes Viralโ€”Is It True?
โž ๐Ÿ‡จ๐Ÿ‡ฆ ๐Ÿฌ declares public enemy No. 1 in car-theft crackdown
โž ๐Ÿฉน : Patch new Connect Secure auth bypass bug immediately
โž ๐Ÿ› ๐Ÿ“ Security flaw in a popular smart helmet allowed silent location tracking
โž ๐Ÿฉน Critical Patches Released for New Flaws in , , Products
โž ๐Ÿ› ๐Ÿง Critical Boot Loader in Shim Impacts Nearly All Distros
โž ๐Ÿ› โœˆ๏ธ App Vulnerability Introduced Aircraft Safety Risk
โž ๐Ÿฉน Patches High-Severity Bugs in QTS, Qsync Central

--

๐Ÿ“š This week's recommended reading is: "x86 Software Reverse-Engineering, Cracking, and Counter-Measure" by Stephanie Domas & Christopher Domas

--

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-062024

0x58, to Cybersecurity
0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated #cybersecurity and #infosec list of resources for week #05/2024 is out!

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://open.substack.com/pub/0x58/p/infosec-mashup-week-052024?r=299go8&utm_campaign=post&utm_medium=web&showWelcomeOnShare=true

0x58, to infosec

๐Ÿ“จ In case you missed the latest issue of my #InfosecMASHUP newsletter, it's available here for you to read! ๐Ÿ‘‡

#infosec #cybersecurity #tech

https://open.substack.com/pub/0x58/p/infosec-mashup-week-032024?r=299go8&utm_campaign=post&utm_medium=web&showWelcome=true

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

โž ๐Ÿ”“ ๐ŸŽฝ Halara probes breach after hacker leaks data for 950,000 people
โž ๐Ÿ”“ ๐Ÿ’ฅ 's X Account Was Hacked Using Brute-Force Attack
โž ๐Ÿ”“ ๐Ÿ‡ต๐Ÿ‡พ warns of Black Hunt attacks after Tigo Business
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ’ธ US SECโ€™s X account hacked to announce fake ETF approval
โž ๐Ÿ”“ ๐Ÿ‡จ๐Ÿ‡ฆ Toronto Zoo: Ransomware attack had no impact on animal
โž ๐Ÿ”“ Mortgage firm loanDepot impacts IT systems, payment portal
โž ๐Ÿ‡ซ๐Ÿ‡ฎ ๐Ÿ’ธ warns of Akira ransomware wiping NAS and tape devices
โž ๐Ÿ‡ฉ๐Ÿ‡ฐ ๐Ÿ‡ท๐Ÿ‡บ probably wasnโ€™t behind Danish critical infrastructure cyberattack, report says
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ‡ท๐Ÿ‡บ Pro-Ukraine hackers breach Russian ISP in revenge for attack
โž ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡บ๐Ÿ‡ธ French Computer Hacker Jailed in US
โž ๐Ÿ‡ณ๐Ÿ‡ฌ โš–๏ธ Nigerian gets 10 years for laundering millions stolen from elderly
โž ๐Ÿ‡น๐Ÿ‡ท Turkish Hackers Exploiting Poorly Secured Servers Across the Globe
โž ๐Ÿ‡น๐Ÿ‡ท ๐Ÿ‡ณ๐Ÿ‡ฑ Turkish Targeting Netherlands
โž โ˜๏ธ ๐Ÿ‡ช๐Ÿ‡บ Lets Cloud Users Keep Personal Data Within to Ease Fears
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡จ๐Ÿ‡ณ is helping US spies catch stealthy Chinese hacking ops, official says
โž ๐Ÿ‡ฑ๐Ÿ‡ง โœˆ๏ธ Beirut Airport Screens Hacked with Anti-Hezbollah Message
โž ๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Ministry exposed sensitive data for 15 months
โž ๐Ÿ‡ฌ๐Ÿ‡ท to Establish New Authority to Counter Cyber-Attacks
โž ๐Ÿฉน , Release First Patch Tuesday Advisories of 2024
โž ๐Ÿ โ˜๏ธ New -based FBot Hacking Toolkit Aims at and Platforms
โž ๐Ÿฆ  ๐Ÿ“บ Videos Promoting Cracked Software Distribute Lumma Stealer
โž ๐Ÿฆ  ๐Ÿง devices are under attack by a never-before-seen worm
โž ๐Ÿฆ  ๐Ÿ‡ณ๐Ÿ‡ฑ Dutch Engineer Used Water Pump to Get Billion-Dollar Into Iranian Nuclear Facility
โž ๐Ÿก ๐Ÿ” DSA removal from
โž ๐Ÿฉน
โž ๐Ÿ› ๐Ÿ”“ Actively exploited 0-days in VPN are letting hackers networks
โž ๐Ÿ”“ ๐Ÿ”ง Hackers can infect network-connected wrenches to install ransomware
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ”“ cracked by , revealing phone number and email address of sender
โž ๐Ÿฉน Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products
โž ๐Ÿ› ๐Ÿ”“ KyberSlash attacks put projects at risk

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-022024

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ–ผ๏ธ MAJOR US SUFFER FALLOUT
โž ๐Ÿ‡ช๐Ÿ‡ธ ๐Ÿ“ก A โ€œridiculously weakโ€œ password causes disaster for โ€™s No. 2 mobile carrier
โž ๐Ÿ”“ ๐Ÿงฌ tells victims itโ€™s their fault that their data was breached
โž ๐Ÿ”“ ๐Ÿ’ธ loses $86 million in the last hack of 2023
โž ๐Ÿ”“ ๐Ÿ…ฟ๏ธ Europeโ€™s Largest Parking App Provider Informs Customers of Data Breach
โž ๐Ÿ’ธ ๐Ÿ™Š wallet founder loses $125,000 to fake airdrop website
โž ๐Ÿ‡บ๐Ÿ‡ธ โš–๏ธ US Says 19 People Charged Following 2019 Takedown of Cybercrime Marketplace
โž ๐Ÿ‡ต๐Ÿ‡ธ ๐Ÿ‡ฎ๐Ÿ‡ฑ Palestinian Hackers Hit 100 Israeli Organizations in Destructive Attacks
โž ๐Ÿ”“ โŒ Hacked X Account Abused for Theft
โž ๐Ÿ‡ณ๐Ÿ‡ฌ ๐Ÿ‡บ๐Ÿ‡ธ โš–๏ธ Nigerian hacker arrested for stealing $7.5M from charities
โž ๐Ÿ‡ฆ๐Ÿ‡ฑ ๐Ÿ“ก Albanian Parliament and One Albania Telecom Hit by Cyber Attacks
โž ๐Ÿ‡บ๐Ÿ‡ธ The FBI is adding more cyber-focused agents to U.S. embassies
โž ๐Ÿ‡บ๐Ÿ‡ธ โš–๏ธ Former admin to be jailed until Jan. 19 sentencing
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ’ฐ DOJ Slams with $10 Million Fine Over Massive Illegal Robocall Operation
โž ๐Ÿ“ท ๐Ÿฅธ Contractor Pays Parents $50 to Scan Their Childrens' Faces
โž ๐Ÿ’ฐ ๐Ÿฅธ Google Settles $5 Billion Lawsuit Over Tracking Users in 'Incognito Mode'
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ—ณ๏ธ to reveal Chinese election interference after Saturdayโ€™s vote
โž ๐Ÿฆ  ๐Ÿ’ฐ Settles Insurance Claim, Leaving Definition Unresolved
โž ๐Ÿฆ  ๐Ÿ‡ฐ๐Ÿ‡ต SpectralBlur: New Backdoor Threat from North Korean Hackers
โž ๐Ÿฆ  ๐Ÿ 3 Malicious Packages Found Targeting with Crypto Miners
โž ๐Ÿฆ  ๐ŸŽ  New Bandook Variant Resurfaces, Targeting Machines
โž ๐Ÿฆ  ๐ŸŽ  UAC-0050 Group Using New Tactics to Distribute Remcos RAT
โž ๐Ÿฆ  ๐Ÿ‡บ๐Ÿ‡ฆ CERT-UA Uncovers New Wave Distributing OCEANMAP, MASEPIE, STEELHOOK
โž ๐Ÿ”“ ๐Ÿฆ  Free Decryptor Released for Ransomware
โž ๐Ÿ› ๐Ÿ“จ Smuggling: New Flaw Lets Attackers Bypass Security and Spoof
โž ๐Ÿฉน warns critical EPM lets hackers hijack enrolled devices
โž ๐Ÿฉน Google Patches Six Vulnerabilities With First Update of 2024
โž ๐Ÿฉน ๐Ÿก Millions still havenโ€™t patched SSH protocol

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-012024

0x58, to infosec
0x58, to infosec

๐Ÿ“จ First issue of 2024 of my weekly #InfosecMASHUP newsletter is going out tomorrow! You still have time to subscribe ๐Ÿ™Œ

#infosec #cybersecurity #news

https://infosec-mashup.santolaria.net

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ”“ ๐Ÿ‡บ๐Ÿ‡ธ U.S. nuclear research lab impacts 45,000 people
โž ๐Ÿ‡ฉ๐Ÿ‡ช Germany Says Customer Data Stolen in Attack
โž ๐Ÿ”“ ๐Ÿง ATM company Coin Cloud got hacked. Even its new owners donโ€™t know how
โž ๐Ÿ”“ ๐Ÿ‡บ๐Ÿ‡ธ Norton discloses data breach after May ransomware attack
โž ๐Ÿ‡ท๐Ÿ‡บ Russian SVR-Linked Targets TeamCity Servers in Ongoing Attacks
โž ๐Ÿ‘ฅ ransomware now poaching , NoEscape affiliates
โž ๐Ÿ‡ป๐Ÿ‡ณ ๐Ÿ’ป seizes domains used to sell fraudulent accounts
โž ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ’ธ French police arrests Russian suspect linked to ransomware
โž ๐Ÿ‡จ๐Ÿ‡ณ Chinese APT Volt Typhoon Linked to Unkillable SOHO Router
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ‡ท๐Ÿ‡บ Ukrainian military says it hacked 's federal tax agency
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿšช Researchers Unmask Sandman APT's Hidden Link to China-Based Backdoor
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ“ก โ€™s largest mobile communications provider down after apparent
โž ๐Ÿ‡ช๐Ÿ‡ธ Kelvin Security hacking group leader arrested in
โž ๐Ÿ”ป ๐Ÿ‘ฎ๐Ÿปโ€โ™‚๏ธ ransomware site outage rumored to be caused by law enforcement
โž ๐Ÿ“น ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ devices broadcasted private video to other usersโ€™ accounts
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ‡ช๐Ÿ‡บ Russian Diplomat Expelled Amid EU Spy Purge Is Now An OSCE Election Observer In Serbia
โž ๐Ÿ‡บ๐Ÿ‡ธ Harry Coker confirmed to be the next National Cyber Director
โž ๐Ÿ‡ช๐Ÿ‡ธ ๐Ÿ‡บ๐Ÿ‡ธ Spain expels two US spies for infiltrating secret service
โž ๐Ÿ“ Unveils EMB3D Threat Model for Embedded Devices Used in Critical Infrastructure
โž ๐Ÿฉน Patch Tuesday: Electromagnetic Fault Injection, Critical Redis Vulnerability
โž ๐Ÿฆ  ๐Ÿ‡ต๐Ÿ‡ธ New Pierogi++ by Cyber Gang Targeting Palestinian Entities
โž ๐Ÿฆ  ๐Ÿ‡ฎ๐Ÿ‡ท Iranian State-Sponsored Group Deploys 3 New Malware Downloaders
โž ๐Ÿฆ  ๐Ÿ‡ฉ๐Ÿ‡ช New MrAnon Stealer Malware Targeting German Users via Booking-Themed
โž ๐Ÿช 's New Tracking Protection in Chrome Blocks Third-Party
โž ๐Ÿ› ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป Unveils Open Source Vulnerability Impact Scoring System
โž ๐Ÿฉน ๐Ÿงฑ backports RCE fix after attacks on unsupported
โž ๐Ÿ”“ ๐Ÿงฑ Over 1,450 servers exposed to RCE attacks via bug chain
โž ๐Ÿฉน ๐Ÿ Ships iOS 17.2 With Urgent Security
โž ๐Ÿ› Over 30% of apps use a vulnerable version of the library

๐Ÿ“š This week's recommended reading is: "Black Hat Python, 2nd Edition: Python Programming for Hackers and Pentesters (2nd Edition)" by Justin Seitz and Tim Arnold

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-502023

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ”“ ๐Ÿ‡ฌ๐Ÿ‡ง University of Manchester Speaks Out on Summer Cyber-Attack
โž ๐Ÿ”“ ๐Ÿ‡บ๐Ÿ‡ธ Hacktivists breach U.S. nuclear research lab, steal employee data
โž ๐Ÿ”“ ๐Ÿ‘€ Sumo Logic Completes Investigation Into Recent Security
โž ๐Ÿ”“ ๐Ÿ‡บ๐Ÿ‡ธ Auto parts giant AutoZone warns of data breach
โž ๐Ÿ”“ ๐Ÿ‡จ๐Ÿ‡ฆ Canadian government discloses data breach after contractor hacks
โž ๐Ÿ‡ฆ๐Ÿ‡ซ New 'HrServ.dll' Web Shell Detected in Attack Targeting Afghan Government
โž ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ‡ฐ๐Ÿ‡ท UK and South Korea: Hackers use zero-day in supply-chain attack
โž ๐Ÿ‡ต๐Ÿ‡ธ ๐Ÿ‡ฎ๐Ÿ‡ฑ -Linked Using Rust-Powered SysJoker Against
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ˜ฑ โ€œThey are tired of him, but they are afraidโ€: what is known about the leader of the hacker group Killnet
โž ๐Ÿ‡ฐ๐Ÿ‡ต N. Korean Hackers Distribute Trojanized Software in Supply Chain Attack
โž โ–ถ๏ธ ๐Ÿ›’ Play Goes Commercial - Now Offered as a Service to Cybercriminals
โž ๐Ÿ‡ฎ๐Ÿ‡ณ Indian Hack-for-Hire Group Targeted U.S., , and More for Over 10 Years
โž ๐Ÿ‡ท๐Ÿ‡บ Russian hackers use feature and exploit to attack embassies
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿฉบ Releases Cybersecurity Guidance for , Public Health Organizations
โž ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ™๐Ÿป Thanking the vulnerability research community with Challenge Coins
โž ๐Ÿง… Network Removes Risky Relays Associated With Scheme
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ‘‹๐Ÿป fires top cybersecurity officials
โž ๐Ÿฉน Johnson Controls Patches Critical in Industrial Refrigeration Products
โž ๐Ÿฆ  ๐Ÿฆ€ New WailingCrab Loader Spreading via Shipping-Themed Emails
โž ๐Ÿฆ  ๐Ÿ“จ New Agent Tesla Malware Variant Using ZPAQ Compression in Email Attacks
โž ๐Ÿฆ  ๐ŸŽ  NetSupport Infections on the Rise - Targeting Government and Business Sectors
โž ๐Ÿšซ Google will limit ad blockers starting June 2024
โž ๐Ÿ› โ˜๏ธ 3 Critical Vulnerabilities Expose Users to Data Breaches
โž ๐Ÿ”“ โ˜๏ธ Researchers Discover Dangerous Exposure of Sensitive Secrets
โž ๐Ÿ”“ โ˜๐Ÿป New Flaws in Fingerprint Sensors Let Attackers Bypass Hello Login
โž ๐Ÿ”“ ๐Ÿฉธ โ€˜โ€™ vulnerability targeted by nation-state and criminal hackers: CISA
โž ๐Ÿก Researchers extract RSA keys from server signing errors

๐Ÿ“š This week's recommended reading is: "How I Rob Banks: And Other Such Places" by FC a.k.a. Freakyclown

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-472023

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ”“ ๐Ÿ‡ฏ๐Ÿ‡ต confirms breach after Medusa threatens to leak data
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ˜‚ Ransomware gang files complaint over victimโ€™s undisclosed
โž ๐Ÿ”“ ๐Ÿชถ Attackers claim Plume Design, Inc data breach
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ’ฐ paid ransom after hack that disrupted markets, say
โž ๐Ÿ”“ Says No Evidence of Breach After Ransomware Gang Claims Hack via Third Party
โž ๐Ÿ”“ โœˆ๏ธ Hackers swipe Booking.com, damage from attack is global
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ‡บ๐Ÿ‡ฆ Russian Group Deploys USB in Targeted Attacks
โž ๐Ÿ‡ฎ๐Ÿ‡ฑ ๐Ÿ‡บ๐Ÿ‡ธ Israeli Man Who Made $5M From Hacking Scheme Sentenced to Prison in US
โž ๐Ÿ‡ซ๐Ÿ‡ฎ โš–๏ธ Alleged Extortioner of Psychotherapy Patients Faces Trial
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ’ธ ransomware exploits in attacks, 10K servers exposed
โž ๐Ÿ‡บ๐Ÿ‡ธ โš–๏ธ botnet with 23,000 proxies for malicious traffic dismantled
โž ๐Ÿ‘ถ๐Ÿป ๐Ÿงจ Teens with โ€œdigital bazookasโ€ are winning the ransomware war, researcher laments
โž ๐Ÿ’ธ feature abused to steal $60 million from 99K victims
โž ๐Ÿ‡ฉ๐Ÿ‡ฐ ๐Ÿ‡ท๐Ÿ‡บ Hit With Largest on Record
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡ฐ๐Ÿ‡ญ Chinese Hackers Launch Covert Attacks on 24 Cambodian Organizations
โž ๐Ÿ‡ฒ๐Ÿ‡พ Major Phishing-as-a-Service Syndicate '' Dismantled by Malaysian Authorities
โž ๐Ÿ‡ช๐Ÿ‡บ ๐Ÿฅณ EU Parliament committee rejects mass scanning of private and encrypted communications
โž ๐Ÿฉน Patch Tuesday: 90 Vulnerabilities Addressed by Siemens and Schneider Electric
โž ๐Ÿฆ  ๐Ÿ 27 Malicious Packages with Thousands of Downloads Found Targeting IT Experts
๐Ÿ‡ป๐Ÿ‡ณ ๐Ÿ‡ฎ๐Ÿ‡ณ Vietnamese Hackers Using New -Powered to Target Indian Marketers
โž ๐Ÿ” Adds Support to New Titan Security Key
โž ๐Ÿ› Zero-Day Flaw in Email Software Exploited by Four Hacker Groups
โž ๐Ÿฉน Patches Critical Vulnerability in Business One Product
โž ๐Ÿ› New CPU flaw impacts Intel desktop and server systems
โž ๐Ÿ› New AMD attack lets hackers gain root in Linux VMs

๐Ÿ“š This week's recommended reading is: "Tribe of Hackers: Cybersecurity Advice from the Best Hackers in the World" by @marcusjcarey and Jennifer Jin

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-462023

0x58, to blackfriday

๐Ÿท๏ธ Get 50% off annual plans for my #infosecMASHUP newsletter for #blackfriday :lolsob:โ€‹ - Promotion end on the 27th! Use link below to redeem.

Thank you for all your support thus far! Enjoy the holidays! ๐Ÿฆƒ

#infosec #cybersecurity

https://infosec-mashup.santolaria.net/bf2023

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ”“ โœˆ๏ธ breach: LockBit leaks 50 GB of data
โž ๐Ÿ‡จ๐Ÿ‡ณ Worldโ€™s largest commercial bank confirms attack
โž ๐Ÿ”“ โ˜๏ธ Sumo Logic alerts customers about ; advises rotate Sumo Logic API access keys
โž ๐Ÿ”“ ๐Ÿ‡ฎ๐Ÿ‡ช Electric Ireland admits data breach that could see customer financial data compromised
โž ๐Ÿ”“ ๐Ÿ‡จ๐Ÿ‡ฆ says ransomware data breach affects 267,000 patients
โž ๐Ÿ”“ ๐Ÿ‡ธ๐Ÿ‡ฌ Marina Bay Sands reward members data breached, over 650k people exposed
โž ๐Ÿ‡ฎ๐Ÿ‡ฑ ๐Ÿ‡ต๐Ÿ‡ธ ๐Ÿ‡ฎ๐Ÿ‡ท Cyber ops linked to - conflict largely improvised, researchers say
โž ๐Ÿงจ ๐Ÿค– confirms attacks behind ongoing outages
โž ๐Ÿ›๏ธ ๐Ÿ’ธ Fake Ledger Live app in Store steals $768,000 in
โž ๐Ÿ”“ ๐Ÿฐ โ€˜Looney Tunablesโ€™ Vulnerability Exploited in Attacks
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ท๐Ÿ‡บ US Sanctions Russian National for Helping Ransomware Groups Launder Money
โž ๐Ÿ‡ฎ๐Ÿ‡ท ๐Ÿ‡ฎ๐Ÿ‡ฑ Iranian Hackers Launch Destructive Cyber Attacks on Israeli and Sectors
โž ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡ฌ๐Ÿ‡ง , Seek Greater Regulation of Commercial
โž ๐Ÿ‡ช๐Ÿ‡บ ๐Ÿค is trading security for digital
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ‡บ๐Ÿ‡ฆ Russian Hackers Used Attack to Disrupt Power in Amid Mass Missile Strikes
โž ๐Ÿฆ  ๐Ÿšช Highly invasive snuck into packages targets developers
โž ๐Ÿฆ  ๐Ÿ‡ฐ๐Ÿ‡ต N. Korea's Blamed for Hacking Machines with ObjCShellz
โž ๐Ÿซฃ tests usernames that keep your phone number private
โž ๐Ÿ” Microsoft Authenticator now blocks suspicious alerts by default
โž โ˜๏ธ ๐Ÿ’ฐ Researchers Uncover Undetectable Technique on Automation
โž ๐Ÿ‘ฅ ๐Ÿ’ฐ Data Brokers Expose Sensitive US Military Member Info to Foreign Threat Actors: Study
โž ๐Ÿฉน Microsoft Says Exchange โ€˜Zero Daysโ€™ Disclosed by Already Patched or Not Urgent
โž ๐Ÿ› Veeam warns of critical bugs in ONE monitoring platform

๐Ÿ“š This week's recommended reading is: "How the F*ck Did This Happen?: A guide for executives who need to understand Cyber Security in plain, actionable language" by Dr Darryl Carlton

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-452023

0x58, to infosec

๐ŸŽ If you're (still) looking for ideas for the holidays season, and the recipient of your lovely attention is into #infosec and #cybersecurity, here's the compiled list of #books that I've recommended YTD in my weekly #InfosecMASHUP newsletter ๐Ÿ‘‡

https://open.substack.com/pub/0x58/p/infosec-books-for-end-of-year-gifts

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ”“ hit by another , this one stealing employee data from 3rd-party vendor
โž ๐Ÿ”“ ๐Ÿ’ธ breach linked to theft of $4.4 million in crypto
โž ๐Ÿ‡ฎ๐Ÿ‡ณ 's Biggest Data Leak So Far? Covid-19 Test Info of 81.5Cr Citizens With ICMR Up for Sale
โž ๐Ÿ”“ โœˆ๏ธ ransomware group claims to have hacked
โž ๐Ÿ‡ณ๐Ÿ‡ฑ โš–๏ธ Dutch hacker jailed for extortion, selling stolen data on RaidForums
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ‡บ๐Ÿ‡ธ Russian Reshipping Service โ€˜SWAT USA Dropโ€™ Exposed
โž ๐Ÿ‡ฎ๐Ÿ‡ท ๐Ÿฆ  Iranian Cyber Spies Use โ€˜โ€™ Malware in Latest Attacks
โž ๐Ÿ“‰ Security researchers observed โ€˜deliberateโ€™ takedown of notorious
โž ๐Ÿ‡ฎ๐Ÿ‡ณ ๐Ÿ“ฑ Apple warns Indian opposition leaders of state-sponsored attacks
โž ๐ŸŒ Four dozen countries declare they wonโ€™t pay ransoms
โž ๐Ÿ‡ท๐Ÿ‡บ How , an Automated Social Media Accounts Creation Service, Can Facilitate
โž ๐Ÿ‡ช๐Ÿ‡บ EU digital ID reforms should be โ€˜actively resistedโ€™, say experts
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ‡บ๐Ÿ‡ฆ arrests Russian hackers working for Ukrainian cyber forces
โž ๐Ÿ‡บ๐Ÿ‡ธ FTC orders non-bank financial firms to report breaches in 30 days
โž ๐Ÿ‡จ๐Ÿ‡ฆ ๐Ÿ“ฑ Bans and Apps On Government Devices
โž ๐Ÿ‡บ๐Ÿ‡ธ Charges and Its With Fraud and Cybersecurity Failures
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿค– Wants to Move Fast on AI Safeguards and Will Sign an Executive Order to Address His Concerns
โž ๐Ÿฆ  ๐Ÿ“ฑ confirms it tagged Google app as on Android phones
โž ๐Ÿฆ  ๐Ÿ‡ฐ๐Ÿ‡ต North Korean Hackers Targeting Crypto Experts with Malware
โž ๐Ÿ‘ฅ ๐Ÿ’ธ EleKtra-Leak Attacks Exploit IAM Credentials Exposed on
โž ๐Ÿฆ  ๐Ÿ Trojanized Software Version Delivered via Search Ads
โž โœ… ๐Ÿค– adds security audit badges for Android apps
โž ๐Ÿ” Microsoft pledges to bolster security as part of โ€˜Secure Futureโ€™ initiative
โž ๐Ÿ†• FIRST Releases 4.0 Vuln Scoring Standard
โž ๐Ÿ†• Releases ATT&CK v14 With Improvements to Detections, ICS, Mobile
โž โ›”๏ธ ๐Ÿฆ  Galaxy gets new Auto Blocker anti-malware feature
โž ๐Ÿ ๐Ÿ” Improves Security With Contact Key Verification
โž ๐Ÿ”“ Researchers Find 34 Drivers Vulnerable to Full Device Takeover
โž ๐Ÿ”“ ๐Ÿชถ 3,000 servers vulnerable to RCE attacks exposed online
โž ๐Ÿ—ฃ๏ธ CISO Urges Quick Action to Protect Instances From Critical
โž ๐Ÿ”“ ๐Ÿฉธ โ€œThis vulnerability is now under mass exploitation.โ€ bug bites hard
โž ๐Ÿ› ๐Ÿ’ฐ HackerOne paid ethical hackers over $300 million in

๐Ÿ“š This week's recommended reading is: "Permanent Record" by Edward Snowden

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-442023

0x58, to infosec

๐Ÿ“ˆ +61 new subscribers to my #InfosecMASHUP newlesetter in October ๐Ÿ“† - Grateful for all your support! ๐Ÿ™

#infosec #cybersecurity

https://infosec-mashup.santolaria.net

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ‡บ๐Ÿ‡ธ ๐ŸŽฐ Hackers that breached Las Vegas casinos rely on violent threats, research shows
โž ๐Ÿ”“ ๐Ÿ‡บ๐Ÿ‡ธ University of Michigan employee, student data stolen in
โž ๐Ÿ”“ discloses security incident linked to breach
โž ๐Ÿ‡บ๐Ÿ‡ธ Cyber attacks hit NY state operation, two Hudson Valley hospitals
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ—ณ๏ธ D.C. Board of Elections: Hackers may have breached entire voter roll
โž ๐Ÿ”“ ๐Ÿ‡ฎ๐Ÿ‡ช Thousands of drivers have sensitive data exposed to hackers in major IT
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ“จ Pro-Russia hackers target inboxes with in webmail app used by millions
โž ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡ท๐Ÿ‡บ says Russian state hackers breached numerous critical networks
โž ๐Ÿ‡ณ๐Ÿ‡ฌ Nigerian Police dismantle recruitment, mentoring hub
โž ๐Ÿ‡ต๐Ÿ‡ธ ๐Ÿ’ธ donation scams emerge amid Israel-Hamas war
โž ๐Ÿ‡ช๐Ÿ‡ธ ๐Ÿ‘ฎ๐Ÿปโ€โ™‚๏ธ arrests 34 who stole data of 4 million people
โž ๐Ÿ‡จ๐Ÿ‡ฆ ๐Ÿ‡จ๐Ÿ‡ณ : Lawmakers Targeted by China-Linked โ€˜โ€™ Disinformation
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ท๐Ÿ‡บ Ex-NSA Employee Pleads Guilty to Leaking Classified Data to
โž ๐Ÿฆ  ๐Ÿ‡ฐ๐Ÿ‡ต N. Korean Group Targets Software Vendor Using Known Flaws
โž ๐Ÿฆ  ๐Ÿ‡ฎ๐Ÿ‡ท Iranian Group Launches New Wave of IMAPLoader Attacks
โž ๐Ÿฆ  ๐Ÿชฐ malware framework infects 1 million , hosts
โž ๐Ÿฆ  ๐Ÿ“ฑ Zero-Day Attacks: Experts Uncover Deeper Insights into Operation Triangulation
โž ๐Ÿ”“ ๐Ÿ“ฑ Galaxy S23 hacked two more times at Toronto
โž ๐Ÿ”“ Critical Flaws Uncovered in , , and Platforms
โž ๐Ÿ”“ ๐Ÿฉบ Critical Flaw in NextGen's Mirth Connect Could Expose Data
โž ๐Ÿ”“ Warns of Critical Remote Code Execution Vulnerability in BIG-IP
โž ๐Ÿ”“ ๐Ÿ Hackers can force iOS and browsers to divulge and much more
โž ๐Ÿฉน warns admins to patch CVE-2023-4966 bug immediately
โž ๐Ÿ”“ โœŒ๐Ÿป Finds Second Zero-Day as Number of Hacked Devices Apparently Drops
โž ๐Ÿ”“ Critical RCE flaws found in access audit solution

๐Ÿ“š This week's recommended reading is: "Click Here to Kill Everybody: Security and Survival in a Hyper-connected World" by Bruce Schneier

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-432023

cedricpernet, to random

Wanna read more on how a Russian service helps cybercriminals register thousands of social media accounts in seconds ? Read my latest research here: https://www.trendmicro.com/fr_fr/research/23/j/how-kopeechka--an-automated-social-media-accounts-creation-servi.html

0x58,

@cedricpernet Great research Cedric. Added it to next week issue of my #InfosecMASHUP newsletter :kirby_happy:โ€‹

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated #cybersecurity and #infosec list of resources for week #42/2023 is out! It includes the following and much more:

โž ๐Ÿ”“ ๐Ÿ‘€ Tracking Unauthorized Access to #Okta's Support System
โž ๐Ÿ”“ ๐Ÿ‡ฏ๐Ÿ‡ต #Casio discloses #databreach impacting customers in 149 countries
โž ๐Ÿ”“ ๐Ÿงฌ Hacker leaks millions more #23andMe user records on #cybercrime forum
โž ๐Ÿ”“ ๐Ÿ‡จ๐Ÿ‡ณ D-Link confirms data breach after employee #phishing attack
โž ๐Ÿ”“ ๐Ÿ’ฐ #Equifax Fined $13.5 Million Over 2017 Data Breach
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿงน Ukrainian activists hack Trigona #ransomware gang, wipe servers
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ฐ๐Ÿ‡ต FBI: Thousands of Remote IT Workers Sent Wages to #NorthKorea to Help Fund Weapons Program
โž ๐Ÿ‡ฎ๐Ÿ‡ณ โ˜๏ธ #India targets #Microsoft, #Amazon tech support #scammers in nationwide crackdown
โž ๐Ÿ‡ต๐Ÿ‡ธ ๐Ÿ‡ฎ๐Ÿ‡ท #Hamas-linked app offers window into cyber infrastructure, possible links to Iran
โž ๐Ÿ‘ฎ๐Ÿปโ€โ™‚๏ธ ๐Ÿฅท๐Ÿป Police seize #RagnarLocker leak site
โž ๐Ÿ‡ฐ๐Ÿ‡ต North Korean Hackers Exploiting Recent #TeamCity Vulnerability
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡ท๐Ÿ‡บ #China replaces #Russia as top #cyberthreat
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ“ก CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks
โž ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡ช๐Ÿ‡ธ #France frees the two biggest Spanish hackers
โž ๐Ÿ‡บ๐Ÿ‡ธ โš“๏ธ Ex-Navy IT head gets 5 years for selling peopleโ€™s data on #darkweb
โž ๐Ÿ‡จ๐Ÿ‡ญ ๐Ÿ—ณ๏ธ #Switzerlandโ€™s e-voting system has predictable implementation blunder
โž ๐Ÿ”“ ๐Ÿญ Critical Vulnerabilities Expose โ€‹โ€‹#Weintek HMIs to Attacks
โž ๐Ÿ”“ ๐Ÿญ #Milesight Industrial Router #Vulnerability Possibly Exploited in Attacks
โž ๐Ÿฆ  ๐Ÿ‡ป๐Ÿ‡ณ Fake #Corsair job offers on #LinkedIn push #DarkGate malware
โž ๐Ÿฆ  Google-hosted #malvertising leads to fake #Keepass site that looks genuine
โž ๐Ÿฆ  ๐Ÿ’ฌ #Discord still a hotbed of #malware activity โ€” Now APTs join the fun
โž ๐Ÿฆ  ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ SpyNote: Beware of This Android #Trojan that Records Audio and Phone Calls
โž ๐Ÿ›๏ธ ๐Ÿฆ  #Android will now scan sideloaded apps for malware at install time
โž ๐Ÿ’ฌ ๐Ÿ” #WhatsApp #passkeys on the way, but as usual, for Android first
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ—‚๏ธ Pro-Russian Hackers Exploiting Recent #WinRAR Vulnerability in New Campaign
โž ๐Ÿ—“๏ธ โŒ Signal Pours Cold Water on Zero-Day Exploit Rumors
โž ๐Ÿ”“ ๐Ÿ’ฅ #Cisco warns of new #IOS XE #zeroday actively exploited in attacks

๐Ÿ“š This week's recommended reading is: "RTFM: Red Team Field Manual v2" by Ben Clark and Nicholas Downer

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-422023

0x58, to Cybersecurity

๐Ÿ“š InfoSec Books for End-of-Year Gifts List ๐Ÿฆƒ ๐ŸŽ…๐Ÿป

Recap of the recommended readings I've shared throughout 2023 in my weekly #InfoSecMASHUP newsletter. Remember, sharing is caring; Enjoy the holidays!

#cybersecurity #infosec #bookstodon #books

https://infosec-mashup.santolaria.net/p/infosec-books-for-end-of-year-gifts

0x58, to infosec

September stats for my #InfosecMASHUP newsletter:

๐Ÿ“Š 1062 subscribers
๐Ÿ“ˆ +47 new free subscribers

Thank you all!

#infosec #cybersecurity

https://infosec-mashup.santolaria.net

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ”“ repos bombarded by info-stealing commits masked as
โž ๐Ÿ‡ฏ๐Ÿ‡ต ๐Ÿ’ธ Investigating After Hackers Offer to Sell Stolen Data
โž ๐Ÿ”“ Ontario child registry affects 3.4 million people
โž ๐Ÿ‡ญ๐Ÿ‡ฐ ๐Ÿ”“ Personal data of 25,000 Hongkongers at risk after against consumer watchdog, up from earlier estimate of 8,000
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ”“ National Student Clearinghouse data breach impacts 890
โž ๐Ÿ‡จ๐Ÿ‡ฆ โœˆ๏ธ discloses data breach of employee and 'certain records'
โž ๐Ÿ‡ฐ๐Ÿ‡ต ๐Ÿ‡ช๐Ÿ‡ธ North Korean hackers posed as recruiter on
โž ๐Ÿ‘ฅ ShadowSyndicate: A New Group Linked to 7 Families
โž ๐Ÿ‡ท๐Ÿ‡บ โœˆ๏ธ Russian flight booking system suffers โ€˜massiveโ€™ cyberattack
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡บ๐Ÿ‡ธ Chinese hackers stole emails from US State Dept in breach, Senate staffer says
โž ๐Ÿ‡จ๐Ÿ‡ณ Chinese Hackers TAG-74 Targets South Korean Organizations in a Multi-Year Campaign
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿš€ Ukrainian Military Targeted in Phishing Campaign Leveraging Manuals
โž ๐Ÿฅท๐Ÿป ๐Ÿ’ฐ Hackers steal $200M from company
โž ๐Ÿ‡ณ๐Ÿ‡ฌ โš–๏ธ Nigerian man pleads guilty to attempted $6 million BEC email heist
โž ๐Ÿ‡บ๐Ÿ‡ธ โš–๏ธ ShinyHunters member pleads guilty to $6 million in data theft damages
โž ๐Ÿ‡จ๐Ÿ‡ณ -Linked Budworm Targeting Middle Eastern and Asian Government Agencies
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿšช Backdoored firmware lets China state hackers control with โ€œmagic packetsโ€
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‘ฎ๐Ÿปโ€โ™‚๏ธSecurity researcher warns of chilling effect after feds search phone at
โž ๐Ÿฆ  โ—๏ธFBI Warns Organizations of Dual Ransomware, Wiper Attacks
โž ๐Ÿค– ๐Ÿฆ  Chat responses infiltrated by ads pushing
โž ๐Ÿฅ ๐ŸŽฃ Red Cross-Themed Attacks Distributing DangerAds and AtlasAgent Backdoors
โž ๐Ÿฅท๐Ÿป ๐Ÿ keys stolen by stream of malicious and packages
โž ๐Ÿฆ ๐ŸŽ  New Variant of BBTok Targets Over 40 Latin American Banks
โž ๐Ÿฆ  ๐Ÿšช : New Advanced Backdoor with Distinctive Malware Tactics
โž ๐Ÿš€ Launches Realtime Attack Graph for Cloud Environments
โž ๐Ÿ› ๐Ÿ“จ Critical vulnerabilities in threaten over 250k servers worldwide
โž ๐Ÿ”“ Progress warns of maximum severity WS_FTP Server vulnerability
โž ๐Ÿฉน ๐Ÿ”ฅ fixes fifth actively exploited Chrome zero-day of 2023
โž ๐Ÿฉน ๐Ÿ 14 Patches 60
โž ๐Ÿฉน ๐ŸฆŠ 118 Patches High-Severity Vulnerabilities
โž ๐Ÿคซ โœ… Google quietly corrects previously submitted disclosure for critical 0-day
โž ๐Ÿ‘€ ๐Ÿ‡ช๐Ÿ‡ฌ 0-days exploited by commercial surveillance vendor in

๐Ÿ“š This week's recommended reading is: "Philosophy of Cybersecurity" by @LukaszOlejnik and Artur Kurasinski

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-392023

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ”“ โŒ TransUnion Denies After Hacker Publishes Allegedly Stolen Data
โž ๐Ÿ”“ โš–๏ธ Hackers breached International Criminal Courtโ€™s systems last week
โž ๐Ÿ”“ ๐Ÿค– researchers accidentally exposed terabytes of internal sensitive data
โž ๐Ÿฆ  ๐Ÿ’ธ hits Storage with encryptor
โž ๐Ÿ‡ฎ๐Ÿ‡ท ๐Ÿ‡ฎ๐Ÿ‡ฑ Iranian Nation-State Actor OilRig Targets Israeli Organizations
โž ๐Ÿ‡ฎ๐Ÿ‡ณ 's biggest tech centers named as hotspots
โž ๐Ÿ‡ซ๐Ÿ‡ฎ ๐Ÿ’Š Finnish Authorities Dismantle Notorious Dark Web Drug Marketplace
โž ๐Ÿ‡จ๐Ÿ‡ฆ ๐Ÿ‡ท๐Ÿ‡บ Canadian Government Targeted With Attacks by Pro- Group
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡บ๐Ÿ‡ธ Accuses U.S. of Decade-Long Campaign Against Servers
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡จ๐Ÿ‡ณ China's Malicious Cyber Activity Informing War Preparations, Says
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿฆ  New Linux used in cyber espionage attacks
โž ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ” UK Minister Warns Over End-to-End Encryption
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ท๐Ÿ‡บ One of the โ€™s most wanted hackers is trolling the U.S. government
โž ๐Ÿฆ  ๐Ÿฅธ Fake proof-of-concept exploit drops malware
โž ๐Ÿฆ  ๐Ÿ“ˆ botnet activity surges 600x with stealthier malware variants
โž ๐Ÿฆ  ๐Ÿ“ก Hackers backdoor providers with new HTTPSnoop malware
โž ๐Ÿฆ  ๐Ÿ malware returns in new attacks abusing folders
โž ๐Ÿ” launches support into general availability
โž โ˜‘๏ธ ๐Ÿง Free Download Manager releases script to check for malware
โž ๐Ÿ’ฌ ๐Ÿ” adds quantum-resistant encryption to its messaging protocol
โž ๐Ÿ ๐Ÿ” 17 includes these new security and features
โž ๐Ÿฉน High-Severity Flaws Uncovered in Products and ISC BIND Server
โž ๐Ÿฉน ๐Ÿ˜ก Incomplete disclosures by and create โ€œhuge blindspotโ€ for 0-day hunters
โž ๐Ÿ ๐Ÿฉน Apple emergency updates fix 3 new zero-days exploited in attacks
โž ๐Ÿฉน fixes protection zero-day used in attacks
โž ๐Ÿฉน Patches High-Severity in FortiOS, FortiProxy, FortiWeb Products
โž ๐Ÿ”“ Nearly 12,000 Found Vulnerable to Recently Disclosed RCE Vulnerability

๐Ÿ“š This week's recommended reading is: "Future Crimes: Everything Is Connected, Everyone Is Vulnerable and What We Can Do About It" by Marc Goodman

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-382023

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž โ˜๏ธ ๐Ÿ”‘ How Authenticator made one companyโ€™s network much, much worse
โž ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ”“ 30k primary pupilsโ€™ data may be at risk after cyber attack
โž ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ”“ Police officers' data exposed in attack
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐ŸŽฐ Entertainment says customer data stolen in
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐ŸŽฐ Resorts shuts down IT systems after cyberattack
โž ๐Ÿ”“ discloses data breach after hackers stole access tokens
โž ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ”“ Launches Investigation After Hacker Leaks Data
โž ๐Ÿ‡ฎ๐Ÿ‡ท Microsoft: Iranian espionage campaign targeted satellite and defense sectors
โž ๐Ÿ’ธ Hackers steal $53 million worth of from
โž ๐Ÿงจ After and X, Hackers Launch DDoS Attack on
โž ๐Ÿ‡บ๐Ÿ‡ธ โŒ passes first-in-the-nation data broker deletion tool
โž ๐Ÿ‡จ๐Ÿ‡ด ๐Ÿ’ธ Several Colombian ministries hampered by ransomware attack
โž ๐Ÿ‡ฎ๐Ÿ‡ช ๐Ÿ’ฐ slapped with $368 million fine over child privacy violations
โž ๐Ÿ“ฑ ๐Ÿ“ก and Google Are Introducing New Ways to Defeat Cell Site Simulators, But Is it Enough?
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ” Washington summit grapples with securing software
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ‘€ Hacking : Pegasus used to target โ€™s critic
โž โš–๏ธ ๐Ÿ’ป The International Criminal Court will now prosecute crimes
โž ๐Ÿ‡ต๐Ÿ‡ฑ ๐Ÿ‘€ Polish Senate says use of government spyware is illegal in the country
โž ๐Ÿฆ  -Written 3AM Ransomware: A Sneak Peek into a New Family
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿฅธ US Agencies Publish Cybersecurity Report on Threats
โž ๐Ÿง ๐Ÿฆ  Password-stealing Linux malware served for 3 years and no one noticed
โž ๐Ÿ ๐Ÿฆ  Malware Targets Apple in Recent Attacks
โž ๐Ÿ‡ฎ๐Ÿ‡ท ๐Ÿฆ  Iranian hackers 34 orgs with new Sponsor malware
โž ๐Ÿฉน โ˜๏ธ Researchers Detail 8 Vulnerabilities in HDInsight Analytics Service
โž ๐Ÿ ๐Ÿ”“ Mullvad Warns of Critical Firewall Flaw in Apple's MacOS
โž โ˜๏ธ ๐Ÿ”“ New Enable Remote Attacks on Windows Endpoints
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ’ฆ CISA offers free security scans for public water utilities
โž ๐Ÿฉน Rushes to Patch WebP Critical Zero-Day Exploit in Firefox and Thunderbird
โž ๐Ÿฉน Google Patches Zero-Day Reported by Apple, Spyware Hunters
โž ๐Ÿฉน Microsoft September 2023 Patch Tuesday fixes 2 zero-days, 59 flaws

๐Ÿ“š This week's recommended reading is: "Extreme Privacy: What It Takes to Disappear" by Michael Bazzell

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-372023

0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

โž ๐Ÿ‡บ๐Ÿ‡ธ โ˜๏ธ finally explains cause of breach: An engineerโ€™s account was hacked
โž ๐ŸŽซ ๐Ÿ”“ See Tickets says accessed customersโ€™ payment data โ€” again
โž ๐Ÿ‡ณ๐Ÿ‡ฑ ๐Ÿ”“ Chipmaker NXP Semiconductors confirms involving customersโ€™ information
โž ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ”“ election body failed cybersecurity test before hack
โž ๐Ÿšฎ ๐Ÿ”“ confirms massive data breach impacting 7 million users
โž ๐Ÿ‡ฆ๐Ÿ‡บ ๐Ÿ”“ University of data breach impacts recent applicants
โž ๐Ÿ‡ท๐Ÿ‡บ ๐Ÿ‡บ๐Ÿ‡ธ Wealthy Russian With Ties Gets 9 Years in for Hacking and Insider Trading Scheme
โž ๐Ÿ‡บ๐Ÿ‡ธ โœˆ๏ธ US Aeronautical Organization Hacked via , Vulnerabilities
โž ๐Ÿ‡ฎ๐Ÿ‡ท ๐ŸŽฃ Alert: Campaigns Deliver New SideTwist Backdoor and Agent Tesla Variant
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ‡ท๐Ÿ‡บ 's CERT Thwarts 's Cyberattack on Critical Energy
โž ๐ŸŽฐ ๐Ÿ’ธ Stake.com loses $41 million to hot wallet hackers
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ฌ๐Ÿ‡ง US, UK take action against members of the Russian-linked hacker syndicate
โž ๐Ÿš— ๐Ÿ‘€ 25 Major Car Brands Get Failing Marks From Mozilla for Security and Privacy
โž ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ‘€ UK lawmakers back down on encryption-busting โ€˜spy clauseโ€™
โž ๐ŸŒ Hundreds of thousands trafficked to work as online scammers in SE , says UN report
โž ๐Ÿ‡บ๐Ÿ‡ธ โœ๐Ÿป Hires @dotmudge to Work on Security-by-Design Principles
โž ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ›’ Children's snack recalled after its website caught serving porn
โž ๐Ÿ‡ธ๐Ÿ‡ช ๐Ÿ’ฐ Insurer fined $3M for exposing data of 650k clients for two years
โž ๐Ÿ‡ท๐Ÿ‡บ Elon Musk's erosion of safety standards at X is helping spread Russian propaganda, study finds
โž ๐Ÿ‡ฐ๐Ÿ‡ต North Korea-backed hackers target security researchers with 0-day
โž ๐ŸŽฃ Researchers identify high-grade phishing kits attacking nearly 60,000 accounts
โž ๐Ÿ‡ฎ๐Ÿ‡ณ ๐Ÿค– warns of attacks targeting its users
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ’ฌ Chinese-Speaking Cybercriminals Launch Large-Scale Smishing Campaign in U.S.
โž ๐Ÿ’ธ ๐Ÿ’Œ Fake extortion threatens to leak your sex tape
โž ๐Ÿ‘ค Warns of Social Engineering Attacks Targeting Super Administrator Privileges
โž ๐ŸŽฃ ๐Ÿ›ก๏ธ is enabling real-time phishing protection for everyone
โž ๐Ÿ“ฑ๐Ÿงจ Hacking device can spam nearby with pop-ups
โž ๐Ÿฉน ๐Ÿ patches โ€œclicklessโ€ 0-day image processing in ,
โž ๐Ÿฉน ๐Ÿ”“ to Patch IP Leak Vulnerability After Public Disclosure

๐Ÿ“š This week's recommended reading is: "Blue Team Handbook: SOC, SIEM, and Threat Hunting (V1.02): A Condensed Guide for the Security Operations Team and Threat Hunter" by Don Murdoch GSE, MSISE, MBA

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-362023

  • All
  • Subscribed
  • Moderated
  • Favorites
  • โ€ข
  • JUstTest
  • InstantRegret
  • rosin
  • modclub
  • Youngstown
  • khanakhh
  • Durango
  • slotface
  • mdbf
  • cubers
  • GTA5RPClips
  • kavyap
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • osvaldo12
  • tester
  • tacticalgear
  • ethstaker
  • Leos
  • thenastyranch
  • everett
  • normalnudes
  • anitta
  • megavids
  • cisconetworking
  • lostlight
  • All magazines