11/22

New Flaws in Fingerprint Sensors Let Attackers Bypass Windows Hello Login

https://thehackernews.com/2023/11/new-flaws-in-fingerprint-sensors-let.html
New Flaws in Fingerprint Sensors Let Attackers Bypass Windows Hello Login

Hacktivists breach U.S. nuclear research lab, steal employee data

https://www.bleepingcomputer.com/news/security/hacktivists-breach-us-nuclear-research-lab-steal-employee-data/
Hacktivists breach U.S. nuclear research lab, steal employee data

North Korean Hackers Pose as Job Recruiters and Seekers in Malware Campaigns

https://thehackernews.com/2023/11/north-korean-hackers-pose-as-job.html
North Korean Hackers Pose as Job Recruiters and Seekers in Malware Campaigns

ClearFake Campaign Expands to Deliver Atomic Stealer on Mac Systems

https://thehackernews.com/2023/11/clearfake-campaign-expands-to-deliver.html
ClearFake Campaign Expands to Deliver Atomic Stealer on Mac Systems

Remember, Remember the 22nd of November

http://www.damninteresting.com/remember-remember-the-22nd-of-november/
Remember, Remember the 22nd of November

LockBit Ransomware Exploiting Critical Citrix Bleed Vulnerability to Break In

https://thehackernews.com/2023/11/lockbit-ransomware-exploiting-critical.html
LockBit Ransomware Exploiting Critical Citrix Bleed Vulnerability to Break In

Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors

https://unit42.paloaltonetworks.com/two-campaigns-by-north-korea-bad-actors-target-job-hunters/
Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors

New botnet malware exploits two zero-days to infect NVRs and routers

https://www.bleepingcomputer.com/news/security/new-botnet-malware-exploits-two-zero-days-to-infect-nvrs-and-routers/
New botnet malware exploits two zero-days to infect NVRs and routers

Microsoft: Lazarus hackers breach CyberLink in supply chain attack

https://www.bleepingcomputer.com/news/security/microsoft-lazarus-hackers-breach-cyberlink-in-supply-chain-attack/
Microsoft: Lazarus hackers breach CyberLink in supply chain attack

MalwareBazaar | NetSupport

https://bazaar.abuse.ch/browse/tag/NetSupport/
MalwareBazaar | NetSupport

GitHub - synacktiv/Mindmaps

https://github.com/synacktiv/Mindmaps
GitHub - synacktiv/Mindmaps

Exploit for Critical Windows Defender Bypass Goes Public

https://www.darkreading.com/vulnerabilities-threats/exploit-critical-windows-defender-bypass-public
Exploit for Critical Windows Defender Bypass Goes Public

Welltok data breach exposes data of 8.5 million US patients

https://www.bleepingcomputer.com/news/security/welltok-data-breach-exposes-data-of-85-million-us-patients/
Welltok data breach exposes data of 8.5 million US patients

Kansas courts confirm data theft, ransom demand after cyberattack

https://www.bleepingcomputer.com/news/security/kansas-courts-confirm-data-theft-ransom-demand-after-cyberattack/
Kansas courts confirm data theft, ransom demand after cyberattack

Kansas Officials Blame 5-Week Disruption of Court System on ‘Sophisticated Foreign Cyberattack’ - SecurityWeek

https://www.securityweek.com/kansas-officials-blame-5-week-disruption-of-court-system-on-sophisticated-foreign-cyberattack/
Kansas Officials Blame 5-Week Disruption of Court System on ‘Sophisticated Foreign Cyberattack’ - SecurityWeek

Open-source Blender project battling DDoS attacks since Saturday

https://www.bleepingcomputer.com/news/security/open-source-blender-project-battling-ddos-attacks-since-saturday/
Open-source Blender project battling DDoS attacks since Saturday

Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products - SecurityWeek

https://www.securityweek.com/microsoft-offers-up-to-20000-for-vulnerabilities-in-defender-products/
Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products - SecurityWeek

CISOs can marry security and business success - Help Net Security

https://www.helpnetsecurity.com/2023/11/22/cisos-business-security-goals/
CISOs can marry security and business success - Help Net Security

SiegedSec hacktivist group hacked Idaho National Laboratory (INL)

https://securityaffairs.com/154598/hacktivism/siegedsec-hacked-idaho-national-laboratory.html
SiegedSec hacktivist group hacked Idaho National Laboratory (INL)

ETW internals for security research and forensics | Trail of Bits Blog

https://blog.trailofbits.com/2023/11/22/etw-internals-for-security-research-and-forensics/
ETW internals for security research and forensics | Trail of Bits Blog

Thanking the vulnerability research community with NCSC... - NCSC.GOV.UK

https://www.ncsc.gov.uk/blog-post/thanking-vulnerability-research-community-ncsc-challenge-coins
Thanking the vulnerability research community with NCSC... - NCSC.GOV.UK

CERT-EU - Critical vulnerability in FortiSIEM

https://www.cert.europa.eu/publications/security-advisories/2023-092/
CERT-EU - Critical vulnerability in FortiSIEM

Windows Hello Fingerprint Authentication Bypassed on Popular Laptops - SecurityWeek

https://www.securityweek.com/windows-hello-fingerprint-authentication-bypassed-on-popular-laptops/
Windows Hello Fingerprint Authentication Bypassed on Popular Laptops - SecurityWeek

XXE, You Can Depend On Me (OpenCMS CVE-2023-42344 and Friends)

https://labs.watchtowr.com/xxe-you-can-depend-on-me-opencms/
XXE, You Can Depend On Me (OpenCMS CVE-2023-42344 and Friends)