01/23

TeamCity Intrusion Saga: APT29 Suspected Among the Attackers Exploiting CVE-2023-42793 | FortiGuard Labs

https://www.fortinet.com/blog/threat-research/teamcity-intrusion-saga-apt29-suspected-exploiting-cve-2023-42793
TeamCity Intrusion Saga: APT29 Suspected Among the Attackers Exploiting CVE-2023-42793 | FortiGuard Labs

SEC confirms X account was hacked in SIM swapping attack

https://www.bleepingcomputer.com/news/security/sec-confirms-x-account-was-hacked-in-sim-swapping-attack/
SEC confirms X account was hacked in SIM swapping attack

ScarCruft | Attackers Gather Strategic Intelligence and Target Cybersecurity Professionals - SentinelOne

https://www.sentinelone.com/labs/a-glimpse-into-future-scarcruft-campaigns-attackers-gather-strategic-intelligence-and-target-cybersecurity-professionals/
ScarCruft | Attackers Gather Strategic Intelligence and Target Cybersecurity Professionals - SentinelOne

~40,000 Attacks in 3 Days: Critical Confluence RCE Under Active Exploitation

https://thehackernews.com/2024/01/40000-attacks-in-3-days-critical.html
~40,000 Attacks in 3 Days: Critical Confluence RCE Under Active Exploitation

Mother of All Breaches: ​a Historic Data Leak Reveals 26 Billion Records | Cybernews

https://cybernews.com/security/billions-passwords-credentials-leaked-mother-of-all-breaches/
Mother of All Breaches: ​a Historic Data Leak Reveals 26 Billion Records | Cybernews

Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing - Mobile Hacker

https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/
Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing - Mobile Hacker

VexTrio: The Uber of Cybercrime - Brokering Malware for 60+ Affiliates

https://thehackernews.com/2024/01/vextrio-uber-of-cybercrime-brokering.html
VexTrio: The Uber of Cybercrime - Brokering Malware for 60+ Affiliates

Fortra warns of new critical GoAnywhere MFT auth bypass, patch now

https://www.bleepingcomputer.com/news/security/fortra-warns-of-new-critical-goanywhere-mft-auth-bypass-patch-now/
Fortra warns of new critical GoAnywhere MFT auth bypass, patch now

"Activator" Alert: MacOS Malware Hides in Cracked Apps, Targeting Crypto Wallets

https://thehackernews.com/2024/01/activator-alert-macos-malware-hides-in.html
"Activator" Alert: MacOS Malware Hides in Cracked Apps, Targeting Crypto Wallets

Black Basta gang claims the hack of the UK water utility Southern Water - Security Affairs

https://securityaffairs.com/157951/cyber-crime/black-basta-gang-claims-the-hack-of-the-uk-water-utility-southern-water.html
Black Basta gang claims the hack of the UK water utility Southern Water - Security Affairs

Jason’s Deli says customer data exposed in credential stuffing attack

https://www.bleepingcomputer.com/news/security/jasons-deli-says-customer-data-exposed-in-credential-stuffing-attack/
Jason’s Deli says customer data exposed in credential stuffing attack

BreachForums Founder Sentenced to 20 Years of Supervised Release, No Jail Time

https://thehackernews.com/2024/01/breachforums-founder-sentenced-to-20.html
BreachForums Founder Sentenced to 20 Years of Supervised Release, No Jail Time

Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub

https://thehackernews.com/2024/01/malicious-npm-packages-exfiltrate-1600.html
Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub

Apple Issues Patch for Critical Zero-Day in iPhones, Macs - Update Now

https://thehackernews.com/2024/01/apple-issues-patch-for-critical-zero.html
Apple Issues Patch for Critical Zero-Day in iPhones, Macs - Update Now

High-Severity Vulnerability Patched in Splunk Enterprise - SecurityWeek

https://www.securityweek.com/high-severity-vulnerability-patched-in-splunk-enterprise/
High-Severity Vulnerability Patched in Splunk Enterprise - SecurityWeek

Fortra's Security and Trust Center

https://www.fortra.com/security/advisory/fi-2024-001
Fortra's Security and Trust Center

These Are the Notorious NSA Furby Documents Showing Spy Agency Freaking Out About Embedded AI in Children's Toy

https://www.404media.co/these-are-the-notorious-nsa-furby-documents-showing-spy-agency-freaking-out-about-childrens-toy/
These Are the Notorious NSA Furby Documents Showing Spy Agency Freaking Out About Embedded AI in Children's Toy

Kasseika Ransomware Deploys BYOVD Attacks Abuses PsExec and Exploits Martini Driver 

https://www.trendmicro.com/en_us/research/24/a/kasseika-ransomware-deploys-byovd-attacks-abuses-psexec-and-expl.html
Kasseika Ransomware Deploys BYOVD Attacks Abuses PsExec and Exploits Martini Driver 

Space / X

https://twitter.com/i/spaces/1mnGepwBdbPKX
Space / X

Water services giant Veolia North America hit by ransomware attack

https://www.bleepingcomputer.com/news/security/water-services-giant-veolia-north-america-hit-by-ransomware-attack/
Water services giant Veolia North America hit by ransomware attack

.NET Hooking - Harmonizing Managed Territory - Check Point Research

https://research.checkpoint.com/2024/net-hooking-harmonizing-managed-territory/
.NET Hooking - Harmonizing Managed Territory - Check Point Research

PS C:\Users\

http://xtest.stderr.pl/
PS C:\Users\

GreyNoise Labs - The Confusing History of F5 BIG-IP RCE Vulnerabilities

https://www.labs.greynoise.io/grimoire/2024-01-14-f5-rce-explained/
GreyNoise Labs - The Confusing History of F5 BIG-IP RCE Vulnerabilities

TeamViewer Exploited to Obtain Remote Access, Deploy Ransomware

https://www.hackread.com/teamviewer-exploited-remote-access-ransomware/
TeamViewer Exploited to Obtain Remote Access, Deploy Ransomware

Why cyberattacks mustn’t be kept secret - Help Net Security

https://www.helpnetsecurity.com/2024/01/23/cybersecurity-transparency/
Why cyberattacks mustn’t be kept secret - Help Net Security

From Megabits to Terabits: Gcore Radar Warns of a New Era of DDoS Attacks

https://thehackernews.com/2024/01/from-megabits-to-terabits-gcore-radar.html
From Megabits to Terabits: Gcore Radar Warns of a New Era of DDoS Attacks

Writeup for CVE-2023-39143: PaperCut WebDAV Vulnerability – Horizon3.ai

https://www.horizon3.ai/writeup-for-cve-2023-39143-papercut-webdav-vulnerability/
Writeup for CVE-2023-39143: PaperCut WebDAV Vulnerability – Horizon3.ai