02/09

PSIRT | FortiGuard

https://fortiguard.fortinet.com/psirt/FG-IR-24-015
PSIRT | FortiGuard

Wall Mounted Toothbrush Sanitizer / Squeezer

https://store.fortinet.com/wall-mounted-toothbrush-sanitizer-squeezer/product/100046
Wall Mounted Toothbrush Sanitizer / Squeezer

New RustDoor macOS malware impersonates Visual Studio update

https://www.bleepingcomputer.com/news/security/new-rustdoor-macos-malware-impersonates-visual-studio-update/
New RustDoor macOS malware impersonates Visual Studio update

New Fortinet RCE bug is actively exploited, CISA confirms

https://www.bleepingcomputer.com/news/security/new-fortinet-rce-bug-is-actively-exploited-cisa-confirms/
New Fortinet RCE bug is actively exploited, CISA confirms

Stealthy Zardoor Backdoor Targets Saudi Islamic Charity Organization

https://thehackernews.com/2024/02/stealthy-zardoor-backdoor-targets-saudi.html
Stealthy Zardoor Backdoor Targets Saudi Islamic Charity Organization

Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation

https://thehackernews.com/2024/02/fortinet-warns-of-critical-fortios-ssl.html
Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation

Americans lost record $10 billion to fraud in 2023, FTC warns

https://www.bleepingcomputer.com/news/security/americans-lost-record-10-billion-to-fraud-in-2023-ftc-warns/
Americans lost record $10 billion to fraud in 2023, FTC warns

Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA Gateways

https://thehackernews.com/2024/02/warning-new-ivanti-auth-bypass-flaw.html
Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA Gateways

District of Massachusetts | International Cybercrime Malware Service Dismantled by Federal Authorities | United States Department of Justice

https://www.justice.gov/usao-ma/pr/international-cybercrime-malware-service-dismantled-federal-authorities
District of Massachusetts | International Cybercrime Malware Service Dismantled by Federal Authorities | United States Department of Justice

MoqHao Android Malware Evolves with Auto-Execution Capability

https://thehackernews.com/2024/02/new-variant-of-moqhao-android-malware.html
MoqHao Android Malware Evolves with Auto-Execution Capability

PSIRT | FortiGuard

https://www.fortiguard.com/psirt/FG-IR-24-029
PSIRT | FortiGuard

Raspberry Robin Malware Upgrades with Discord Spread and New Exploits

https://thehackernews.com/2024/02/raspberry-robin-malware-upgrades-with.html
Raspberry Robin Malware Upgrades with Discord Spread and New Exploits

New Coyote Trojan Targets 61 Brazilian Banks with Nim-Powered Attack

https://thehackernews.com/2024/02/new-coyote-trojan-targets-61-brazilian.html
New Coyote Trojan Targets 61 Brazilian Banks with Nim-Powered Attack

Fake LastPass password manager spotted on Apple’s App Store

https://www.bleepingcomputer.com/news/security/fake-lastpass-password-manager-spotted-on-apples-app-store/
Fake LastPass password manager spotted on Apple’s App Store

AnyDesk Shares More Information on Recent Hack - SecurityWeek

https://www.securityweek.com/anydesk-shares-more-information-on-recent-hack/
AnyDesk Shares More Information on Recent Hack - SecurityWeek

PSIRT | FortiGuard

https://www.fortiguard.com/psirt/FG-IR-24-015
PSIRT | FortiGuard

New Fortinet RCE flaw in SSL VPN likely exploited in attacks

https://www.bleepingcomputer.com/news/security/new-fortinet-rce-flaw-in-ssl-vpn-likely-exploited-in-attacks/
New Fortinet RCE flaw in SSL VPN likely exploited in attacks

FBI and CISA publish guide to Living off the Land techniques | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/02/fbi-and-cisa-publish-guide-to-living-off-the-land-techniques
FBI and CISA publish guide to Living off the Land techniques | Malwarebytes

Fortinet: APTs Exploiting FortiOS Vulnerabilities in Critical Infrastructure Attacks - SecurityWeek

https://www.securityweek.com/fortinet-apts-exploiting-fortios-vulnerabilities-in-critical-infrastructure-attacks/
Fortinet: APTs Exploiting FortiOS Vulnerabilities in Critical Infrastructure Attacks - SecurityWeek

Ivanti warns of a new auth bypass flaw in its Connect Secure, Policy Secure, and ZTA gateway devices

https://securityaffairs.com/158889/security/ivanti-warns-auth-bypass-flaw.html
Ivanti warns of a new auth bypass flaw in its Connect Secure, Policy Secure, and ZTA gateway devices

Black Basta ransomware gang hacked Hyundai Motor Europe

https://securityaffairs.com/158916/data-breach/black-basta-ransomware-hyundai-motor-europe.html
Black Basta ransomware gang hacked Hyundai Motor Europe

Fortinet warns of a new actively exploited RCE flaw in FortiOS SSL VPN

https://securityaffairs.com/158908/hacking/fortinet-fortios-rce-exploitation.html
Fortinet warns of a new actively exploited RCE flaw in FortiOS SSL VPN

Juniper Support Portal Exposed Customer Device Info – Krebs on Security

https://krebsonsecurity.com/2024/02/juniper-support-portal-exposed-customer-device-info/
Juniper Support Portal Exposed Customer Device Info – Krebs on Security

Canada to ban the Flipper Zero to stop surge in car thefts

https://www.bleepingcomputer.com/news/security/canada-wants-to-ban-the-flipper-zero-to-stop-surge-in-car-thefts/
Canada to ban the Flipper Zero to stop surge in car thefts

New MacOS Backdoor Written in Rust Shows Possible Link with Windows Ransomware Group

https://www.bitdefender.com/blog/labs/new-macos-backdoor-written-in-rust-shows-possible-link-with-windows-ransomware-group/
New MacOS Backdoor Written in Rust Shows Possible Link with Windows Ransomware Group

Reverse Engineering with Binary Ninja (Binja) / X

https://twitter.com/i/broadcasts/1yoJMwLVpaNKQ
Reverse Engineering with Binary Ninja (Binja) / X

Exploiting a vulnerable Minifilter Driver to create a process killer

https://securityaffairs.com/158926/hacking/process-killer-with-minifilter-driver.html
Exploiting a vulnerable Minifilter Driver to create a process killer

Form Tools Remote Code Execution: We Need To Talk About PHP

https://labs.watchtowr.com/form-tools-we-need-to-talk-about-php/
Form Tools Remote Code Execution: We Need To Talk About PHP

Tyranid's Lair: Sudo On Windows a Quick Rundown

https://www.tiraniddo.dev/2024/02/sudo-on-windows-quick-rundown.html
Tyranid's Lair: Sudo On Windows a Quick Rundown

JSON Smuggling: A far-fetched intrusion detection evasion technique | by Grimminck | Feb, 2024 | Medium

https://grimminck.medium.com/json-smuggling-a-far-fetched-intrusion-detection-evasion-technique-51ed8f5ee05f
JSON Smuggling: A far-fetched intrusion detection evasion technique | by Grimminck | Feb, 2024 | Medium

Puckungfu 2: Another NETGEAR WAN Command Injection | NCC Group Research Blog | Making the world safer and more secure

https://research.nccgroup.com/2024/02/09/puckungfu-2-another-netgear-wan-command-injection/
Puckungfu 2: Another NETGEAR WAN Command Injection | NCC Group Research Blog | Making the world safer and more secure

Flipping Out for the M1 - Hackster.io

https://www.google.com/amp/s/www.hackster.io/news/flipping-out-for-the-m1-b86efae35a31.amp
Flipping Out for the M1 - Hackster.io

Ivanti Connect Secure CVE-2024-22024 - Are We Now Part Of Ivanti?

https://labs.watchtowr.com/are-we-now-part-of-ivanti/
Ivanti Connect Secure CVE-2024-22024 - Are We Now Part Of Ivanti?

Fortinet Warns of New FortiOS Zero-Day - SecurityWeek

https://www.securityweek.com/fortinet-warns-of-new-fortios-zero-day/
Fortinet Warns of New FortiOS Zero-Day - SecurityWeek

Ivanti: Patch new Connect Secure auth bypass bug immediately

https://www.bleepingcomputer.com/news/security/ivanti-patch-new-connect-secure-auth-bypass-bug-immediately/
Ivanti: Patch new Connect Secure auth bypass bug immediately