03/04

Over 100 Malicious AI/ML Models Found on Hugging Face Platform

https://thehackernews.com/2024/03/over-100-malicious-aiml-models-found-on.html
Over 100 Malicious AI/ML Models Found on Hugging Face Platform

American Express credit cards exposed in vendor data breach

https://www.bleepingcomputer.com/news/security/american-express-credit-cards-exposed-in-vendor-data-breach/
American Express credit cards exposed in vendor data breach

Stealthy GTPDOOR Linux malware targets mobile operator networks

https://www.bleepingcomputer.com/news/security/stealthy-gtpdoor-linux-malware-targets-mobile-operator-networks/
Stealthy GTPDOOR Linux malware targets mobile operator networks

How Cybercriminals are Exploiting India's UPI for Money Laundering Operations

https://thehackernews.com/2024/03/how-cybercriminals-are-exploiting.html
How Cybercriminals are Exploiting India's UPI for Money Laundering Operations

BlackCat ransomware turns off servers amid claim they stole $22 million ransom

https://www.bleepingcomputer.com/news/security/blackcat-ransomware-turns-off-servers-amid-claim-they-stole-22-million-ransom/
BlackCat ransomware turns off servers amid claim they stole $22 million ransom

Phobos Ransomware Aggressively Targeting U.S. Critical Infrastructure

https://thehackernews.com/2024/03/phobos-ransomware-aggressively.html
Phobos Ransomware Aggressively Targeting U.S. Critical Infrastructure

Rust Binary Analysis, Feature by Feature - Check Point Research

https://research.checkpoint.com/2023/rust-binary-analysis-feature-by-feature/
Rust Binary Analysis, Feature by Feature - Check Point Research

春からセキュリティエンジニアとして働く人たちに伝えたいこと - トリコロールな猫/セキュリティ

https://security.nekotricolor.com/entry/the-message-for-new-graduates-who-are-starting-to-work-as-security-engineers-this-spring
春からセキュリティエンジニアとして働く人たちに伝えたいこと - トリコロールな猫/セキュリティ

Ukraine claims it hacked Russian Ministry of Defense servers

https://www.bleepingcomputer.com/news/security/ukraine-claims-it-hacked-russian-ministry-of-defense-servers/
Ukraine claims it hacked Russian Ministry of Defense servers

CVE-2024-27198 and CVE-2024-27199: JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities (FIXED) | Rapid7 Blog

https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/
CVE-2024-27198 and CVE-2024-27199: JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities (FIXED) | Rapid7 Blog

ZAP – ZAP Updates - February 2024

https://www.zaproxy.org/blog/2024-03-04-zap-updates-february-2024/
ZAP – ZAP Updates - February 2024

🔴 Executive Offense Issue #10 - Start Hacking LLMs

https://executiveoffense.beehiiv.com/p/executive-offense-issue-10-start-hacking-llms
🔴 Executive Offense Issue #10 - Start Hacking LLMs

Linux variant of BIFROSE RAT uses deceptive domain strategies

https://securityaffairs.com/159896/malware/bifrose-bifrost-malware.html
Linux variant of BIFROSE RAT uses deceptive domain strategies

Proposed class action lawsuit alleges Apple monopolizing cloud storage for its devices | The Hill

https://thehill.com/policy/technology/4505480-proposed-lawsuit-alleges-apple-monopolizing-cloud-storage-for-its-devices/
Proposed class action lawsuit alleges Apple monopolizing cloud storage for its devices | The Hill

GTPDOOR backdoor is designed to target telecom carrier networks

https://securityaffairs.com/159929/hacking/gtpdoor-backdoor-telecom-carrier-networks.html
GTPDOOR backdoor is designed to target telecom carrier networks

MultiDump - Xre0uS

https://xre0us.io/posts/multidump/
MultiDump - Xre0uS

Threat actors hacked Taiwan-based Chunghwa Telecom

https://securityaffairs.com/159918/data-breach/chunghwa-telecom-data-breach.html
Threat actors hacked Taiwan-based Chunghwa Telecom

North Korea hacks two South Korean chip firms to steal engineering data

https://www.bleepingcomputer.com/news/security/north-korea-hacks-two-south-korean-chip-firms-to-steal-engineering-data/
North Korea hacks two South Korean chip firms to steal engineering data

The Predator spyware ecosystem is not dead - Sekoia.io Blog

https://blog.sekoia.io/the-predator-spyware-ecosystem-is-not-dead/
The Predator spyware ecosystem is not dead - Sekoia.io Blog

Apple blames Spotify for $1.95 billion fine over "abusive" App store rules

https://www.bleepingcomputer.com/news/apple/apple-blames-spotify-for-195-billion-fine-over-abusive-app-store-rules/
Apple blames Spotify for $1.95 billion fine over "abusive" App store rules

FCC Employees Targeted in Sophisticated Phishing Attacks - SecurityWeek

https://www.securityweek.com/fcc-employees-targeted-in-sophisticated-phishing-attacks/
FCC Employees Targeted in Sophisticated Phishing Attacks - SecurityWeek

Hikvision Patches High-Severity Vulnerability in Security Management System - SecurityWeek

https://www.securityweek.com/hikvision-patches-high-severity-vulnerability-in-security-management-system/
Hikvision Patches High-Severity Vulnerability in Security Management System - SecurityWeek

Exploit available for new critical TeamCity auth bypass bug, patch now

https://www.bleepingcomputer.com/news/security/exploit-available-for-new-critical-teamcity-auth-bypass-bug-patch-now/
Exploit available for new critical TeamCity auth bypass bug, patch now

Hackers steal Windows NTLM authentication hashes in phishing attacks

https://www.bleepingcomputer.com/news/security/hackers-steal-windows-ntlm-authentication-hashes-in-phishing-attacks/
Hackers steal Windows NTLM authentication hashes in phishing attacks

Linux Foundation Tackles Financial Fraud With Open Source Platform - SecurityWeek

https://www.securityweek.com/linux-foundation-tackles-financial-fraud-with-open-source-platform/
Linux Foundation Tackles Financial Fraud With Open Source Platform - SecurityWeek