03/07

FBI: U.S. lost record $12.5 billion to online crime in 2023

https://www.bleepingcomputer.com/news/security/fbi-us-lost-record-125-billion-to-online-crime-in-2023/
FBI: U.S. lost record $12.5 billion to online crime in 2023

Flipper Zero WiFi phishing attack can unlock and steal Tesla cars

https://www.bleepingcomputer.com/news/security/flipper-zero-wifi-attack-can-unlock-and-steal-tesla-cars/
Flipper Zero WiFi phishing attack can unlock and steal Tesla cars

Watch Out for Spoofed Zoom, Skype, Google Meet Sites Delivering Malware

https://thehackernews.com/2024/03/watch-out-for-spoofed-zoom-skype-google.html
Watch Out for Spoofed Zoom, Skype, Google Meet Sites Delivering Malware

Source Code Disclosure in ASP.NET apps – PT SWARM

https://swarm.ptsecurity.com/source-code-disclosure-in-asp-net-apps/
Source Code Disclosure in ASP.NET apps – PT SWARM

New Python-Based Snake Info Stealer Spreading Through Facebook Messages

https://thehackernews.com/2024/03/new-python-based-snake-info-stealer.html
New Python-Based Snake Info Stealer Spreading Through Facebook Messages

Ex-Google Engineer Arrested for Stealing AI Technology Secrets for China

https://thehackernews.com/2024/03/ex-google-engineer-arrested-for.html
Ex-Google Engineer Arrested for Stealing AI Technology Secrets for China

https://www.sans.org/u/1uNy

https://www.sans.org/u/1uNy

Chinese State Hackers Target Tibetans with Supply Chain, Watering Hole Attacks

https://thehackernews.com/2024/03/chinese-state-hackers-target-tibetans.html
Chinese State Hackers Target Tibetans with Supply Chain, Watering Hole Attacks

Linux Malware targets misconfigured misconfigured Apache Hadoop, Confluence, Docker, and Redis servers

https://securityaffairs.com/160093/hacking/linux-malware-cryptocurrency-campaign.html
Linux Malware targets misconfigured misconfigured Apache Hadoop, Confluence, Docker, and Redis servers

Hacked WordPress sites use visitors' browsers to hack other sites

https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-use-visitors-browsers-to-hack-other-sites/
Hacked WordPress sites use visitors' browsers to hack other sites

TeamCity JetBrain CVE-2024-27198 Auth Bypass Attempt | GreyNoise Visualizer

https://viz.greynoise.io/tags/teamcity-jetbrain-cve-2024-27198-auth-bypass-attempt?days=10
TeamCity JetBrain CVE-2024-27198 Auth Bypass Attempt | GreyNoise Visualizer

TeamCity auth bypass bug exploited to mass-generate admin accounts

https://www.bleepingcomputer.com/news/security/teamcity-auth-bypass-bug-exploited-to-mass-generate-admin-accounts/
TeamCity auth bypass bug exploited to mass-generate admin accounts

National intelligence agency of Moldova warns of Russia attacks ahead of the presidential election

https://securityaffairs.com/160112/cyber-warfare-2/moldova-warns-of-hybrid-attacks-from-russia.html
National intelligence agency of Moldova warns of Russia attacks ahead of the presidential election

Hacked WordPress Sites Abusing Visitors' Browsers for Distributed Brute-Force Attacks

https://thehackernews.com/2024/03/hacked-wordpress-sites-abusing-visitors.html
Hacked WordPress Sites Abusing Visitors' Browsers for Distributed Brute-Force Attacks

FBI: Cybercrime Losses Exceeded $12.5 Billion in 2023 - SecurityWeek

https://www.securityweek.com/fbi-cybercrime-losses-exceeded-12-5-billion-in-2023/
FBI: Cybercrime Losses Exceeded $12.5 Billion in 2023 - SecurityWeek

arm64.syscall.sh

https://arm64.syscall.sh
arm64.syscall.sh

PetSmart warns of credential stuffing attacks trying to hack accounts

https://www.bleepingcomputer.com/news/security/petsmart-warns-of-credential-stuffing-attacks-trying-to-hack-accounts/
PetSmart warns of credential stuffing attacks trying to hack accounts

Cisco Patches High-Severity Vulnerabilities in VPN Product - SecurityWeek

https://www.securityweek.com/cisco-patches-high-severity-vulnerabilities-in-vpn-product/
Cisco Patches High-Severity Vulnerabilities in VPN Product - SecurityWeek

Hacktivity – HackerOne Hacker API v1

https://api.hackerone.com/hacker-resources/#hacktivity
Hacktivity – HackerOne Hacker API v1

Cybercriminals Spoof US Government Organizations in BEC, Phishing Attacks - SecurityWeek

https://www.securityweek.com/cybercriminals-spoof-us-government-organizations-in-bec-phishing-attacks/
Cybercriminals Spoof US Government Organizations in BEC, Phishing Attacks - SecurityWeek

PetSmart warns customers of credential stuffing attack | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/03/petsmart-warns-customers-of-credential-stuffing-attack
PetSmart warns customers of credential stuffing attack | Malwarebytes

Switzerland: Play ransomware leaked 65,000 government documents

https://www.bleepingcomputer.com/news/security/switzerland-play-ransomware-leaked-65-000-government-documents/
Switzerland: Play ransomware leaked 65,000 government documents

Google engineer caught stealing AI tech secrets for Chinese firms

https://www.bleepingcomputer.com/news/google/google-engineer-caught-stealing-ai-tech-secrets-for-chinese-firms/
Google engineer caught stealing AI tech secrets for Chinese firms

On SSRF (Server Side Request Forgery) or Simple Stuff Rodolfo Found — Part I | by Rodolfo Assis (Brute) | Medium

https://rodoassis.medium.com/on-ssrf-server-side-request-forgery-or-simple-stuff-rodolfo-found-part-i-4edf7ee75389
On SSRF (Server Side Request Forgery) or Simple Stuff Rodolfo Found — Part I | by Rodolfo Assis (Brute) | Medium