03/08

Carrot disclosure

https://dustri.org/b/carrot-disclosure.html
Carrot disclosure

Microsoft says Russian hackers breached its systems, accessed source code

https://www.bleepingcomputer.com/news/microsoft/microsoft-says-russian-hackers-breached-its-systems-accessed-source-code/
Microsoft says Russian hackers breached its systems, accessed source code

CISA forced to take two systems offline last month after Ivanti compromise

https://therecord.media/cisa-takes-two-systems-offline-following-ivanti-compromise
CISA forced to take two systems offline last month after Ivanti compromise

QEMU Emulator Exploited as Tunneling Tool to Breach Company Network

https://thehackernews.com/2024/03/cybercriminals-utilize-qemu-emulator-as.html
QEMU Emulator Exploited as Tunneling Tool to Breach Company Network

CISA Warns of Actively Exploited JetBrains TeamCity Vulnerability

https://thehackernews.com/2024/03/cisa-warns-of-actively-exploited.html
CISA Warns of Actively Exploited JetBrains TeamCity Vulnerability

GreyNoise Labs - Hunting for Fortinet CVE-2024-21762: Vulnerability Research for Detection Engineering

https://www.labs.greynoise.io/grimoire/2024-03-08-fortinet-cve-2024-21762/
GreyNoise Labs - Hunting for Fortinet CVE-2024-21762: Vulnerability Research for Detection Engineering

Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client

https://thehackernews.com/2024/03/cisco-issues-patch-for-high-severity.html
Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client

Switzerland: Play ransomware leaked 65,000 government documents

https://www.bleepingcomputer.com/news/security/switzerland-play-ransomware-leaked-65-000-government-documents/
Switzerland: Play ransomware leaked 65,000 government documents

You can not simply publicly access private secure links, can you? | Vin01’s Blog

https://vin01.github.io/piptagole/security-tools/soar/urlscan/hybrid-analysis/data-leaks/urlscan.io/cloudflare-radar%22/2024/03/07/url-database-leaks-private-urls.html
You can not simply publicly access private secure links, can you? | Vin01’s Blog

Meta Details WhatsApp and Messenger Interoperability to Comply with EU's DMA Regulations

https://thehackernews.com/2024/03/meta-details-whatsapp-and-messenger.html
Meta Details WhatsApp and Messenger Interoperability to Comply with EU's DMA Regulations

[Information ; Dear Friends and Partners] | DRAGON BALL OFFICIAL SITE

https://en.dragon-ball-official.com/news/01_2499.html
[Information ; Dear Friends and Partners] | DRAGON BALL OFFICIAL SITE

The Week in Ransomware - March 8th 2024 - Waiting for the BlackCat rebrand

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-march-8th-2024-waiting-for-the-darkside-rebrand/
The Week in Ransomware - March 8th 2024 - Waiting for the BlackCat rebrand

Shielder - pgAdmin (<=8.3) Path Traversal in Session Handling Leads to Unsafe Deserialization and Remote Code Execution (RCE)

https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/
Shielder - pgAdmin (<=8.3) Path Traversal in Session Handling Leads to Unsafe Deserialization and Remote Code Execution (RCE)

Windows 10 KB5001716 update fails with 0x80070643 errors, how to fix

https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5001716-update-fails-with-0x80070643-errors-how-to-fix/
Windows 10 KB5001716 update fails with 0x80070643 errors, how to fix

QNAP warns of critical auth bypass flaw in its NAS devices

https://www.bleepingcomputer.com/news/security/qnap-warns-of-critical-auth-bypass-flaw-in-its-nas-devices/
QNAP warns of critical auth bypass flaw in its NAS devices

Chinese Cyberspies Target Tibetans via Watering Hole, Supply Chain Attacks - SecurityWeek

https://www.securityweek.com/chinese-cyberspies-target-tibetans-via-watering-hole-supply-chain-attacks/
Chinese Cyberspies Target Tibetans via Watering Hole, Supply Chain Attacks - SecurityWeek

TrustedSec | Careers

https://www.trustedsec.com/about-us/careers
TrustedSec | Careers

Evasive Panda leverages Monlam Festival to target Tibetans

https://www.welivesecurity.com/en/eset-research/evasive-panda-leverages-monlam-festival-target-tibetans/
Evasive Panda leverages Monlam Festival to target Tibetans

MalpediaFLOSSed

https://danielplohmann.github.io/blog/2024/03/08/malpediaflossed.html
MalpediaFLOSSed

https://pathonproject.com/zb/?72a14ef558282358=#62b6252Rz6Ln1OxPuHMQY2hjgAyLRFSgcYEVVEc2ag4=

https://pathonproject.com/zb/?72a14ef558282358=#62b6252Rz6Ln1OxPuHMQY2hjgAyLRFSgcYEVVEc2ag4=

Change Healthcare Restores Pharmacy Services Disrupted by Ransomware - SecurityWeek

https://www.securityweek.com/change-healthcare-restores-pharmacy-services-disrupted-by-ransomware/
Change Healthcare Restores Pharmacy Services Disrupted by Ransomware - SecurityWeek

GitHub - LloydLabs/process-enumeration-stealth

https://github.com/LloydLabs/process-enumeration-stealth
GitHub - LloydLabs/process-enumeration-stealth

CISA, NSA share best practices for securing cloud services

https://www.bleepingcomputer.com/news/security/cisa-nsa-share-best-practices-for-securing-cloud-services/
CISA, NSA share best practices for securing cloud services

Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard | MSRC Blog | Microsoft Security Response Center

https://msrc.microsoft.com/blog/2024/03/update-on-microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/
Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard | MSRC Blog | Microsoft Security Response Center

Answer.AI - You can now train a 70b language model at home

https://www.answer.ai/posts/2024-03-06-fsdp-qlora.html
Answer.AI - You can now train a 70b language model at home

VP and Chief Info Security Officer

https://jobs.jhu.edu/job/Baltimore-VP-and-Chief-Info-Security-Officer-MD-21209/1141579200/
VP and Chief Info Security Officer