03/25

Hackers poison source code from largest Discord bot platform

https://www.bleepingcomputer.com/news/security/hackers-poison-source-code-from-largest-discord-bot-platform/
Hackers poison source code from largest Discord bot platform

Google's new AI search results promotes sites pushing malware, scams

https://www.bleepingcomputer.com/news/google/googles-new-ai-search-results-promotes-sites-pushing-malware-scams/
Google's new AI search results promotes sites pushing malware, scams

Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others

https://thehackernews.com/2024/03/hackers-hijack-github-accounts-in.html
Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others

Curious Serpens’ FalseFont Backdoor: Technical Analysis, Detection and Prevention

https://unit42.paloaltonetworks.com/curious-serpens-falsefont-backdoor/
Curious Serpens’ FalseFont Backdoor: Technical Analysis, Detection and Prevention

Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks

https://thehackernews.com/2024/03/iran-linked-muddywater-deploys-atera.html
Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks

New MFA-bypassing phishing kit targets Microsoft 365, Gmail accounts

https://www.bleepingcomputer.com/news/security/new-mfa-bypassing-phishing-kit-targets-microsoft-365-gmail-accounts/
New MFA-bypassing phishing kit targets Microsoft 365, Gmail accounts

Hackers Target System Admins with Fake PuTTY Website, Deploy Rhadamanthys Stealer

https://securityonline.info/hackers-target-system-admins-with-fake-putty-website-deploy-rhadamanthys-stealer/
Hackers Target System Admins with Fake PuTTY Website, Deploy Rhadamanthys Stealer

20 essential open-source cybersecurity tools that save you time - Help Net Security

https://www.helpnetsecurity.com/2024/03/25/essential-open-source-cybersecurity-tools/
20 essential open-source cybersecurity tools that save you time - Help Net Security

Mozilla Patches Firefox Zero-Days Exploited at Pwn2Own - SecurityWeek

https://www.securityweek.com/mozilla-patches-firefox-zero-days-exploited-at-pwn2own/
Mozilla Patches Firefox Zero-Days Exploited at Pwn2Own - SecurityWeek

White House Nominates First Assistant Secretary of Defense for Cyber Policy - SecurityWeek

https://www.securityweek.com/white-house-nominates-first-assistant-secretary-of-defense-for-cyber-policy/
White House Nominates First Assistant Secretary of Defense for Cyber Policy - SecurityWeek

Blaze's Security Blog: Analyse, hunt and classify malware using .NET metadata

https://bartblaze.blogspot.com/2024/03/analyse-hunt-and-classify-malware-using.html
Blaze's Security Blog: Analyse, hunt and classify malware using .NET metadata

New ZenHammer memory attack impacts AMD Zen CPUs

https://www.bleepingcomputer.com/news/security/new-zenhammer-memory-attack-impacts-amd-zen-cpus/
New ZenHammer memory attack impacts AMD Zen CPUs

The OODA Loop: The Military Model That Speeds Up Cybersecurity Response - SecurityWeek

https://www.securityweek.com/the-ooda-loop-the-military-model-that-speeds-up-cybersecurity-response/
The OODA Loop: The Military Model That Speeds Up Cybersecurity Response - SecurityWeek

GoFetch side-channel attack against Apple systems allows secret keys extraction

https://securityaffairs.com/160993/hacking/gofetch-side-channel-attack-apple.html
GoFetch side-channel attack against Apple systems allows secret keys extraction

Large-Scale StrelaStealer Campaign in Early 2024

https://unit42.paloaltonetworks.com/strelastealer-campaign/
Large-Scale StrelaStealer Campaign in Early 2024

US Treasury Slaps Sanctions on China-Linked APT31 Hackers - SecurityWeek

https://www.securityweek.com/us-treasury-slaps-sanctions-on-china-linked-apt31-hackers/
US Treasury Slaps Sanctions on China-Linked APT31 Hackers - SecurityWeek

CISA urges software devs to weed out SQL injection vulnerabilities

https://www.bleepingcomputer.com/news/security/cisa-urges-software-devs-to-weed-out-sql-injection-vulnerabilities/
CISA urges software devs to weed out SQL injection vulnerabilities

StrelaStealer targeted 100+ organizations across the EU and US

https://securityaffairs.com/161022/cyber-crime/strelastealer-malware-eu-us.html
StrelaStealer targeted 100+ organizations across the EU and US

Panera Bread experiencing nationwide IT outage since Saturday

https://www.bleepingcomputer.com/news/security/panera-bread-experiencing-nationwide-it-outage-since-saturday/
Panera Bread experiencing nationwide IT outage since Saturday

Over 100 US and EU orgs targeted in StrelaStealer malware attacks

https://www.bleepingcomputer.com/news/security/over-100-us-and-eu-orgs-targeted-in-strelastealer-malware-attacks/
Over 100 US and EU orgs targeted in StrelaStealer malware attacks

US sanctions APT31 hackers behind critical infrastructure attacks

https://www.bleepingcomputer.com/news/security/us-sanctions-apt31-hackers-behind-critical-infrastructure-attacks/
US sanctions APT31 hackers behind critical infrastructure attacks

Your Pocket Guide to OPSEC in Adversary Emulation - RistBS's Blog

https://ristbs.github.io/2023/02/08/your-pocket-guide-to-opsec-in-adversary-emulation.html
Your Pocket Guide to OPSEC in Adversary Emulation - RistBS's Blog

Windows Server memory leak in patch confirmed by Microsoft • The Register

https://go.theregister.com/feed/www.theregister.com/2024/03/25/microsoft_confirms_memory_leak_in/
Windows Server memory leak in patch confirmed by Microsoft • The Register

Top Python Developers Hacked in Sophisticated Supply Chain Attack - SecurityWeek

https://www.securityweek.com/top-python-developers-hacked-in-sophisticated-supply-chain-attack/
Top Python Developers Hacked in Sophisticated Supply Chain Attack - SecurityWeek

Vans warns customers of data breach | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/03/vans-warns-customers-of-data-breach
Vans warns customers of data breach | Malwarebytes

Over 100 Organizations Targeted in Recent 'StrelaStealer' Attacks - SecurityWeek

https://www.securityweek.com/over-100-organizations-targeted-in-recent-strelastealer-attacks/
Over 100 Organizations Targeted in Recent 'StrelaStealer' Attacks - SecurityWeek