04/16

Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400)

https://labs.watchtowr.com/palo-alto-putting-the-protecc-in-globalprotect-cve-2024-3400/
Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400)

Justin Elze on LinkedIn: Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400)

https://www.linkedin.com/posts/justinelze_palo-alto-putting-the-protecc-in-globalprotect-activity-7186009203759624192-RTle
Justin Elze on LinkedIn: Palo Alto - Putting The Protecc In GlobalProtect (CVE-2024-3400)

Cisco warns of large-scale brute-force attacks against VPN services

https://www.bleepingcomputer.com/news/security/cisco-warns-of-large-scale-brute-force-attacks-against-vpn-services/
Cisco warns of large-scale brute-force attacks against VPN services

FTC Fines Mental Health Startup Cerebral $7 Million for Major Privacy Violations

https://thehackernews.com/2024/04/ftc-fines-mental-health-startup.html
FTC Fines Mental Health Startup Cerebral $7 Million for Major Privacy Violations

OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

https://thehackernews.com/2024/04/openjs-foundation-targeted-in-potential.html
OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

Release 0.12.0 · AFLplusplus/LibAFL · GitHub

https://github.com/AFLplusplus/LibAFL/releases/tag/0.12.0
Release 0.12.0 · AFLplusplus/LibAFL · GitHub

Palo Alto Networks Senior Manager, Malware Reverse Engineering | SmartRecruiters

https://jobs.smartrecruiters.com/PaloAltoNetworks2/743999980896644-senior-manager-malware-reverse-engineering
Palo Alto Networks Senior Manager, Malware Reverse Engineering | SmartRecruiters

Exploit released for Palo Alto PAN-OS bug used in attacks, patch now

https://www.bleepingcomputer.com/news/security/exploit-released-for-palo-alto-pan-os-bug-used-in-attacks-patch-now/
Exploit released for Palo Alto PAN-OS bug used in attacks, patch now

PuTTY SSH client flaw allows recovery of cryptographic private keys

https://www.bleepingcomputer.com/news/security/putty-ssh-client-flaw-allows-recovery-of-cryptographic-private-keys/
PuTTY SSH client flaw allows recovery of cryptographic private keys

LOTP - Living Off the Pipeline

https://boostsecurityio.github.io/lotp/
LOTP - Living Off the Pipeline

New SteganoAmor attacks use steganography to target 320 orgs globally

https://www.bleepingcomputer.com/news/security/new-steganoamor-attacks-use-steganography-to-target-320-orgs-globally/
New SteganoAmor attacks use steganography to target 320 orgs globally

Hive RAT Creators and $3.5M Cryptojacking Mastermind Arrested in Global Crackdown

https://thehackernews.com/2024/04/hive-rat-creators-and-35m-cryptojacking.html
Hive RAT Creators and $3.5M Cryptojacking Mastermind Arrested in Global Crackdown

Google to crack down on third-party YouTube apps that block ads

https://www.bleepingcomputer.com/news/google/google-to-crack-down-on-third-party-youtube-apps-that-block-ads/
Google to crack down on third-party YouTube apps that block ads

TA558 Hackers Weaponize Images for Wide-Scale Malware Attacks

https://thehackernews.com/2024/04/ta558-hackers-weaponize-images-for-wide.html
TA558 Hackers Weaponize Images for Wide-Scale Malware Attacks

GitHub - BC-SECURITY/IronSharpPack

https://github.com/BC-SECURITY/IronSharpPack
GitHub - BC-SECURITY/IronSharpPack

Giant Tiger breach sees 2.8 million records leaked | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/04/giant-tiger-breach-sees-2-8-million-records-leaked
Giant Tiger breach sees 2.8 million records leaked | Malwarebytes

Ransomware group Dark Angels claims the theft of 1TB of data from chipmaker Nexperia 

https://securityaffairs.com/161888/cyber-crime/ransomware-dark-angels-nexperia.html
Ransomware group Dark Angels claims the theft of 1TB of data from chipmaker Nexperia 

CVE-2024-31497: Critical PuTTY Vulnerability Exposes Private Keys – Immediate Action Required

https://securityonline.info/cve-2024-31497-critical-putty-vulnerability-exposes-private-keys-immediate-action-required/
CVE-2024-31497: Critical PuTTY Vulnerability Exposes Private Keys – Immediate Action Required

From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering  | Proofpoint US

https://www.proofpoint.com/us/blog/threat-insight/social-engineering-dmarc-abuse-ta427s-art-information-gathering
From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering  | Proofpoint US

Omni Hotels Says Personal Information Stolen in Ransomware Attack - SecurityWeek

https://www.securityweek.com/omni-hotels-says-personal-information-stolen-in-ransomware-attack/
Omni Hotels Says Personal Information Stolen in Ransomware Attack - SecurityWeek

AWS, Google, and Azure CLI Tools Could Leak Credentials in Build Logs

https://thehackernews.com/2024/04/aws-google-and-azure-cli-tools-could.html
AWS, Google, and Azure CLI Tools Could Leak Credentials in Build Logs

You've been invited to participate in a short test.

https://usabi.li/do/a5a9593efa04/789f
You've been invited to participate in a short test.

Ivanti warns of critical flaws in its Avalanche MDM solution

https://www.bleepingcomputer.com/news/security/ivanti-warns-of-critical-flaws-in-its-avalanche-mdm-solution/
Ivanti warns of critical flaws in its Avalanche MDM solution