05/21

Call for papers is now open for hack.lu 2024 - hack.lu 2024

https://2024.hack.lu/blog/hack.lu-2024-call-for-papers/
Call for papers is now open for hack.lu 2024 - hack.lu 2024

VirusTotal - File - da1a50f6d6ec5e3321ec1d98055dff1b522d0d34eb7b0e00138df6beee17001d

https://www.virustotal.com/gui/file/da1a50f6d6ec5e3321ec1d98055dff1b522d0d34eb7b0e00138df6beee17001d
VirusTotal - File - da1a50f6d6ec5e3321ec1d98055dff1b522d0d34eb7b0e00138df6beee17001d

CVE-2024-4985 (CVSS 10): Critical Authentication Bypass Flaw Found in GitHub Enterprise Server

https://securityonline.info/cve-2024-4985-cvss-10-critical-authentication-bypass-flaw-found-in-github-enterprise-server/
CVE-2024-4985 (CVSS 10): Critical Authentication Bypass Flaw Found in GitHub Enterprise Server

Zoom adds post-quantum end-to-end encryption to video meetings

https://www.bleepingcomputer.com/news/security/zoom-adds-post-quantum-end-to-end-encryption-to-video-meetings/
Zoom adds post-quantum end-to-end encryption to video meetings

Windows 11 to Deprecate NTLM, Add AI-Powered App Controls and Security Defenses

https://thehackernews.com/2024/05/windows-11-to-deprecate-ntlm-add-ai.html
Windows 11 to Deprecate NTLM, Add AI-Powered App Controls and Security Defenses

Rockwell Automation warns admins to take ICS devices offline

https://www.bleepingcomputer.com/news/security/rockwell-automation-warns-admins-to-take-ics-devices-offline/
Rockwell Automation warns admins to take ICS devices offline

Malwarebytes on X: "Cool cool cool. 🫠 https://t.co/T6U2jQTIld" / X

https://x.com/Malwarebytes/status/1792925823256735871
Malwarebytes on X: "Cool cool cool. 🫠 https://t.co/T6U2jQTIld" / X

GitHub warns of SAML auth bypass flaw in Enterprise Server

https://www.bleepingcomputer.com/news/security/github-warns-of-saml-auth-bypass-flaw-in-enterprise-server/
GitHub warns of SAML auth bypass flaw in Enterprise Server

Windows 11 Recall AI feature will record everything you do on your PC

https://www.bleepingcomputer.com/news/microsoft/windows-11-recall-ai-feature-will-record-everything-you-do-on-your-pc/
Windows 11 Recall AI feature will record everything you do on your PC

ZAP – Introducing the gRPC Add-on

https://www.zaproxy.org/blog/2024-05-21-introducing-the-grpc-addon/
ZAP – Introducing the gRPC Add-on

NextGen Healthcare Mirth Connect Under Attack - CISA Issues Urgent Warning

https://thehackernews.com/2024/05/nextgen-healthcare-mirth-connect-under.html
NextGen Healthcare Mirth Connect Under Attack - CISA Issues Urgent Warning

Malware Delivery via Cloud Services Exploits Unicode Trick to Deceive Users

https://thehackernews.com/2024/05/malware-delivery-via-cloud-services.html
Malware Delivery via Cloud Services Exploits Unicode Trick to Deceive Users

New Windows 11 features strengthen security to address evolving cyberthreat landscape | Microsoft Security Blog

https://www.microsoft.com/en-us/security/blog/2024/05/20/new-windows-11-features-strengthen-security-to-address-evolving-cyberthreat-landscape/
New Windows 11 features strengthen security to address evolving cyberthreat landscape | Microsoft Security Blog

Abusing url handling in iTerm2 and Hyper for code execution | Vin01’s Blog

https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html
Abusing url handling in iTerm2 and Hyper for code execution | Vin01’s Blog

SolarMarker Malware Evolves to Resist Takedown Attempts with Multi-Tiered Infrastructure

https://thehackernews.com/2024/05/solarmarker-malware-evolves-to-resist.html
SolarMarker Malware Evolves to Resist Takedown Attempts with Multi-Tiered Infrastructure

OmniVision Says Personal Information Stolen in Ransomware Attack - SecurityWeek

https://www.securityweek.com/omnivision-says-personal-information-stolen-in-ransomware-attack/
OmniVision Says Personal Information Stolen in Ransomware Attack - SecurityWeek

Hi Meta, WhatsApp with Integrity? | by Tal Be'ery | May, 2024 | Medium

https://medium.com/@TalBeerySec/hi-meta-whatsapp-with-integrity-4d85756dd7c5
Hi Meta, WhatsApp with Integrity? | by Tal Be'ery | May, 2024 | Medium

Blackbasta group claims to have hacked Atlas, one of the largest US oil distributors

https://securityaffairs.com/163489/cyber-crime/blackbasta-claims-atlas-hack.html
Blackbasta group claims to have hacked Atlas, one of the largest US oil distributors

Critical GitHub Enterprise Server Flaw Allows Authentication Bypass

https://thehackernews.com/2024/05/critical-github-enterprise-server-flaw.html
Critical GitHub Enterprise Server Flaw Allows Authentication Bypass

"Linguistic Lumberjack" Vulnerability Discovered in Popular Logging Utility Fluent Bit

https://thehackernews.com/2024/05/linguistic-lumberjack-vulnerability.html
"Linguistic Lumberjack" Vulnerability Discovered in Popular Logging Utility Fluent Bit