05/22

Microsoft to start killing off VBScript in second half of 2024

https://www.bleepingcomputer.com/news/microsoft/microsoft-to-start-killing-off-vbscript-in-second-half-of-2024/
Microsoft to start killing off VBScript in second half of 2024

Microsoft's new Windows 11 Recall is a privacy nightmare

https://www.bleepingcomputer.com/news/microsoft/microsofts-new-windows-11-recall-is-a-privacy-nightmare/
Microsoft's new Windows 11 Recall is a privacy nightmare

Chinese hackers hide on military and govt networks for 6 years

https://www.bleepingcomputer.com/news/security/unfading-sea-haze-hackers-hide-on-military-and-govt-networks-for-6-years/
Chinese hackers hide on military and govt networks for 6 years

Veeam warns of critical Backup Enterprise Manager auth bypass bug

https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-backup-enterprise-manager-auth-bypass-bug/
Veeam warns of critical Backup Enterprise Manager auth bypass bug

Fuzzing and Attacking Custom Embedded Systems

https://ringzer0.training/doubledown24-fuzzing-and-attacking-custom-embedded-systems/
Fuzzing and Attacking Custom Embedded Systems

Master of Puppets: Uncovering the DoppelGänger pro-Russian influence campaign

https://blog.sekoia.io/master-of-puppets-uncovering-the-doppelganger-pro-russian-influence-campaign/
Master of Puppets: Uncovering the DoppelGänger pro-Russian influence campaign

Rockwell Automation Urges Customers to Disconnect ICS From Internet - SecurityWeek

https://www.securityweek.com/rockwell-automation-urges-customers-to-disconnect-ics-from-internet/
Rockwell Automation Urges Customers to Disconnect ICS From Internet - SecurityWeek

Criminal record database of millions of Americans dumped online | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/05/criminal-record-database-of-millions-of-americans-dumped-online
Criminal record database of millions of Americans dumped online | Malwarebytes

Intercontinental Exchange to pay $10M SEC penalty over VPN breach

https://www.bleepingcomputer.com/news/security/intercontinental-exchange-to-pay-10m-sec-penalty-over-vpn-breach/
Intercontinental Exchange to pay $10M SEC penalty over VPN breach

MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks

https://thehackernews.com/2024/05/ms-exchange-server-flaws-exploited-to.html
MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks

malware-research/DarkGate/darkgate_v6_config_extractor.py at main · leandrofroes/malware-research · GitHub

https://github.com/leandrofroes/malware-research/blob/main/DarkGate/darkgate_v6_config_extractor.py
malware-research/DarkGate/darkgate_v6_config_extractor.py at main · leandrofroes/malware-research · GitHub

Cyphercon VI Presentation Goodies! | Sprocket Security

https://www.sprocketsecurity.com/cyphercon
Cyphercon VI Presentation Goodies! | Sprocket Security

QNAP Patches New Flaws in QTS and QuTS hero Impacting NAS Appliances

https://thehackernews.com/2024/05/qnap-patches-new-flaws-in-qts-and-quts.html
QNAP Patches New Flaws in QTS and QuTS hero Impacting NAS Appliances

Hackers Sell Fake Pegasus Spyware on Clearnet and Dark Web

https://www.hackread.com/threat-actors-spoofing-pegasus-spyware-fake-code/
Hackers Sell Fake Pegasus Spyware on Clearnet and Dark Web

Critical Vulnerability in Honeywell Virtual Controller Allows Remote Code Execution - SecurityWeek

https://www.securityweek.com/critical-vulnerability-in-honeywell-virtual-controller-allows-remote-code-execution/
Critical Vulnerability in Honeywell Virtual Controller Allows Remote Code Execution - SecurityWeek

New Windows 11 features strengthen security to address evolving cyberthreat landscape | Microsoft Security Blog

https://www.microsoft.com/en-us/security/blog/2024/05/20/new-windows-11-features-strengthen-security-to-address-evolving-cyberthreat-landscape/
New Windows 11 features strengthen security to address evolving cyberthreat landscape | Microsoft Security Blog

OmniVision disclosed a data breach after the 2023 Cactus ransomware attack

https://securityaffairs.com/163506/data-breach/omnivision-data-breach.html
OmniVision disclosed a data breach after the 2023 Cactus ransomware attack

Zoom Adopts NIST-Approved Post-Quantum End-to-End Encryption for Meetings

https://thehackernews.com/2024/05/zoom-adopts-nist-approved-post-quantum.html
Zoom Adopts NIST-Approved Post-Quantum End-to-End Encryption for Meetings

GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking Attack

https://thehackernews.com/2024/05/ghostengine-exploits-vulnerable-drivers.html
GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking Attack

Critical Authentication Bypass Resolved in GitHub Enterprise Server - SecurityWeek

https://www.securityweek.com/critical-authentication-bypass-resolved-in-github-enterprise-server/
Critical Authentication Bypass Resolved in GitHub Enterprise Server - SecurityWeek

Getting XXE in Web Browsers using ChatGPT – PT SWARM

https://swarm.ptsecurity.com/xxe-chrome-safari-chatgpt/
Getting XXE in Web Browsers using ChatGPT – PT SWARM

IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders | Google Cloud Blog

https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks/
IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders | Google Cloud Blog

US to Invest $50 Million in Securing Hospitals Against Cyber Threats - SecurityWeek

https://www.securityweek.com/us-to-invest-50-million-in-securing-hospitals-against-cyber-threats/
US to Invest $50 Million in Securing Hospitals Against Cyber Threats - SecurityWeek

Critical Veeam Vulnerability Leads to Authentication Bypass - SecurityWeek

https://www.securityweek.com/critical-veeam-vulnerability-leads-to-authentication-bypass/
Critical Veeam Vulnerability Leads to Authentication Bypass - SecurityWeek

Rockwell Advises Disconnecting Internet-Facing ICS Devices Amid Cyber Threats

https://thehackernews.com/2024/05/rockwell-advises-disconnecting-internet.html
Rockwell Advises Disconnecting Internet-Facing ICS Devices Amid Cyber Threats

Researchers Warn of Chinese-Aligned Hackers Targeting South China Sea Countries

https://thehackernews.com/2024/05/researchers-warn-of-chinese-aligned.html
Researchers Warn of Chinese-Aligned Hackers Targeting South China Sea Countries

A malware campaign exploits Microsoft Exchange Server flaws

https://securityaffairs.com/163521/breaking-news/microsoft-exchange-server-flaws-attacks.html
A malware campaign exploits Microsoft Exchange Server flaws