07/18

Critical Cisco bug lets hackers add root users on SEG devices

https://www.bleepingcomputer.com/news/security/critical-cisco-bug-lets-hackers-add-root-users-on-seg-devices/
Critical Cisco bug lets hackers add root users on SEG devices

Fun with Exception Handlers | Ya boy Manny

https://mannyfreddy.gitbook.io/ya-boy-manny#fun-with-exception-handlers
Fun with Exception Handlers | Ya boy Manny

SolarWinds fixes 8 critical bugs in access rights audit software

https://www.bleepingcomputer.com/news/security/solarwinds-fixes-8-critical-bugs-in-access-rights-audit-software/
SolarWinds fixes 8 critical bugs in access rights audit software

Linux Kernel: Vulnerability in the eBPF verifier register limit tracking · Advisory · google/security-research · GitHub

https://github.com/google/security-research/security/advisories/GHSA-hfqc-63c7-rj9f#event-251168
Linux Kernel: Vulnerability in the eBPF verifier register limit tracking · Advisory · google/security-research · GitHub

HotPage: Story of a signed, vulnerable, ad-injecting driver

https://www.welivesecurity.com/en/eset-research/hotpage-story-signed-vulnerable-ad-injecting-driver/
HotPage: Story of a signed, vulnerable, ad-injecting driver

Alert: HotPage Adware Disguised as Ad Blocker Installs Malicious Kernel Driver

https://thehackernews.com/2024/07/alert-hotpage-adware-disguised-as-ad.html
Alert: HotPage Adware Disguised as Ad Blocker Installs Malicious Kernel Driver

FIN7 group advertises new EDR bypass tool on hacking forums

https://securityaffairs.com/165863/cyber-crime/fin7-advertising-security-evasion.html
FIN7 group advertises new EDR bypass tool on hacking forums

China/France/United States : Chengdu 404's hiring spree, Siren at NYPD, RAID buys Chinese drones

https://www.intelligenceonline.com/surveillance--interception/2024/07/18/chengdu-404-s-hiring-spree-siren-at-nypd-raid-buys-chinese-drones,110269612-art
China/France/United States : Chengdu 404's hiring spree, Siren at NYPD, RAID buys Chinese drones

Gen Z breakups tainted by login abuse for spying and stalking, research shows | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/07/gen-z-breakups-tainted-by-login-abuse-for-spying-and-stalking-research-shows
Gen Z breakups tainted by login abuse for spying and stalking, research shows | Malwarebytes

Coker’s top priorities: Federal cohesion, cyber workforce, other ‘hard problems’ | CyberScoop

https://cyberscoop.com/cokers-top-priorities-federal-cohesion-cyber-workforce-other-hard-problems/
Coker’s top priorities: Federal cohesion, cyber workforce, other ‘hard problems’ | CyberScoop

Port Shadow Attack Allows VPN Traffic Interception, Redirection - SecurityWeek

https://www.securityweek.com/port-shadow-attack-allows-vpn-traffic-interception-redirection/
Port Shadow Attack Allows VPN Traffic Interception, Redirection - SecurityWeek

Notorious FIN7 hackers sell EDR killer to other threat actors

https://www.bleepingcomputer.com/news/security/notorious-fin7-hackers-sell-edr-killer-to-other-threat-actors/
Notorious FIN7 hackers sell EDR killer to other threat actors

Hackers could create traffic jams thanks to flaw in traffic light controller, researcher says | TechCrunch

https://techcrunch.com/2024/07/18/hackers-could-create-traffic-jams-thanks-to-flaw-in-traffic-light-controller-researcher-says/
Hackers could create traffic jams thanks to flaw in traffic light controller, researcher says | TechCrunch

SAPwned flaws in SAP AI core could expose customers' data

https://securityaffairs.com/165888/hacking/sap-ai-core-sapwned.html
SAPwned flaws in SAP AI core could expose customers' data

TAG-100: New Threat Actor Uses Open-Source Tools for Widespread Attacks

https://thehackernews.com/2024/07/tag-100-new-threat-actor-uses-open.html
TAG-100: New Threat Actor Uses Open-Source Tools for Widespread Attacks

Automated Threats Pose Increasing Risk to the Travel Industry

https://thehackernews.com/2024/07/automated-threats-pose-increasing-risk.html
Automated Threats Pose Increasing Risk to the Travel Industry

Over 400,000 Life360 user phone numbers leaked via unsecured API

https://www.bleepingcomputer.com/news/security/over-400-000-life360-user-phone-numbers-leaked-via-unsecured-android-api/
Over 400,000 Life360 user phone numbers leaked via unsecured API

Cisco Warns of Critical Flaw Affecting On-Prem Smart Software Manager

https://thehackernews.com/2024/07/cisco-warns-of-critical-flaw-affecting.html
Cisco Warns of Critical Flaw Affecting On-Prem Smart Software Manager

GitHub - interruptlabs/jadx-collaboration

https://github.com/interruptlabs/jadx-collaboration
GitHub - interruptlabs/jadx-collaboration

SAP AI Core Vulnerabilities Expose Customer Data to Cyber Attacks

https://thehackernews.com/2024/07/sap-ai-core-vulnerabilities-expose.html
SAP AI Core Vulnerabilities Expose Customer Data to Cyber Attacks

Meta Halts AI Use in Brazil Following Data Protection Authority's Ban

https://thehackernews.com/2024/07/meta-halts-ai-use-in-brazil-following.html
Meta Halts AI Use in Brazil Following Data Protection Authority's Ban

Ivanti Issues Hotfix for High-Severity Endpoint Manager Vulnerability - SecurityWeek

https://www.securityweek.com/ivanti-issues-hotfix-for-high-severity-endpoint-manager-vulnerability/
Ivanti Issues Hotfix for High-Severity Endpoint Manager Vulnerability - SecurityWeek