09/02

Admins of MFA bypass service plead guilty to fraud

https://www.bleepingcomputer.com/news/legal/admins-of-mfa-bypass-service-otp.agency-plead-guilty/
Admins of MFA bypass service plead guilty to fraud

Transport for London discloses ongoing “cyber security incident”

https://www.bleepingcomputer.com/news/security/transport-for-london-discloses-ongoing-cyber-security-incident/
Transport for London discloses ongoing “cyber security incident”

Business services giant CBIZ discloses customer data breach

https://www.bleepingcomputer.com/news/security/business-services-giant-cbiz-discloses-customer-data-breach/
Business services giant CBIZ discloses customer data breach

Owners of 1-Time Passcode Theft Service Plead Guilty – Krebs on Security

https://krebsonsecurity.com/2024/09/owners-of-1-time-passcode-theft-service-plead-guilty/
Owners of 1-Time Passcode Theft Service Plead Guilty – Krebs on Security

Thread Name-Calling - using Thread Name for offense - Check Point Research

https://research.checkpoint.com/2024/thread-name-calling-using-thread-name-for-offense/
Thread Name-Calling - using Thread Name for offense - Check Point Research

Verkada to pay $2.95M for security failures leading to breaches

https://www.bleepingcomputer.com/news/security/verkada-to-pay-295m-for-security-failures-leading-to-breaches/
Verkada to pay $2.95M for security failures leading to breaches

Firmware Security: Alcatel-Lucent ALE-DeskPhone | SySS Tech Blog

https://blog.syss.com/posts/voip-deskphone-firmware-security/
Firmware Security: Alcatel-Lucent ALE-DeskPhone | SySS Tech Blog

mskssrv.sys - CVE-2023–29360 | Researchs

https://seg-fault.gitbook.io/researchs/windows-security-research/exploit-development/mskssrv.sys-cve-2023-29360
mskssrv.sys - CVE-2023–29360 | Researchs

Malicious npm Packages Mimicking 'noblox.js' Compromise Roblox Developers' Systems

https://thehackernews.com/2024/09/malicious-npm-packages-mimicking.html
Malicious npm Packages Mimicking 'noblox.js' Compromise Roblox Developers' Systems

The Malware That Must Not Be Named: Suspected Espionage Campaign Delivers “Voldemort” | Proofpoint US

https://www.proofpoint.com/us/blog/threat-insight/malware-must-not-be-named-suspected-espionage-campaign-delivers-voldemort
The Malware That Must Not Be Named: Suspected Espionage Campaign Delivers “Voldemort” | Proofpoint US

US24-Sialveras-Bugs-Of-Yore-Wednesday.pdf

https://i.blackhat.com/BH-US-24/Presentations/US24-Sialveras-Bugs-Of-Yore-Wednesday.pdf
US24-Sialveras-Bugs-Of-Yore-Wednesday.pdf

Cyber Espionage Campaign Leverages Novel Tactics and “Voldemort” Malware to Target Global Organizations

https://securityonline.info/cyber-espionage-campaign-leverages-novel-tactics-and-voldemort-malware-to-target-global-organizations/
Cyber Espionage Campaign Leverages Novel Tactics and “Voldemort” Malware to Target Global Organizations

Breaking Down Barriers: Exploiting Pre-Auth SQL Injection in WhatsUp Gold

https://summoning.team/blog/progress-whatsup-gold-sqli-cve-2024-6670/
Breaking Down Barriers: Exploiting Pre-Auth SQL Injection in WhatsUp Gold

blog | The public blog of Santander Cyber Security Research

https://santandersecurityresearch.github.io/blog/sshing_the_masses.html
blog | The public blog of Santander Cyber Security Research

Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969) | STAR Labs

https://starlabs.sg/blog/2023/11-exploitation-of-a-kernel-pool-overflow-from-a-restrictive-chunk-size-cve-2021-31969/
Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969) | STAR Labs