09/27

Attacking UNIX Systems via CUPS, Part I

https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/
Attacking UNIX Systems via CUPS, Part I

CVE-2024-6769: Poisoning the Activation Cache to Elevate From Medium to High Integrity | Fortra

https://www.fortra.com/blog/cve-2024-6769-poisoning-activation-cache-elevate-medium-high-integrity
CVE-2024-6769: Poisoning the Activation Cache to Elevate From Medium to High Integrity | Fortra

Microsoft: Windows Recall now can be removed, is more secure

https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-recall-now-can-be-removed-is-more-secure/
Microsoft: Windows Recall now can be removed, is more secure

OrangeCon - Slides OrangeCon2024

https://orangecon.nl/slides
OrangeCon - Slides OrangeCon2024

Shodan Search Engine

https://www.shodan.io/search/report?query=product%3Acups
Shodan Search Engine

Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks

https://thehackernews.com/2024/09/microsoft-identifies-storm-0501-as.html
Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks

Hacking Kia cars made after 2013 using just their license plate

https://securityaffairs.com/168966/hacking/hacking-kia-cars-made-after-2013.html
Hacking Kia cars made after 2013 using just their license plate

Five Eyes Agencies Release Guidance on Detecting Active Directory Intrusions - SecurityWeek

https://www.securityweek.com/five-eyes-agencies-release-guidance-on-detecting-active-directory-intrusions/
Five Eyes Agencies Release Guidance on Detecting Active Directory Intrusions - SecurityWeek

Embargo ransomware escalates attacks to cloud environments

https://www.bleepingcomputer.com/news/security/embargo-ransomware-escalates-attacks-to-cloud-environments/
Embargo ransomware escalates attacks to cloud environments

Storm-0501: Ransomware attacks expanding to hybrid cloud environments | Microsoft Security Blog

https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/
Storm-0501: Ransomware attacks expanding to hybrid cloud environments | Microsoft Security Blog

Kia dealer portal flaw could let attackers hack millions of cars

https://www.bleepingcomputer.com/news/security/kia-dealer-portal-flaw-could-let-attackers-hack-millions-of-cars/
Kia dealer portal flaw could let attackers hack millions of cars

Hybrid Analysis Blog: Analyzing the Newest Turla Backdoor Through the Eyes of Hybrid Analysis

https://hybrid-analysis.blogspot.com/2024/09/analyzing-newest-turla-backdoor-through.html
Hybrid Analysis Blog: Analyzing the Newest Turla Backdoor Through the Eyes of Hybrid Analysis

Progress urges admins to patch critical WhatsUp Gold bugs ASAP

https://www.bleepingcomputer.com/news/security/progress-urges-admins-to-patch-critical-whatsup-gold-bugs-asap/
Progress urges admins to patch critical WhatsUp Gold bugs ASAP

Tails OS merges with Tor Project for better privacy, security

https://www.bleepingcomputer.com/news/software/tails-os-merges-with-tor-project-for-better-privacy-security/
Tails OS merges with Tor Project for better privacy, security

Iranian hackers charged for ‘hack-and-leak’ plot to influence election

https://www.bleepingcomputer.com/news/security/iranian-hackers-charged-for-hack-and-leak-plot-to-influence-election/
Iranian hackers charged for ‘hack-and-leak’ plot to influence election

Meta Hit With $102 Million Privacy Fine From European Union Over 2019 Password Security Lapse - SecurityWeek

https://www.securityweek.com/meta-hit-with-102-million-privacy-fine-from-european-union-over-2019-password-security-apse/
Meta Hit With $102 Million Privacy Fine From European Union Over 2019 Password Security Lapse - SecurityWeek

CUPS flaws enable Linux remote code execution, but there’s a catch

https://www.bleepingcomputer.com/news/security/cups-flaws-enable-linux-remote-code-execution-but-theres-a-catch/
CUPS flaws enable Linux remote code execution, but there’s a catch

Controversial Windows Recall AI Search Tool Returns With Proof-of-Presence Encryption, Data Isolation - SecurityWeek

https://www.securityweek.com/microsofts-controversial-recall-returns-with-proof-of-presence-encryption-data-isolation-opt-in-model/
Controversial Windows Recall AI Search Tool Returns With Proof-of-Presence Encryption, Data Isolation - SecurityWeek

New HTML Smuggling Campaign Delivers DCRat Malware to Russian-Speaking Users

https://thehackernews.com/2024/09/new-html-smuggling-campaign-delivers.html
New HTML Smuggling Campaign Delivers DCRat Malware to Russian-Speaking Users

Critical RCE vulnerability found in OpenPLC - Security Affairs

https://securityaffairs.com/168953/ics-scada/openplc-critical-flaw.html
Critical RCE vulnerability found in OpenPLC - Security Affairs

A Deep Dive into the CoSoSys EndPoint Protector Exploit: Remote Code Execution | by Theori Security Assessment | Aug, 2024 | Theori BLOG

https://blog.theori.io/a-deep-dive-into-the-cososys-endpoint-protector-exploit-remote-code-execution-6c0f6b791f4e
A Deep Dive into the CoSoSys EndPoint Protector Exploit: Remote Code Execution | by Theori Security Assessment | Aug, 2024 | Theori BLOG

Highly Anticipated Linux Flaw Allows Remote Code Execution, but Less Serious Than Expected - SecurityWeek

https://www.securityweek.com/highly-anticipated-linux-flaw-allows-remote-code-execution-but-less-serious-than-expected/
Highly Anticipated Linux Flaw Allows Remote Code Execution, but Less Serious Than Expected - SecurityWeek

Man arrested over rail station wi-fi terror messages cyber hack

https://www.bbc.co.uk/news/articles/c1jd5k8x4y4o
Man arrested over rail station wi-fi terror messages cyber hack

Page not found · GitHub · GitHub

http://github.com/bettercap/bettercap/v2@master
Page not found · GitHub · GitHub

U.S. Sanctions Two Crypto Exchanges for Facilitating Cybercrime and Money Laundering

https://thehackernews.com/2024/09/us-sanctions-two-crypto-exchanges-for.html
U.S. Sanctions Two Crypto Exchanges for Facilitating Cybercrime and Money Laundering

Sophistication of AI-Backed Operation Targeting Senator Points to Future of Deepfake Schemes - SecurityWeek

https://www.securityweek.com/sophistication-of-ai-backed-operation-targeting-senator-points-to-future-of-deepfake-schemes/
Sophistication of AI-Backed Operation Targeting Senator Points to Future of Deepfake Schemes - SecurityWeek

U.S. charges Joker's Stash and Rescator money launderers

https://www.bleepingcomputer.com/news/legal/us-charges-jokers-stash-and-rescator-money-launderers/
U.S. charges Joker's Stash and Rescator money launderers