12/17

Bitter APT Targets Turkish Defense Sector with WmRAT and MiyaRAT Malware

https://thehackernews.com/2024/12/bitter-apt-targets-turkish-defense.html
Bitter APT Targets Turkish Defense Sector with WmRAT and MiyaRAT Malware

The Full Story of CVE-2024-6386: Remote Code Execution in WPML - WPSec

https://blog.wpsec.com/the-full-story-of-cve-2024-6386-remote-code-execution-in-wpml/
The Full Story of CVE-2024-6386: Remote Code Execution in WPML - WPSec

Cisco Intends to Acquire Threat Detection and Defense Company SnapAttack, Driving Further Splunk Innovation to Power the SOC of the Future | Splunk

https://www.splunk.com/en_us/blog/security/cisco-intends-to-acquire-threat-detection-and-defense-company-snapattack.html?locale=en_us
Cisco Intends to Acquire Threat Detection and Defense Company SnapAttack, Driving Further Splunk Innovation to Power the SOC of the Future | Splunk

Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware

https://thehackernews.com/2024/12/attackers-exploit-microsoft-teams-and.html
Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware

Hackers exploit critical Apache Struts RCE flaw (CVE-2024-53677) after PoC exploit release

https://securityonline.info/hackers-exploit-critical-apache-struts-rce-flaw-cve-2024-53677-after-poc-exploit-release/
Hackers exploit critical Apache Struts RCE flaw (CVE-2024-53677) after PoC exploit release

Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks | Trend Micro (NO)

https://www.trendmicro.com/en_no/research/24/l/earth-koshchei.html
Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks | Trend Micro (NO)

Over 25,000 SonicWall VPN Firewalls exposed to critical flaws

https://www.bleepingcomputer.com/news/security/over-25-000-sonicwall-vpn-firewalls-exposed-to-critical-flaws/
Over 25,000 SonicWall VPN Firewalls exposed to critical flaws

Kali Linux 2024.4 released with 14 new tools, deprecates some features

https://www.bleepingcomputer.com/news/security/kali-linux-20244-released-with-14-new-tools-deprecates-some-features/
Kali Linux 2024.4 released with 14 new tools, deprecates some features

How to disable Run Command (Win+R) box in Windows 11/10

https://www.thewindowsclub.com/enable-or-disable-run-command-winr-box-in-windows-10
How to disable Run Command (Win+R) box in Windows 11/10

FBI warns of HiatusRAT scanning campaigns against Chinese-branded web cameras and DVRs

https://securityaffairs.com/172074/malware/fbi-warns-of-hiatusrat-scanning-campaigns.html
FBI warns of HiatusRAT scanning campaigns against Chinese-branded web cameras and DVRs

Texas Tech University Data Breach Impacts 1.4 Million People - SecurityWeek

https://www.securityweek.com/texas-tech-university-data-breach-impacts-1-4-million-people/
Texas Tech University Data Breach Impacts 1.4 Million People - SecurityWeek

New fake Ledger data breach emails try to steal crypto wallets

https://www.bleepingcomputer.com/news/security/new-fake-ledger-data-breach-emails-try-to-steal-crypto-wallets/
New fake Ledger data breach emails try to steal crypto wallets

Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection

https://thehackernews.com/2024/12/hackers-exploit-webview2-to-deploy.html
Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection

Windows kernel bug now exploited in attacks to gain SYSTEM privileges

https://www.bleepingcomputer.com/news/security/windows-kernel-bug-now-exploited-in-attacks-to-gain-system-privileges/
Windows kernel bug now exploited in attacks to gain SYSTEM privileges

Ireland fines Meta $264 million over 2018 Facebook data breach

https://www.bleepingcomputer.com/news/security/ireland-fines-meta-264-million-over-2018-facebook-data-breach/
Ireland fines Meta $264 million over 2018 Facebook data breach

Apache Struts2 文件上传逻辑绕过(CVE-2024-53677)(S2-067)

https://y4tacker.github.io/2024/12/16/year/2024/12/Apache-Struts2-%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E9%80%BB%E8%BE%91%E7%BB%95%E8%BF%87-CVE-2024-53677-S2-067/
Apache Struts2 文件上传逻辑绕过(CVE-2024-53677)(S2-067)

Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks

https://thehackernews.com/2024/12/hackers-use-microsoft-msc-files-to.html
Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks