FBI, CISA warning over false claims of hacked voter data – Week in security with Tony Anscombe

With just weeks to go before the US presidential election, the FBI and the CISA are warning about attempts to sow distrust in the electoral process

WeLiveSecurity – ​Read More

Patch this Critical Safeguard for Privileged Passwords Authentication Bypass Flaw

Researchers have released technical details about CVE-2024-45488, a critical authentication bypass vulnerability affecting One Identity’s Safeguard for Privileged Passwords (SPP), which could allow attackers to gain full administrative access.

Cyware News – Latest Cyber News – ​Read More

Germany Seizes 47 Crypto Exchanges Used by Ransomware Gangs

These exchanges allowed users to trade cryptocurrencies anonymously, creating a safe environment for cybercriminals to launder their proceeds without fear of prosecution.

Cyware News – Latest Cyber News – ​Read More

Clever ‘GitHub Scanner’ Campaign Abusing Repositories to Push Malware

A sophisticated campaign is using GitHub repositories to spread the Lumma Stealer malware, targeting users interested in open-source projects or receiving email notifications from them.

Cyware News – Latest Cyber News – ​Read More

CISA Adds Windows, Apache HugeGraph-Server, Oracle JDeveloper, Oracle WebLogic Server, and MSSQL Server Bugs to its KEV Catalog

These vulnerabilities can lead to remote code execution and privilege escalation, posing a significant risk to affected systems. For example, the Oracle JDeveloper vulnerability can allow attackers to compromise the software and take over the system.

Cyware News – Latest Cyber News – ​Read More

Microsoft Entra ID’s Administrative Units Weaponized to Gain Stealthy Persistence

Datadog Security Labs recently revealed a security risk within Microsoft Entra ID, showing how its administrative units (AUs) can be weaponized by attackers to create persistent backdoor access.

Cyware News – Latest Cyber News – ​Read More

Adversarial attacks on AI models are rising: what should you do now?

With AI’s growing influence across industries, malicious attackers continue to sharpen their tradecraft to exploit ML models.Read More

Security News | VentureBeat – ​Read More

Citrine Sleet Poisons PyPI Packages With Mac & Linux Malware

A North Korean advanced persistent threat (APT) actor (aka Gleaming Pisces) tried to sneak simple backdoors into public software packages.

darkreading – ​Read More

Ivanti’s Cloud Service Appliance Attacked via Second Vuln

The critical bug, CVE-2024-8963, can be used in conjunction with the prior known flaw to achieve remote code execution (RCE).

darkreading – ​Read More

More than $44 million in cryptocurrency stolen from Singaporean platform BingX

Singaporean crypto platform BingX said Friday that more than $44 million was stolen from their platform in a cyberattack.

The Record from Recorded Future News – ​Read More