Cyber League: UK’s NCSC Calls on Industry Experts to Join its Fight Against Cyber Threats

The NCSC wants volunteers from the U.K.’s public and private sectors to join its new cybersecurity community.

Security | TechRepublic – ​Read More

Jason’s Deli Data Breach Exposes 344,000 Users in Credential Stuffing Attack

By Waqas

The data breach occurred a few days before Christmas on December 21, 2023, but the details have only been revealed now.

This is a post from Read the original post: Jason’s Deli Data Breach Exposes 344,000 Users in Credential Stuffing Attack

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

Kasseika Ransomware Linked to BlackMatter in BYOVD Attack

An emerging actor is the latest to deploy a tactic that terminates AV processes and services before deploying its payload; the campaign is part of a bigger “bring your own vulnerable driver” trend.

darkreading – ​Read More

How the Sys:All Loophole Allowed Us To Penetrate GKE Clusters in Production

An external threat actor in possession of a Google account could misuse this misconfiguration by using their own Google OAuth 2.0 bearer token to seize control of the cluster for follow-on exploitation.

Cyware News – Latest Cyber News – ​Read More

Water Services Giant Veolia North America Hit by Ransomware Attack

The company has discovered a limited number of individuals whose personal information may have been impacted during the breach and is working with a third-party forensics firm to assess the extent of the attack’s impact on its operations and systems.

Cyware News – Latest Cyber News – ​Read More

Windows 11 KB5034204 Update Fixes Bluetooth Audio Issues, 24 bugs

KB5034204 also fixes an issue caused by a deadlock that prevents search from working on the Start menu for some users and addresses a bug affecting the OpenType font driver, affecting how text renders for third-party applications.

Cyware News – Latest Cyber News – ​Read More

VexTrio: The Uber of Cybercrime – Brokering Malware for 60+ Affiliates

VexTrio has been attributed to malicious campaigns that use domains generated by a dictionary domain generation algorithm (DDGA) to propagate scams, riskware, spyware, adware, potentially unwanted programs (PUPs), and pornographic content.

Cyware News – Latest Cyber News – ​Read More

Splunk fixed high-severity flaw impacting Windows versions

Deserialization of untrusted data can allow malicious code to be executed on the system. This is because the serialized data can contain instructions that the application will execute when it deserializes the data.

Cyware News – Latest Cyber News – ​Read More

Chrome 121 Patches 17 Vulnerabilities

Google releases Chrome 121 to the stable channel with 17 security fixes, including 11 reported by external researchers.

The post Chrome 121 Patches 17 Vulnerabilities appeared first on SecurityWeek.

SecurityWeek – ​Read More

Trello API Abused to Link Email Addresses to 15 Million Accounts

For those concerned, the Trello leak has been added to the Have I Been Pwned data breach notification service, allowing anyone to check if they are among the 15 million leaked email addresses.

Cyware News – Latest Cyber News – ​Read More