Updates
- VMware Aria vulnerable to critical SSH authentication bypass flaw
- PoC Exploit Released for Critical VMware Aria's SSH Auth Bypass Vulnerability
- Webbrowser: Google-Chrome-Update stopft hochriskante Sicherheitslücke
- Webbrowser: Neue Firefox-Releases schließen mehrere Sicherheitslücken
- Multiple Notepad++ Flaws Let Attackers Execute Arbitrary Code
- Exploit released for Juniper firewall bugs allowing RCE attacks
Threats
- Unpatched Citrix NetScaler Devices Targeted by Ransomware Group FIN8
- Hackers Can Exploit Windows Container Isolation Framework to Bypass Endpoint Security
- Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges
- Unveiling the Sneaky ‘MalDoc in PDF’ Attack: A Novel Evasion Technique Detected by Japan’s…
- MalDoc in PDFs: Hiding malicious Word docs in PDF files
- Classiscam fraud-as-a-service expands, now targets banks and 251 brands
- Hacking campaign bruteforces Cisco VPNs to breach networks
- Chrome extensions can steal plaintext passwords from websites
- Midnight Blizzard conducts targeted social engineering over Microsoft Teams | Microsoft Security Blog
- DLL-Hijacking: Asiatische Angreifer nutzen gestohlenes VPN-Zertifikat für Angriffe
- Chinesische Cyberkriminelle: Verfassungsschutz warnt vor Hackerangriffen auf Heimnetzwerke
- Bundesinnenministerium: Komplexes Netzwerk verbreitet russische Desinformation
Incidents
- Toyota Japan back on the road after probably-not-cyberattack
- Hackers infiltrated Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC) for months
- Cyber hackers target Polish rail network, cause operational disruptions - Industrial Cyber
- 'The Wallet Event': Crypto Startup Bankrupt After Losing Password to $38.9 Million Physical Crypto Wallet
- Paramount discloses data breach following security incident
- Forever 21 data breach: hackers accessed info of 500,000
- Golf gear giant Callaway data breach exposes info of 1.1 million
- Cyber-Angriff nun auch auf VG Wörrstadt
Cyber Crime
- Qakbot Botnet Disrupted in Operation ‘Duck Hunt’
- US, European agencies dismantle Qakbot network used for ransomware and scams
- How the FBI nuked Qakbot malware from infected Windows PCs
- North Korean hackers behind malicious VMConnect PyPI campaign
- Hackerangriffe aus Nordkorea: Lazarus greift Europa und USA mit zwei neuen RATs an