Updates
- Atlassian warns users: patch critical Confluence flaw ASAP
- Atlassian warns of critical Confluence flaw leading to data loss
- Atlassian warns of exploit for Confluence data wiping bug, get patching
- Urgent: New Security Flaws Discovered in NGINX Ingress Controller for Kubernetes
- New Microsoft Exchange zero-days allow RCE, data theft attacks
- ZDI discloses four zero-day flaws in Microsoft Exchange
Threats
- Apples "Wo ist": Keylogger-Tastatur nutzt Ortungsnetz zum Passwortversand
- Apple 'Find My' network can be abused to steal keylogged passwords
- LinkedIn’s New Nemesis: The DuckTail Malware Strikes
- NodeStealer Malware Hijacking Facebook Business Accounts for Malicious Ads
- Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover
- Nozomi discloses presence of security flaws affect component of Arduino Create Cloud IDE - Industrial Cyber
- Avast confirms it tagged Google app as malware on Android phones
- Massive cybercrime URL shortening service uncovered via DNS data
- Hackers exploit recent F5 BIG-IP flaws in stealthy attacks
- EleKtra-Leak Cryptojacking Attacks Exploit AWS IAM Credentials Exposed on GitHub
Incidents
- Großausfall bei Cloudflare
- Post Mortem on Cloudflare Control Plane and Analytics Outage
- Riesen-Cyberattacke: Rathäuser bleiben abgeschnitten
- Mehre Städte und Kreise betroffen: Hackerangriff sorgt für Verwaltungsausfall in NRW
- Okta breach: 134 customers exposed in October support system hack
- Okta discloses a data breach after a third-party vendor was hacked
- Okta Hack Blamed on Employee Using Personal Google Account on Company Laptop
- Boeing Admits Cyberattack; Lockbit Claims Zero-Day Exploit Was Used to Gain Access
- Boeing confirms cyberattack amid LockBit ransomware claims
- LastPass breach linked to theft of $4.4 million in crypto
Cyber Crime
- SEC charges SolarWinds CISO with fraud for misleading investors before major cyberattack
- Florida man sentenced to prison for SIM Swapping conspiracy that led to theft of $1M in cryptocurrency
- Dutch hacker jailed for extortion, selling stolen data on RaidForums
- Iran's MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign
Malware
- HelloKitty ransomware now exploiting Apache ActiveMQ flaw in attacks
- Mysterious Kill Switch Disrupts Mozi IoT Botnet Operations
- HelloKitty Ransomware Group Exploiting Apache ActiveMQ Vulnerability
- Hackers Using MSIX App Packages to Infect Windows PCs with GHOSTPULSE Malware
- Malicious NuGet packages abuse MSBuild to install malware
- North Korean Hackers Targeting Crypto Experts with KANDYKORN macOS Malware
- New macOS 'KandyKorn' malware targets cryptocurrency engineers
- New BiBi-Linux wiper malware targets Israeli orgs in destructive attacks
- Turla Updates Kazuar Backdoor with Advanced Anti-Analysis to Evade Detection
Misc.
- BSI-Lagebericht 2023: Cybersicherheitslage in Deutschland weiterhin kritisch
- Die Lage der IT-Sicherheit in Deutschland
- Einstufung von Sicherheitslücken: Der CVSS-4.0-Standard ist da
- FIRST Announces CVSS 4.0 - New Vulnerability Scoring System
- FIRST has officially published the latest version of the Common Vulnerability Scoring System (CVSS v4.0)
- Google Play adds security audit badges for Android VPN apps
- Mehr Sicherheit bei E-Mails
- Hackers Earn Over $1 Million at Pwn2Own Toronto 2023
- Russia to launch its own version of VirusTotal due to US snooping fears
- Canada bans WeChat and Kaspersky products on govt devices
- Meta faces EU ban on Facebook, Instagram targeted advertising