2025-01-14 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 28 janvier 2025\] Une preuve de concept permettant l'exploitation de cette vulnérabilité est disponible publiquement. Le 14 janvier 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-55591 affectant FortiOS et FortiProxy. Elle permet à un...
P5
2025-01-13 06:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Minimize false positives, proactively prevent threats, and gain customized fraud protection with Group-IB. Our AI-powered solutions are fine-tuned by local experts and real-time threat intelligence in key regions, ensuring optimal security performance and minimal disruption to your business.
P0
2025-01-09 22:12 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what LOLBins are, threats malicious threat actors can pose, how to detect those threats, and how to prevent them.
P0
2025-01-09 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Une vulnérabilité jour-zéro de type débordement de pile a été découverte dans Ivanti Connect Secure (ICS), Policy Secure (IPS), Neurons for Zero Trust Access (ZTA) gateways. Cette vulnérabilité, d'identifiant CVE-2025-0282, permet à un attaquant non authentifié de provoquer une exécution de code...
P5
2025-01-08 06:27 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Fraudsters have devised a sophisticated scheme targeting banking customers in the Middle East, impersonating government officials and using remote access software to steal credit card information and OTP codes. This scam specifically targets individuals who have lodged complaints online via a government portal, taking advantage of their trust and willingness to cooperate in hopes of refunds, leading to significant financial losses through fraudulent transactions.
P0
2025-01-08 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure Machine Learning notebooks can be hijacked by attackers with Storage Account access to inject malicious code. A now-fixed vulnerability allowed Reader role escalation to code execution. The article details the attack methods, including modifying notebooks, obtaining managed identity tokens, and exfiltrating data. It also introduces a tool for dumping AML workspace credentials.
P0
2025-01-07 11:47 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Don’t fall weak in the face of change and disruption. Review the upcoming cybersecurity changes and become equipped while there’s time!
P0
2025-01-06 21:16 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress identified an emerging threat involving Cleo’s LexiCom, VLTransfer, and Harmony software, known as CVE-2024-55956, commonly used to manage file transfers. Read more about this emerging threat on the Huntress Blog.
P25
2025-01-02 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Smishing (or SMS phishing) is far more frequent during the holidays. Learn to recognize the signs of a smish and how to avoid falling victim to one.
P0
2024-12-31 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Take a look back at some of the biggest threats we observed and analyzed in 2024.
P0
2024-12-29 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS Neuron SDK has reintroduced a dependency confusion vulnerability three times in four years. The issue stems from using the --extra-index-url parameter in pip install commands, which allows potential installation of malicious packages from PyPI instead of AWS's private repository. Despite previous reports, AWS has not fully addressed the problem, leaving new packages vulnerable to exploitation.
P0
2024-12-26 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Understand how Managed SIEM supports your compliance journey worldwide.
P0
2024-12-19 12:00 UTC
Government
NIST Cybersecurity Insights · Amy Mahn · indexed 2026-08-15 20:45 UTC
As the year comes to a close, NIST continues to engage with our international partners to strengthen cybersecurity, including sharing over ten new international translations in over six languages as resources for our stakeholders around the world. These efforts were complemented by discussions on opportunities for future enhanced international collaboration and resource sharing. Here are some updates from the past few months: Our international engagement continues through our support to the Dep…
P0
2024-12-19 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn more about the initial access techniques observed by the Huntress SOC and Tactical Response teams! Gain valuable insights to help you protect your environment.
P0
2024-12-18 06:11 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how smartphone manufacturers conceal security flaws, the risks these vulnerabilities pose to users and businesses, and actionable steps to protect devices from data breaches, identity theft, and exploitative attacks.
P0
2024-12-18 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Understanding SIEM’s benefits, limitations, and best applications in a strong healthcare security stack
P0
2024-12-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Unit 42 researchers identified vulnerabilities in the Azure Data Factory's integration with Apache Airflow. These vulnerabilities include misconfigured Kubernetes Role-Based Access Control (RBAC), improper secret handling in Azure’s internal Geneva service, and weak authentication mechanisms. Exploiting these flaws, attackers could gain shadow admin control over Azure infrastructure by crafting malicious DAG files or compromising service principals, leading to unauthorized access, data exfiltra…
P0
2024-12-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Managed ITDR uncovers risks behind popular VPNs and proxies like NordVPN, Mullvad, and more—helping you steer clear of hackers this holiday season.
P0
2024-12-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Sysdig's Threat Research Team discovered an issue with Amazon Bedrock API logging in CloudTrail. Failed API calls were logged as successful without error codes, hindering detection efforts and potentially generating false positives. The issue affected Bedrock Runtime APIs, specifically InvokeModel and Converse. AWS resolved the problem.
P0
2024-12-11 07:11 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Explore the advanced tactics employed in recent email phishing campaigns targeting employees from over 30 companies across 12 industries and 15 jurisdictions. This blog unveils sophisticated techniques used to outsmart Secure Email Gateways (SEGs) and exploit trusted platforms, creating highly convincing schemes to deceive victims and steal their credentials.
P0
2024-12-11 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Azure API Management Developer Portal allows arbitrary code execution and secret exfiltration. The issue stems from a workflow that loads untrusted data from opened issues, potentially allowing attackers to inject malicious commands. This could lead to code execution in the runner, granting access to sensitive tokens and permissions.
P0
2024-12-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Team Huntress has analyzed Cleo's software vulnerability CVE-2024-55956. Take a look at the technical breakdown of a new family of malware we’ve named Malichus.
P5
2024-12-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
With 2024 ending, let’s look back at everything new from Huntress Managed SAT this past year.
P0
2024-12-05 12:00 UTC
Government
NIST Cybersecurity Insights · Dr. Xiaowei Huang, Dr. Yi Dong, Sikha Pentyala · indexed 2026-08-15 20:45 UTC
This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for Data Ethics and Innovation. Learn more and read all the posts published to date at NIST’s Privacy Engineering Collaboration Space or RTA’s blog . Introduction In this post, we talk with Dr. Xiaowei Huang and Dr. Yi Dong (University of Liverpool) and Sikha Pentyala (University of W…
P0
2024-12-05 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
How Huntress Managed SIEM turns signal recognition into defensive mastery.
P0
2024-12-04 07:05 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB’s Fraud Protection team examines how fraudsters use deepfake technology to bypass biometric security in financial institutions, including facial recognition and liveness detection. This blog highlights the use of emulators, app cloning, and virtual cameras to exploit vulnerabilities, and highlights the financial and societal impacts of deepfake fraud.
P0
2024-12-02 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this new blog series, we’ll explore the managed episodes from Huntress Managed SAT, dive into the topics, and gain insight into why these episodes are relevant right now.
P0
2024-11-28 05:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Scammers are using fake betting game advertisements on social media to target users, with over 500 deceptive advertisements and 1,377 malicious websites identified by Group-IB CERT. These scams promise quick money but are designed to steal personal data and funds, and this blog aims to educate users on how to recognize and protect themselves from such threats.
P0
2024-11-25 08:05 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2024-11-25 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, Huntress SOC investigators unravel the lateral movement and persistence of an interesting threat actor and their novel infrastructure
P0