Artificial Intelligence ChatGPT Jailbreak: Researchers Bypass AI Safeguards Using Hexadecimal Encoding and Emojis New jailbreak technique tricked ChatGPT into generating Python exploits and a malicious SQL injection tool. Eduard KovacsOctober 29, 2024
ICS/OT Armis Raises $200M at $4.2B Valuation, Eyes IPO Armis raised an additional $200 million in funding at valuation of $4.2 billion as the company aims for an IPO. SecurityWeek NewsOctober 28, 2024
Malware & Threats Russia Targeting Ukrainian Military Recruits With Android, Windows Malware, Google Says Google has uncovered a Russian cyberespionage and influence campaign targeting Ukrainian military recruits. Ionut ArghireOctober 28, 2024
Data Breaches Change Healthcare Ransomware Attack Impacts 100 Million People UnitedHealth told the US health department that hackers stole the information of 100 million people in a February ransomware attack. Ionut ArghireOctober 25, 2024
Network Security Cisco Patches Vulnerability Exploited in Large-Scale Brute-Force Campaign Cisco has released patches for multiple vulnerabilities in ASA, FMC, and FTD products, including an exploited flaw. Ionut ArghireOctober 24, 2024
Vulnerabilities White Hat Hackers Earn $500,000 on First Day of Pwn2Own Ireland 2024 Pwn2Own Ireland 2024 participants have earned half a million dollars on the first day for hacking NAS devices, cameras, speakers and printers. Eduard KovacsOctober 23, 2024
ICS/OT SecurityWeek’s 2024 ICS Cybersecurity Conference Kicks Off in Atlanta Premier Industrial Cybersecurity Conference offers 80+ sessions and hands-on training to tackle critical infrastructure cyber threats. SecurityWeek NewsOctober 22, 2024
Mobile & Wireless Google Warns of Samsung Zero-Day Exploited in the Wild A zero-day vulnerability in Samsung mobile processors has been abused as part of an exploit chain for arbitrary code execution. Ionut ArghireOctober 22, 2024
Data Breaches Cisco Confirms Security Incident After Hacker Offers to Sell Data Cisco has confirmed that some files have been stolen from its DevHub environment after a hacker offered to sell information. Eduard KovacsOctober 21, 2024
Supply Chain Security North Korean APT Exploited IE Zero-Day in Supply Chain Attack A Pyongyang-aligned APT was caught exploiting a recent zero-day in Internet Explorer in a supply chain attack. Ionut ArghireOctober 18, 2024
Cybercrime Anonymous Sudan DDoS Service Disrupted, Members Charged by US The DoJ has announced charges against Anonymous Sudan members and the disruption of their DDoS attack service. Eduard KovacsOctober 17, 2024
Vulnerabilities CISA Flags Critical SolarWinds Web Help Desk Bug for In-the-Wild Exploitation CISA warns that a critical-severity hardcoded credentials vulnerability in SolarWinds Web Help Desk is exploited in attacks. Ionut ArghireOctober 16, 2024
Cloud Security New CounterSEVeillance and TDXDown Attacks Target AMD and Intel TEEs Intel and AMD respond to new attack methods named TDXDown and CounterSEVeillance that can be used against TDX and SEV technology. Eduard KovacsOctober 15, 2024
Vulnerabilities Iranian Cyberspies Exploiting Recent Windows Kernel Vulnerability The Iran-linked APT OilRig has intensified cyber operations against the United Arab Emirates and the broader Gulf region. Ionut ArghireOctober 14, 2024
Data Breaches Fidelity Data Breach Exposed Customer Information Fidelity Investments is notifying 77,000 individuals that their personal information was compromised in a data breach. Eduard KovacsOctober 11, 2024
Artificial Intelligence OpenAI Says Iranian Hackers Used ChatGPT to Plan ICS Attacks OpenAI has disrupted 20 cyber and influence operations this year, including the activities of Iranian and Chinese state-sponsored hackers. Eduard KovacsOctober 11, 2024
Endpoint Security Microsoft’s Take on Kernel Access and Safe Deployment Following CrowdStrike Incident SecurityWeek talked to David Weston, VP enterprise and OS security at Microsoft, to discuss Windows kernel access and safe deployment practices. Kevin TownsendOctober 10, 2024
Vulnerabilities Firefox 131 Update Patches Exploited Zero-Day Vulnerability Mozilla has released a Firefox 131 update to resolve CVE-2024-9680, a code execution vulnerability exploited in the wild as a zero-day. Ionut ArghireOctober 10, 2024
Network Security Palo Alto Patches Critical Firewall Takeover Vulnerabilities Palo Alto warns that attackers can access usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. Ryan NaraineOctober 9, 2024
Malware & Threats Microsoft Confirms Exploited Zero-Day in Windows Management Console Patch Tuesday: Redmond warns that attackers are rigging Microsoft Saved Console (MSC) files to execute remote code on targeted Windows systems. Ryan NaraineOctober 8, 2024