Google pushing out .zip as a TLD and then divesting their registrar business is the equivalent on pooping in the punch bowl as you leave a party
https://9to5google.com/2023/06/15/google-domains-squarespace/
Google pushing out .zip as a TLD and then divesting their registrar business is the equivalent on pooping in the punch bowl as you leave a party
https://9to5google.com/2023/06/15/google-domains-squarespace/
Great article on recent malvertising https://www.malwarebytes.com/blog/threat-intelligence/2023/05/malvertising-its-a-jungle-out-there
Really cool initial access and malware graph https://onodo.org/visualizations/235067
@support.bsky.team how are the weekly invites granted? As Iβm a week and an hour into this account and I do not have any invites. Thanks!
It was trivial to come up with a POC for #CVE-2023-32243 thanks to @patchstackapp detailed write up. Already seeing it abused in the wild. #wordpress owners need to upgrade Essential Addons for Elementor plugin now and check for signs of intrusion.
This will lead to a lot of hacked WordPress sites I wonder if any of the link pits are running this plugin https://www.bleepingcomputer.com/news/security/wordpress-elementor-plugin-bug-let-attackers-hijack-accounts-on-1m-sites/
Great research on the Vidar Stealer https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-vidar-stealer
Looking forward to seeing the POC on Monday for this LPE on Linux https://www.bleepingcomputer.com/news/security/new-linux-kernel-netfilter-flaw-gives-attackers-root-privileges/
Note that the update for CVE-2023-24932 does NOT actually fix anything. It gives you the option of applying the fix yourself. Read through ALL of https://tinyurl.com/mprmsext if you want to consider applying the protection. Feel free to cry a bit and/or consider a career change.
Great work by the spanish police https://www.bleepingcomputer.com/news/security/spanish-police-dismantle-phishing-operation-linked-to-crime-ring/
Great work taking down DDoS services https://arstechnica.com/information-technology/2023/05/feds-seize-13-more-ddos-for-hire-platforms-in-ongoing-international-crackdown/
Nice article from CISA https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a
7
Ouch https://techcrunch.com/2023/05/08/nextgen-healthcare-data-breach/
Thatβs pretty funny #Microsoft #clippy
Seems legit⦠https://www.reddit.com/r/techsupport/comments/9gwwcj/windowsdefendervbs_on_cuserspubliclibraries_is/
https://cybafrique.substack.com/p/kenya-is-turning-to-spyware-again
Please educate yβallβs older folks https://www.malwarebytes.com/blog/threat-intelligence/2023/04/massive-malvertising-campaign-targets-seniors-via-fake-weebly-sites
https://abc7.com/san-bernardino-cyberattack-ransom-paid-hackers/13215833/
Stuff like this and the satellite network keep me up and employed https://www.darkreading.com/ics-ot/2-years-after-colonial-pipeline-attack-us-critical-infrastructure-remains-as-vulnerable-to-ransomware
Lol
Great post on bad practices in cyber security from CISA https://www.cisa.gov/news-events/news/bad-practices-0
If people havenβt upgraded their Papercut software now, this seems pretty bad https://thehackernews.com/2023/05/researchers-uncover-new-exploit-for.html
What prevents this individual from just starting a new domain and running the same business again? #infosec https://krebsonsecurity.com/2023/05/10m-is-yours-if-you-can-get-this-guy-to-leave-russia/
Hello World! Happy to be here on #BlueSky instead of the dumpster fire!