Hi,
We've archived the MITRE CVE database. The CVE DB is free and open source on GitHub. However, we're providing a backup location for the data. We doubt it'll magically disintegrate in ash, but if it does we have a copy.
https://t.co/BFvcxeQvWn
A reminder to those reading this that we're developers. We do the 'MVP as a service' thing, too. Pretty good at it (humble brag)
Got an idea? Got funding? Be pretty dumb/uncool of you not to check us out, really. More info👇
https://t.co/ImEbjl8eNE
A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake "Security Alert" issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code.
https://t.co/z6qrr8XYSq
New Phishing-as-a-Service targets Microsoft 365, leveraging sophisticated evasion techniques and a Telegram-based platform to steal credentials.
https://t.co/8uAtKhSycB
Microsoft is investigating an ongoing Multi-Factor Authentication outage that is blocking customers from accessing Microsoft 365 apps.
Some affected Microsoft 365 users have also reported that MFA registration and reset are not working.
https://t.co/hlZEQFhEPT
🚨 A botnet named Socks5Systemz has infected over 85,000 machines worldwide, transforming them into anonymous proxy servers marketed on PROXY[.]AM for as much as $700/month.
Learn more: https://t.co/6ThLhuhZyt
#infosec#hacking#malware
MITRE has shared this year's top 25 list of the most common and dangerous software weaknesses behind more than 31,000 vulnerabilities disclosed between June 2023 and June 2024.
https://t.co/AigbAMWVw6
8% of DNS name servers have zone transfer enabled. Zone transfer can reveal a lot of information about your network and infrastructure, it might leak data that should be private and leave you vulnerable to DDOS amplification.
https://t.co/ZB7Xf4BKrx
Today the United States Securities and Exchange Commission charged four companies for intentionally misleading investors about the severity of the SolarWinds breach.
In or around September 2019, APT29 a/k/a Cozy Bear a/k/a Turla Group compromised United States-based network monitoring company SolarWinds. The compromise resulted in one of the largest Supply-Chain attacks in history when the state-sponsored group began slipstreaming malicious payloads into the SolarWinds Orion toolset updates.
The United States Securities and Exchange Commission has issued the following fines:
- Unisys, an information technology service and consulting company : $4,000,000 fine
- Avaya, a company with provides cloud services and workplace collaboration services: $1,000,000 fine
- Check Point Software, a provider for hardware and software cyber security solutions: $995,000 fine
- Mimecast, a cloud-based email management company: $990,000 fine
🚨🚨WordPress sites are being hacked to install malicious plugins that display fake software updates and errors to push information-stealing malware.
ZoomEye Dork👉app:"WordPress"
3 million+ results are found on https://t.co/jfhKNZYvyg.
ZoomEye Link: https://t.co/uJt8gxTcjG
Refer: https://t.co/CyTeXLxPUk
#WordPress #Cyberspacemapping #cybersecurity #ZoomEye #infosec2024
Google Mandiant security analysts warn of a worrying new trend of threat actors demonstrating a better capability to discover and exploit zero-day vulnerabilities in software. Google state that 70% of exploited flaws disclosed in 2023 were zero-days.
https://t.co/wua2juXQO1
Deleting yourself and installing a different AV product without any warning or consent is certainly an interesting market exit.
https://t.co/T2WdGusxRp