Aggregator
Попытка сорвать Олимпиаду? Саботаж на кабельных линиях вызвал масштабные сбои связи по всей Франции
Метеоритный дождь: почему стоит посмотреть на небо 30 июля
Ransomware operators exploit ESXi hypervisor vulnerability for mass encryption
Microsoft Security researchers have observed a vulnerability used by various ransomware operators to get full administrative access to domain-joined ESXi hypervisors and encrypt the virtual machines running on them. The vulnerability involves creating a group called “ESX Admins” in Active Directory and adding an attacker-controlled user account to this group. This manipulation of the Active Directory group takes advantage of a privilege escalation vulnerability (CVE-2024-37085) in ESXi hypervisors that grants the added user full administrative access to the ESXi hypervisor. The vulnerability was fixed by VMware in their June release and ESXi administrators should install this security update.
The post Ransomware operators exploit ESXi hypervisor vulnerability for mass encryption appeared first on Microsoft Security Blog.
SecWiki News 2024-07-29 Review
如何构建属于自己的docker镜像
前沿追踪 | 深度分析新型APT组织CloudSorcerer
免手机验证注册Gmail邮箱
От Белого дома к блокчейну: Дональд Трамп подарит Америке криптовалютное господство
See How Realistic Cyber Defense Is in a New Trailhead Course
See How Realistic Cyber Defense Is in a New Trailhead Course
Mandrake Spyware Infects 32,000 Devices Via Google Play Apps
Acronis Cyber Infrastructure bug actively exploited in the wild
XDSpy возвращается: российские компании снова под прицелом хакеров
29th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Superior Court of Los Angeles was forced to shut down its network following a ransomware attack. The court, the largest in the United States, has closed all of its 36 courthouse […]
The post 29th July – Threat Intelligence Report appeared first on Check Point Research.
北京交通大学 | 面向个性化联邦学习的系统化后门攻击:方法与对抗(USENIX Security '24)
OAuth+XSS Attack Threatens Millions of Web Users With Account Takeover
От RuStore до госуслуг: что будет в вашем новом смартфоне?
Threat Actots Leveraging ChatGPT To Craft Sophisticated Attacks
Adversaries are employing Large Language Models to generate malicious code, delivered via phishing emails, for downloading diverse payloads, including Rhadamanthys, NetSupport, CleanUpLoader, ModiLoader, LokiBot, and Dunihi. It indicates a concerning trend of threat actors leveraging AI to automate malware creation and distribution, posing significant challenges for cybersecurity defenses. A broad-spectrum cyberattack campaign leverages phishing emails […]
The post Threat Actots Leveraging ChatGPT To Craft Sophisticated Attacks appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.