Sports betting company DraftKings said its customers suffered credential stuffing attacks, but denies a hack of its own systems. total loss of users is estimated at $300,000. At the same time, DraftKings emphasizes that its own...
Author - Emma Davis
Google Decided to Fight Hacked Versions of Cobalt Strike
Google Cloud Threat Intelligence announced the release of YARA rules, as well as a collection of indicators of compromise VirusTotal, which should facilitate the detection of Cobalt Strike components and prevent abuse of this...
F5 Fixes Serious Vulnerabilities in BIG-IP and BIG-IQ
F5 developers have released patches for BIG-IP and BIG-IQ products and the patches fixed two serious vulnerabilities that could allow unauthenticated attackers to remotely execute arbitrary code (RCE) on vulnerable endpoints. ...
November Windows Updates Broke Kerberos Authentication
Microsoft says they are already aware of a new issue in Windows updates that causes corporate domain controllers to fail when using Kerberos authentication, as well as other authentication issues that have emerged since the...
Bypassing the Lock Screen on Pixel Smartphones Netted a Researcher $70,000
This month, Google developers fixed a serious issue that could bypass the lock screen on Pixel smartphones and could be lead to use of other people’s devices. independent researcher who discovered this bug received a reward...
Microsoft Fixed Six 0-Day Vulnerabilities and Finally Released Patches for ProxyNotShell
As part of November’s Update Tuesday, Microsoft fixed 68 vulnerabilities in its products, including six zero-day problems that the attackers had already exploited, and released patches for ProxyNotShell. the 68...
China Is Accumulating Vulnerabilities and Exploiting Them in Cyber-Spy Attacks
Microsoft experts say that China is accumulating vulnerabilities for their further exploitation in cyber espionage. China’s offensive cyber capabilities have improved due to a law that allowed Beijing to create an arsenal...
Access to AstraZeneca Databases Was in the Public Domain
Due to human error, confidential customer data of the international pharmaceutical company AstraZeneca was in the public domain. Hussain, director of security at SpiderSilk, said that in 2021, the developer left the credentials...
Dozens of PyPI Packages Distribute W4SP Malware
Phylum, a supply chain security company, discovered 29 malicious packages in the PyPI repository (the list can be found below) that infected their victims with the W4SP data-stealing malware. me remind you that we also said that...
Microsoft Developers Fixed a Critical Bug in Azure Cosmos DB
Orca Security analysts have discovered a critical vulnerability affecting Jupyter Notebook for Azure Cosmos DB. The problem that researchers dubbed CosMiss, allowed unauthorized access to containers for reading and writing, as...