Talk With an Expert

Internet Storm Center Tech Corner

More Scans for Ivanti Connect "Secure" VPN. Exploits Public

https://isc.sans.edu/diary/More+Scans+for+Ivanti+Connect+Secure+VPN+Exploits+Public/30568

Ivanti Vulnerability Widespread Scanning

https://isc.sans.edu/diary/Scans+for+Ivanti+Connect+Secure+VPN+Vulnerability+CVE202346805+CVE202421887/30562

https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/

Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited CVE-2023-35082

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Number Usage in Passwords

https://isc.sans.edu/diary/Number+Usage+in+Passwords/30540

Attacks against Exposed Databases

https://twitter.com/fasterthanlime/status/1741935393413402739

Citrix Patches Already Exploited Vulnerability

https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549

GitHub Key Rotation

https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/

Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes

https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes

A Lightweight Method to Detect Potential iOS Malware

https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/

macOS Infostealers

https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/

CISA and FBI Release Known IOCs Associated with Androxgh0st Malware

https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware

Atlassian Confluence Remote Code Execution Vulnerability

https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html

Google Chrome 0-day

https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive