Talk With an Expert

Internet Storm Center Tech Corner

INTERNET STORM CENTER TECH CORNER

Malicious PDF File As Delivery Mechanism

https://isc.sans.edu/diary/Malicious+PDF+File+Used+As+Delivery+Mechanism/30848

Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400

https://isc.sans.edu/diary/Palo+Alto+Networks+GlobalProtect+exploit+public+and+widely+exploited+CVE20243400/30844

Updated Palo Alto Networks GlobalProtect Guidance

https://security.paloaltonetworks.com/CVE-2024-3400

Delinea Secret Server Authn Authz Bypass

https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3

Ivanti Avalanche Poc/Details

https://www.tenable.com/security/research/tra-2024-10

Advanced Phishing Campaign

https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit

Hashicorp go-getter update CVE-2024-3817

https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040

OfflRouter Virus

https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/

Coordinated Social Engineering Takeovers of Open Source Projects

https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/

OpenMetaData Attacks

https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/

Putty Private Key Recovery

https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html

Oracle Critical Patch Update

https://www.oracle.com/security-alerts/cpuapr2024.html

Ivanti Avalanche MDM Patches

https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive