Talk With an Expert

Internet Storm Center Tech Corner

PHPUnit and Androxgh0st

https://isc.sans.edu/diary/Command+Injection+Exploit+For+PHPUnit+before+4828+and+5x+before+563+Guest+Diary/31528

A Deep Dive into TeamTNT and Spinning YARN

https://isc.sans.edu/diary/Guest+Diary+A+Deep+Dive+into+TeamTNT+and+Spinning+YARN/31530

Python Delivering AnyDesk Client as RAT

https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/

Mirai Attacks Session Smart Routers

https://supportportal.juniper.net/s/article/2024-12-Reference-Advisory-Session-Smart-Router-Mirai-malware-found-on-systems-when-the-default-password-remains-unchanged?language=en_US

FortiWLM Unauthenticated limited file read vulnerability

https://fortiguard.fortinet.com/psirt/FG-IR-23-144

https://securityonline.info/kaspersky-uncovers-active-exploitation-of-fortinet-vulnerability-cve-2023-48788/

Beyond Trust Security Advisory

https://www.beyondtrust.com/trust-center/security-advisories/bt24-10

BadBox Update

https://www.bitsight.com/blog/badbox-botnet-back

SS7 Attacks

https://www.404media.co/email/ac709882-1e4b-42fc-bcca-cf7ce4793716/

Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks

https://www.trendmicro.com/en_us/research/24/l/earth-koshchei.html

Okta Social Engineering Impersonation Report

https://sec.okta.com/articles/2024/okta-social-engineering-report-response-and-recommendation

US considers banning TP-Link routers over cybersecurity risks

https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/

CISA Releases Best Practice Guidance for Mobile Communications

https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications

Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion

https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html

CrushFTP Vulnerability

https://crushftp.com/crush11wiki/Wiki.jsp?page=Update

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive
CISA: Secure Cloud Environments Directive and Mobile Communications Guidance; Look Out for Google Calendar Phishing