Talk With an Expert

Internet Storm Center Tech Corner

Struts2 devmode Still a Problem Ten Years Later

https://isc.sans.edu/diary/Struts+devmode+Still+a+problem+ten+years+later/30866

API Rug Pull - The NIST NVD Database and API

https://isc.sans.edu/diary/API+Rug+Pull+The+NIST+NVD+Database+and+API+Part+4+of+3/30868

Does it matter if iptables isn't running on my honeypot?

https://isc.sans.edu/diary/Does+it+matter+if+iptables+isnt+running+on+my+honeypot/30862

Matthew Alan Vorhees: Prevention Strategies for Modern Living Off the Land Usage

https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/

Unplugging PlugX: Singholing the PlugX USB worm botnet

https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/

pfSense Updates

https://docs.netgate.com/advisories/index.html

GitLab Updates

https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/

Cisco Patches Vulnerabilities and Discovers Arcane Backdoor

https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/

Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers

https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/

MySQL2: Dangers of User-Defined Database Connections

https://blog.slonser.info/posts/mysql2-attacker-configuration/

Netgear Nighthawk Vulnerabilities

https://jvn.jp/en/vu/JVNVU91883072/

Analyzing Forest Blizzard's Custom Post-Compromise Tool for exploiting CVE-2022-38028

https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/

April 2024 Exchange Server Hotfix Update

https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536

CVE-2024-2389: Command Injection Vulnerability in Progress Flowmon

https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/

GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining

https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive