Skip to main content

BleepingComputer.com

"Microsoft launches Zero Day Quest hacking event with $4million in rewards."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 19 November 2024, 1437 UTC.

Content and Source:   https://www.bleepingcomputer.com/

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

Microsoft launches Zero Day Quest hacking event with $4 million in rewards

  • ​Microsoft announced today at its Ignite annual conference in Chicago, Illinois, that it's expanding its bug bounty programs with Zero Day Quest, a new hacking event focusing on cloud and AI products and platforms.

  • Windows 11
     

Microsoft shares more details on Windows 11 admin protection

  • ​Microsoft has shared more details about the new Windows 11 administrator protection security feature, which is available in preview and uses Windows Hello authentication prompts to block access to critical system resources.

  • Nudge Security
     

Sponsored Content 
Free shadow SaaS inventory + security insights

  • Discover all SaaS accounts ever created by anyone in your org, in minutes, along with insights on security risks and spend. Save time, money and effort by curbing SaaS sprawl and automating tasks like offboarding and user access reviews. Free trial.

  • Costco
     

This Costco Membership comes with a $45 Digital Costco Shop Card

  • If you're gearing up for holiday shopping, this Costco Gold Star Membership promotion couldn't come at a better time. For only $65, you'll receive a 1-year Costco membership plus a $45 Digital Costco Shop Card*, setting you up with exclusive access to quality products, bulk discounts, and unbeatable holiday savings all year.

    • BleepingComputer Deals
    •  
    • November 19, 2024
    •  
    • 07:11 AM
    •  
    • Comment Count 0
  • Spotify
     

Spotify abused to promote pirated software and game cheats

  • Spotify playlists and podcasts are being abused to push pirated software, game cheat codes, spam links, and "warez" sites. By injecting targeted keywords and links in playlist names and podcast descriptions, threat actors may benefit from boosting SEO for their dubious online properties appearing in Google.

  • Brave
     

Brave on iOS adds new "Shred" button to wipe site-specific data

  • Brave Browser 1.71 for iOS introduces a new privacy-focused feature called "Shred," which allows users to easily delete site-specific mobile browsing data.

  • Fortinet
     

Chinese hackers exploit Fortinet VPN zero-day to steal credentials

  • Chinese threat actors use a custom post-exploitation toolkit named 'DeepData' to exploit a zero-day vulnerability in Fortinet's FortiClient Windows VPN client that steal credentials.

  • Maxar
     

US space tech giant Maxar discloses employee data breach

  • Hackers breached U.S. satellite maker Maxar Space Systems and accessed personal data belonging to its employees, the company informs in a notification to impacted individuals.

  • Palo Alto Networks
     

Palo Alto Networks patches two firewall zero-days used in attacks

  • Palo Alto Networks has finally released security updates for an actively exploited zero-day vulnerability in its Next-Generation Firewalls (NGFW).

  • Police arrest
     

US charges Phobos ransomware admin after South Korea extradition

  • Evgenii Ptitsyn, a Russian national and suspected administrator of the Phobos ransomware operation, was extradited from South Korea and is facing cybercrime charges in the United States.

  • VMware
     

Critical RCE bug in VMware vCenter Server now exploited in attacks

  • ​Broadcom warned today that attackers are now exploiting two VMware vCenter Server vulnerabilities, one of which is a critical remote code execution flaw.

  • Chrome flare
     

Fake Bitwarden ads on Facebook push info-stealing Chrome extension

  • Fake Bitwarden password manager advertisements on Facebook are pushing a malicious Google Chrome extension that collects and steals sensitive user data from the browser.

  • Creative Cloud
     

This $25 course deal teaches how the pros use Adobe Creative Cloud

  • The All-in-One Adobe Creative Cloud Suite Course Bundle is your chance to get professional tips to help you quickly learn Adobe Premiere Pro, After Effects, Lightroom, Animate, and more.

    • BleepingComputer Deals
    •  
    • November 18, 2024
    •  
    • 07:11 AM
    •  
    • Comment Count 0
  • Microsoft 365
     

Microsoft 365 Admin portal abused to send sextortion emails

  • The Microsoft 365 Admin Portal is being abused to send sextortion emails, making the emails appear trustworthy and bypassing email security platforms.

  • Malware Phishing
     

Phishing emails increasingly use SVG attachments to evade detection

  • Threat actors increasingly use Scalable Vector Graphics (SVG) attachments to display phishing forms or deploy malware while evading detection.

  • WordPress
     

Security plugin flaw in millions of WordPress sites gives admin access

  • A critical authentication bypass vulnerability has been discovered impacting the WordPress plugin 'Really Simple Security' (formerly 'Really Simple SSL'), including both free and Pro versions.

  • Microsoft Office
     

Get $89 off Microsoft Office 2024 in this deal

  • Grab the 2024 edition of Microsoft Office for your Mac or PC while it's available for $159.97. Inventory is limited, and this offer expires today, November 17, at 11:59 PM Pacific.

    • BleepingComputer Deals
    •  
    • November 17, 2024
    •  
    • 08:09 AM
    •  
    • Comment Count 0
  • AI Hacker Robot Artificial Intelligence
     

Fake AI video generators infect Windows, macOS with infostealers

  • Fake AI image and video generators infect Windows and macOS with the Lumma Stealer and AMOS information-stealing malware, used to steal credentials and cryptocurrency wallets from infected devices.

  • T-Mobile
     

T-Mobile confirms it was hacked in recent wave of telecom breaches

  • T-Mobile confirms it was hacked in the wave of recently reported telecom breaches conducted by Chinese threat actors to gain access to private communications, call records, and law enforcement information requests.

  • GitHub
     

GitHub projects targeted with malicious commits to frame researcher

  • GitHub projects have been targeted with malicious commits and pull requests, in an attempt to inject backdoors into these projects. Most recently, the GitHub repository of Exo Labs, an AI and machine learning startup, was targeted in the attack, which has left many wondering about the attacker's true intentions.

  • Cybersecurity
     

Advance your cybersecurity knowledge for just $29.97 in this course deal

  • The CISSP (Certified Information Systems Security Professional) certification is one of the most respected certifications in the industry, and for a limited time, you can deep dive into the world of cybersecurity for only $29.97—no coupon needed.

    • BleepingComputer Deals
    •  
    • November 16, 2024
    •  
    • 08:11 AM
    •  
    • Comment Count 0
View More

Comments

Popular posts from this blog

Cyber War News Today.

"International Defence Cooperation:  A key to regional stability." Views expressed in this cybersecurity, cyber espionage, and cyber crime update are those of the reporters and correspondents.  Accessed on 15 December 2024, 0134 UTC. Content and Source:   https://cyberwar.einnews.com/news/cyber-war-news?n=2&code=FA9GNesSTpp2rjO1&utm_source=NewsletterNews&utm_medium=email&utm_campaign=Cyber+War+News&utm_content=navig Please check link or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net). Cyber War News Monitoring Get by    Email    •     RSS Published on  Dec 13, 2024 The Cyber Warfare Market Size Reach USD 127.1 Billion by 2032 Exhibiting CAGR at 13.3% WILMINGTON, DE, UNITED STATES, December 13, 2024 /⁨EINPresswire.com⁩/ -- According to the report, The Cyber Warfare Market Size Reach USD 127.1 Billion by 2032 Exhibiting CAGR at 1...

The Cyberwire Daily Briefing

"Fortinet confirms breach of customer data." Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 15 September 2024, 1339 UTC. Content and Source:   https://thecyberwire.com/newsletters/daily-briefing/13/176 Please check link or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net). V13 | Issue 176 | 9.13.24 Daily Briefing for 09.13.24 Announcement Cloud Security in the Age of Generative AI. Artificial Intelligence is revolutionizing business, but it also introduces new risks. Join us on Wednesday, September 18th at 2pm EDT for a compelling live webinar on "Good vs. Evil: Cloud Security in the Age of Generative AI" with N2K CyberWire’s Dave Bittner and Sysdig’s Loris Degioanni.  Learn more and register now . Summary By the CyberWire staff At a glance. Fortinet confirms breach of customer data. Iran's Scarred Manticore deplo...

SecurityWeek Briefing

"New RAMBO attack allows air-gapped data theft." Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 10 September 2024, 0035 UTC. Content and Source:  https://www.securityweek.com Please check link or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net).   Monday, September 9 , 2024 Are you worried about unmanaged devices and apps? LATEST CYBERSECURITY HEADLINES New RAMBO Attack Allows Air-Gapped Data Theft Predator Spyware Resurfaces With Fresh Infrastructure Google Pushes Rust in Legacy Firmware to Tackle Memory Safety Flaws 300,000 Impacted by Data Breach at Car Rental Firm Avis One Million US Kaspersky Customers Transferred to Pango’s UltraAV Two Indicted in US for Running Dark Web Marketplaces Offering Stolen Information Critical SonicWall Vulnerability Possibly Exploited in Ransomware Attacks CISA Breaks Silence on Controvers...