2025-01-27 12:00 UTC
Government
NIST Cybersecurity Insights · Gary Howarth, Sue Anie · indexed 2026-08-15 20:45 UTC
This post is the final blog in a series on privacy-preserving federated learning . The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for Data Ethics and Innovation. Learn more and read all the posts published to date at NIST’s Privacy Engineering Collaboration Space or RTA’s blog . Reflections and Wider Considerations This is the final post in the series that began with reflections and learnings from the…
P0
2025-01-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A configuration change in Entra ID allowed unprivileged users to update their own User Principal Names (UPNs) through interfaces like the Entra admin center and PowerShell. This could lead to impersonation risks. Microsoft quickly fixed the issue after it was reported. The vulnerability affected synchronized hybrid environments as well.
P0
2025-01-23 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in AWS IAM Sign-in login flow could allow attackers to enumerate IAM usernames by measuring server response times. This issue affected AWS Sign-in IAM User login flow prior to January 16, 2025. AWS has since introduced a delay in response times across all authentication failure scenarios to mitigate the vulnerability.
P0
2025-01-23 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore how Performance Monitor (PerfMon) counters can be used as alternative methods for detecting Kerberos roasting attacks, moving beyond the traditional reliance on Windows Events 4768/4769.
P0
2025-01-22 07:14 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover the world of surebets, a strategy that guarantees profits by leveraging differing odds from multiple bookmakers. Explore how this approach impacts the betting market, challenging traditional profit models and increasing operational costs for bookmakers.
P0
2025-01-21 04:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How is Group-IB evolving into a leading cybersecurity force that the community relies on?
P0
2025-01-17 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Three SSRF vulnerabilities were discovered in Azure DevOps, allowing access to internal metadata endpoints and potential CRLF injection. The issues affected the endpointproxy and Service Hooks functionality. DNS rebinding could bypass initial fixes. Microsoft awarded $15,000 in bug bounties for the findings.
P0
2025-01-16 07:24 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Real estate scams are on the rise as fraudsters exploit online platforms to deceive victims into paying for fake properties. This blog dives into how these scams operate in the Middle East, explains the tools and techniques used to detect and disrupt money-mule networks, and provides practical tips for staying safe.
P0
2025-01-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in AWS CloudWatch dashboard sharing allowed viewers to access EC2 instance tags and potentially invoke Lambda functions in the source account. The issue stemmed from a logic bug in the AWS Console combined with a "fail open" condition in Amazon Cognito. AWS has since patched the vulnerability.
P0
2025-01-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS identified two vulnerabilities in specific versions of native clients for Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV. These issues could allow man-in-the-middle attacks, potentially giving attackers access to remote sessions. Affected versions include WorkSpaces clients 5.20.0 or earlier, AppStream 2.0 Windows client 1.1.1326 or earlier, and various DCV clients. AWS recommends upgrading to patched versions to address these security concerns.
P0
2025-01-14 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 28 janvier 2025\] Une preuve de concept permettant l'exploitation de cette vulnérabilité est disponible publiquement. Le 14 janvier 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-55591 affectant FortiOS et FortiProxy. Elle permet à un...
P5
2025-01-13 06:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Minimize false positives, proactively prevent threats, and gain customized fraud protection with Group-IB. Our AI-powered solutions are fine-tuned by local experts and real-time threat intelligence in key regions, ensuring optimal security performance and minimal disruption to your business.
P0
2025-01-09 22:12 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what LOLBins are, threats malicious threat actors can pose, how to detect those threats, and how to prevent them.
P0
2025-01-09 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Une vulnérabilité jour-zéro de type débordement de pile a été découverte dans Ivanti Connect Secure (ICS), Policy Secure (IPS), Neurons for Zero Trust Access (ZTA) gateways. Cette vulnérabilité, d'identifiant CVE-2025-0282, permet à un attaquant non authentifié de provoquer une exécution de code...
P5
2025-01-08 06:27 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Fraudsters have devised a sophisticated scheme targeting banking customers in the Middle East, impersonating government officials and using remote access software to steal credit card information and OTP codes. This scam specifically targets individuals who have lodged complaints online via a government portal, taking advantage of their trust and willingness to cooperate in hopes of refunds, leading to significant financial losses through fraudulent transactions.
P0
2025-01-08 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure Machine Learning notebooks can be hijacked by attackers with Storage Account access to inject malicious code. A now-fixed vulnerability allowed Reader role escalation to code execution. The article details the attack methods, including modifying notebooks, obtaining managed identity tokens, and exfiltrating data. It also introduces a tool for dumping AML workspace credentials.
P0
2025-01-07 11:47 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Don’t fall weak in the face of change and disruption. Review the upcoming cybersecurity changes and become equipped while there’s time!
P0
2025-01-06 21:16 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress identified an emerging threat involving Cleo’s LexiCom, VLTransfer, and Harmony software, known as CVE-2024-55956, commonly used to manage file transfers. Read more about this emerging threat on the Huntress Blog.
P25
2025-01-02 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Smishing (or SMS phishing) is far more frequent during the holidays. Learn to recognize the signs of a smish and how to avoid falling victim to one.
P0
2024-12-31 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Take a look back at some of the biggest threats we observed and analyzed in 2024.
P0
2024-12-29 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS Neuron SDK has reintroduced a dependency confusion vulnerability three times in four years. The issue stems from using the --extra-index-url parameter in pip install commands, which allows potential installation of malicious packages from PyPI instead of AWS's private repository. Despite previous reports, AWS has not fully addressed the problem, leaving new packages vulnerable to exploitation.
P0
2024-12-26 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Understand how Managed SIEM supports your compliance journey worldwide.
P0
2024-12-19 12:00 UTC
Government
NIST Cybersecurity Insights · Amy Mahn · indexed 2026-08-15 20:45 UTC
As the year comes to a close, NIST continues to engage with our international partners to strengthen cybersecurity, including sharing over ten new international translations in over six languages as resources for our stakeholders around the world. These efforts were complemented by discussions on opportunities for future enhanced international collaboration and resource sharing. Here are some updates from the past few months: Our international engagement continues through our support to the Dep…
P0
2024-12-19 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn more about the initial access techniques observed by the Huntress SOC and Tactical Response teams! Gain valuable insights to help you protect your environment.
P0
2024-12-18 06:11 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how smartphone manufacturers conceal security flaws, the risks these vulnerabilities pose to users and businesses, and actionable steps to protect devices from data breaches, identity theft, and exploitative attacks.
P0
2024-12-18 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Understanding SIEM’s benefits, limitations, and best applications in a strong healthcare security stack
P0
2024-12-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Unit 42 researchers identified vulnerabilities in the Azure Data Factory's integration with Apache Airflow. These vulnerabilities include misconfigured Kubernetes Role-Based Access Control (RBAC), improper secret handling in Azure’s internal Geneva service, and weak authentication mechanisms. Exploiting these flaws, attackers could gain shadow admin control over Azure infrastructure by crafting malicious DAG files or compromising service principals, leading to unauthorized access, data exfiltra…
P0
2024-12-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Managed ITDR uncovers risks behind popular VPNs and proxies like NordVPN, Mullvad, and more—helping you steer clear of hackers this holiday season.
P0
2024-12-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Sysdig's Threat Research Team discovered an issue with Amazon Bedrock API logging in CloudTrail. Failed API calls were logged as successful without error codes, hindering detection efforts and potentially generating false positives. The issue affected Bedrock Runtime APIs, specifically InvokeModel and Converse. AWS resolved the problem.
P0
2024-12-11 07:11 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Explore the advanced tactics employed in recent email phishing campaigns targeting employees from over 30 companies across 12 industries and 15 jurisdictions. This blog unveils sophisticated techniques used to outsmart Secure Email Gateways (SEGs) and exploit trusted platforms, creating highly convincing schemes to deceive victims and steal their credentials.
P0