2024-12-11 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Azure API Management Developer Portal allows arbitrary code execution and secret exfiltration. The issue stems from a workflow that loads untrusted data from opened issues, potentially allowing attackers to inject malicious commands. This could lead to code execution in the runner, granting access to sensitive tokens and permissions.
P0
2024-12-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Team Huntress has analyzed Cleo's software vulnerability CVE-2024-55956. Take a look at the technical breakdown of a new family of malware we’ve named Malichus.
P5
2024-12-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
With 2024 ending, let’s look back at everything new from Huntress Managed SAT this past year.
P0
2024-12-05 12:00 UTC
Government
NIST Cybersecurity Insights · Dr. Xiaowei Huang, Dr. Yi Dong, Sikha Pentyala · indexed 2026-08-15 20:45 UTC
This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for Data Ethics and Innovation. Learn more and read all the posts published to date at NIST’s Privacy Engineering Collaboration Space or RTA’s blog . Introduction In this post, we talk with Dr. Xiaowei Huang and Dr. Yi Dong (University of Liverpool) and Sikha Pentyala (University of W…
P0
2024-12-05 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
How Huntress Managed SIEM turns signal recognition into defensive mastery.
P0
2024-12-04 07:05 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB’s Fraud Protection team examines how fraudsters use deepfake technology to bypass biometric security in financial institutions, including facial recognition and liveness detection. This blog highlights the use of emulators, app cloning, and virtual cameras to exploit vulnerabilities, and highlights the financial and societal impacts of deepfake fraud.
P0
2024-12-02 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this new blog series, we’ll explore the managed episodes from Huntress Managed SAT, dive into the topics, and gain insight into why these episodes are relevant right now.
P0
2024-11-28 05:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Scammers are using fake betting game advertisements on social media to target users, with over 500 deceptive advertisements and 1,377 malicious websites identified by Group-IB CERT. These scams promise quick money but are designed to steal personal data and funds, and this blog aims to educate users on how to recognize and protect themselves from such threats.
P0
2024-11-25 08:05 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2024-11-25 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, Huntress SOC investigators unravel the lateral movement and persistence of an interesting threat actor and their novel infrastructure
P0
2024-11-21 12:00 UTC
Government
NIST Cybersecurity Insights · Katerina Megas, Michael Fagan · indexed 2026-08-15 20:45 UTC
In May 2020, NIST published Foundational Cybersecurity Activities for IoT Device Manufacturers (NIST IR 8259), which describes recommended cybersecurity activities that manufacturers should consider performing before their IoT devices are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of IoT device compromises and the attacks performed using c…
P0
2024-11-21 09:33 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.
P0
2024-11-19 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress joins the Microsoft Intelligent Security Association to enhance Microsoft tools for SMBs, delivering stronger defenses against today’s most advanced cyber threats.
P0
2024-11-18 14:37 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how adversaries are using tools like EDRSilencer to tamper with EDR communications and learn how you can fight back.
P0
2024-11-18 12:00 UTC
Government
NIST Cybersecurity Insights · Marian Merritt · indexed 2026-08-15 20:45 UTC
Cybersecurity is a fast-growing field, with a constant need for skilled professionals. But unlike other professions — like medicine or aviation — there’s no clear-cut pathway to qualifying for cybersecurity positions. For employers and job seekers alike, this can make the journey to building a team (or entering a successful cybersecurity career) feel uncertain. Enter the registered apprenticeship program — a proven method for developing skilled talent in cybersecurity that benefits both the emp…
P0
2024-11-18 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
MFA could be the thing that stops your payroll money from disappearing in a wire transaction. So why do we treat it as an optional inconvenience?
P0
2024-11-15 05:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Know the need to catch mules early in their operations to protect you from severe risks, including large-scale money laundering, compliance breaches, and business and customer disruptions.
P0
2024-11-15 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Le 8 novembre 2024, Palo Alto Networks a publié un avis de sécurité relatif à une vulnérabilité critique dans certains pare-feux Palo Alto Networks. Elle permet à un attaquant non authentifié d'exécuter du code arbitraire à distance sur l'interface d'administration des équipements. L'éditeur...
P0
2024-11-13 12:00 UTC
Government
NIST Cybersecurity Insights · Bill Fisher, Ryan Galluzzo · indexed 2026-08-15 20:45 UTC
If you are interested in the world of digital identities, you have probably heard some of the buzzwords that have been floating around for a few years now… “verifiable credential,” “digital wallet,” “mobile driver’s license” or “mDL.” These terms, among others, all reference a growing ecosystem around what we are calling “verifiable digital credentials.” But what exactly is a verifiable digital credential? Take any physical credential you use in everyday life – your driver’s license, your medic…
P0
2024-11-13 05:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2024-11-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
ITDR is the latest must-know acronym. But what is it? And why does it matter? Let Huntress break down the essentials of identity threat detection and response, and learn why it’s critical for your defenses.
P0
2024-11-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Safeguard holiday tech gifts for kids this season—secure their devices, protect privacy, and build lifelong safety habits. Feat. resources from our exclusive Fireside Chat.
P0
2024-11-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in GCP's Vertex AI service allows privilege escalation and unauthorized access to sensitive LLM models. Attackers can exfiltrate these models by exploiting misconfigurations in access controls and service bindings. By exploiting custom job permissions, researchers were able to escalate their privileges and gain unauthorized access to all data services in the project. In addition, deploying a poisoned model in Vertex AI led to the exfiltration of all other fine-tuned models, posi…
P10
2024-11-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the highlights of Huntress Capture the Flag 2024, where teams cracked complex cyber challenges in a month-long journey of reverse engineering and malware analysis.
P0
2024-11-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Multiple vulnerabilities were discovered in Google's Cloud Architecture Diagramming Tool, including XSS, unauthorized access to user data, and misconfigured storage buckets. The issues allowed accessing sensitive customer information and potentially executing arbitrary code. Google ultimately decommissioned the service due to the severity of the flaws.
P0
2024-11-08 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Multiple security vulnerabilities were identified in data.all, an open source development framework for building data marketplaces on AWS. The issues affect versions 1.0.0 through 2.6.0 and include problems with authentication token invalidation, unauthorized operations on DataSets and Environments, incorrect object-level authorizations, potential access to sensitive data via logs, and unauthorized mutating update operations on notification records.
P0
2024-11-07 07:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Waiting for risks to be presented to you rather than actively hunting them down? After reading this, you might consider a shift in approach to improve detection and proactively counter sophisticated attacks.
P0
2024-11-07 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Leaderboards and Manager Notifications are the new way to motivate learners and track progress in Huntress Managed SAT.
P0
2024-11-06 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how the Health Infrastructure Security and Accountability Act aims to enforce stricter cybersecurity standards across the healthcare sector.
P0
2024-11-05 19:57 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore how the Huntress Neighborhood Watch Program has grown and how it empowers MSPs with Managed ITDR, Managed EDR, and more.
P0