Month: December 2024


  • 6 AI-Related Security Trends to Watch in 2025

    * [Cyber Risk](/cyber-risk)* [Application Security](/application-security)* [Threat Intelligence](/threat-intelligence)6 AI-Related Security Trends to Watch in 2025 6 AI-Related Security Trends to Watch…


  • Analysis of Attack Cases Against Korean Solutions by the Andariel Group (SmallTiger)

    The Andariel group has been targeting various South Korean software solutions, particularly asset management and document management systems. Recent attacks…


  • No Holiday Season for Attackers, (Tue, Dec 31st)

    [No Holiday Season for Attackers](/forums/diary/No+Holiday+Season+for+Attackers/31552/)=======================================================================================* * [](http://www.facebook.com/sharer.php?u=https%3A%2F%2Fisc.sans.edu%2Fforums%2Fdiary%2F31552 ‘Share on Facebook’)* [](http://twitter.com/share?text=No%20Holiday%20Season%20for%20Attackers&url=https%3A%2F%2Fisc.sans.edu%2Fforums%2Fdiary%2F31552&via=SANS_ISC ‘Share on Twitter’) **Published** : 2024-12-31. **Last Updated** :…


  • Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents

    ![U.S. Treasury Systems](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnW4uIKY7rtNoiGYo8nyYHd5Q4GOBJE2Wl-_rkjIV_2niquf9XG2YrD4kttbb6OreSiIdxwiE4vBkrzzBm20bS190-_oo09qmwp2jeTEXnlDUEkw6ue-paA2vVRIH9oQsPo6L7jCfHEAPMgvHQVrhhtp2ROEJRBgypM1uBCb7IA6obfG5TMReQs9QOadE5/s728-rw-e365/chinesehackers.png ‘U.S. Treasury Systems’)The United States Treasury Department said it suffered a ‘major cybersecurity incident’ that allowed suspected…


  • Misconfigured Kubernetes RBAC in Azure Airflow Could Expose Entire Cluster to Exploitation

    ![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjohomRDDjZyJfnjTusOWprpUGv8Yf_k2fgvGvfZqhXhusmUz1WWrkZB6yKdDXD1AOxuLmvoK4MJ88QpRBm0L_zRxNchQGVI0Ib3D3piR43BICNq823bHdXod7ADdFLWRfVlp8lChQjgZwNehps4hJf0atYyxanDBDDLLHQgfqLlXhtxbAQ-HyWs-KefebO/s728-rw-e365/main.png)Cybersecurity researchers have uncovered three security weaknesses in Microsoft’s Azure Data Factory [Apache Airflow](https://airflow.apache.org/) integration that, if successfully exploited, could…


  • China-linked actors hacked US Treasury Department

    China-linked threat actors breached the U.S. Treasury Department by hacking a remote support platform used by the agency.————————————————————————————————————————-China-linked threat actors…


  • An X user claimed a 7-Zip zero-day vulnerability, but 7-Zip’s creator says is a fake

    An X user using the handle @NSA_Employee39 disclosed a zero-day vulnerability in the open-source file archive software 7-Zip.—————————————————————————————————————————–A verified X…


  • More telcos confirm Salt Typhoon breaches as White House weighs in

    #### [Cyber-crime](/security/cyber_crime/)**10** More telcos confirm Salt Typhoon breaches as White House weighs in==================================================================**10** The intrusions allowed Beijing to ‘geolocate millions…


  • Is nowhere safe from AI slop? (Lock and Code S05E27)

    *This week on the Lock and Code podcast…*You can see it on X. You can see on Instagram. It’s flooding…


  • Massive healthcare breaches prompt US cybersecurity rules overhaul

    ![Hospital](https://www.bleepstatic.com/content/hl-images/2024/09/18/Hospital.jpg)The U.S. Department of Health and Human Services (HHS) has proposed updates to the Health Insurance Portability and Accountability Act…