In the security news: You got so many CVEs you need your own, dedicated, vulnerability scanner, melting your neighbors with hacking, The FDA’s SBOM and OSS, when the vulnerability scanner has a vulnerability, violating CISA directives at scale, make 2FA a little easier with this device, NSA’s BlackLotus mitigation guide: who needs those certificate...
In this segment we welcome Carlos Perez back to the show! Carlos will discuss methods we can use to hide one systems and cover our tracks. We'll cover how on a system (as administrator) the blue team's struggle using default logs or even on a default install of Sysmon to detect an attacker. Attackers can selectively disable modern event log provide...
BleepingComputer reports that internet-facing Linux and Internet of Things devices have been targeted by brute-force attacks involving the distribution of a trojanized OpenSSH package to facilitate compromise and SSH credential exfiltration.
U.S.- and India-based organizations have been targeted by the new MULTI#STORM phishing campaign that involved a multi-stage attack chain concluding with the deployment of Warzone RAT, also known as Ave Maria, Quasar RAT, and various other remote access trojan backdoors, The Hacker News reports.