Cyber Defense Advisors

Year: 2024

  • by
  • June 11, 2024

Arm Warns of Actively Exploited Zero-Day Vulnerability in Mali GPU Drivers

Arm is warning of a security vulnerability impacting Mali GPU Kernel Driver that it said has been actively exploited in the wild. Tracked as CVE-2024-4610, the use-after-free issue impacts the following products – Bifrost GPU Kernel Driver (all versions from r34p0 to r40p0) Valhall GPU Kernel Driver (all versions from r34p0 to r40p0) “A local […]

Cyber News

Med Students Save the Day in London Hospitals Cyberattack

Med Students Save the Day in London Hospitals Cyberattack Emergency Response Highlights Need for Robust Disaster Recovery Strategies When ransomware hits, who you gonna call? Medical students, apparently. A major cyberattack by the Russian group Qilin has thrown London hospitals into disarray, disrupting critical services like blood transfusions and test results. The pathology firm Synnovis […]

Cyber Thoughts
  • by
  • June 10, 2024

More_eggs Malware Disguised as Resumes Targets Recruiters in Phishing Attack

Cybersecurity researchers have spotted a phishing attack distributing the More_eggs malware by masquerading it as a resume, a technique originally detected more than two years ago. The attack, which was unsuccessful, targeted an unnamed company in the industrial services industry in May 2024, Canadian cybersecurity firm eSentire disclosed last week. “Specifically, the targeted individual was […]

Cyber News
  • by
  • June 10, 2024

Cybersecurity CPEs: Unraveling the What, Why & How

Staying Sharp: Cybersecurity CPEs Explained Perhaps even more so than in other professional domains, cybersecurity professionals constantly face new threats. To ensure you stay on top of your game, many certification programs require earning Continuing Professional Education (CPE) credits. CPEs are essentially units of measurement used to quantify the time and effort professionals spend on […]

Cyber News
  • by
  • June 10, 2024

Azure Service Tags Vulnerability: Microsoft Warns of Potential Abuse by Hackers

Microsoft is warning about the potential abuse of Azure Service Tags by malicious actors to forge requests from a trusted service and get around firewall rules, thereby allowing them to gain unauthorized access to cloud resources. “This case does highlight an inherent risk in using service tags as a single mechanism for vetting incoming network […]

Cyber News
  • by
  • June 10, 2024

Exploiting Mistyped URLs

@Levi B. “Those who are not familiar with the term “bit-squatting” should look that up” Are you sure you want to go down that rabbit hole? It’s an instant of a general class of problems that are never going to go away. And why in “Web servers would usually have error-correcting (ECC) memory, in which […]

Cyber News
  • by
  • June 10, 2024

Google Takes Down Influence Campaigns Tied to China, Indonesia, and Russia

Google has revealed that it took down 1,320 YouTube channels and 1,177 Blogger blogs as part of a coordinated influence operation connected to the People’s Republic of China (PRC). “The coordinated inauthentic network uploaded content in Chinese and English about China and U.S. foreign affairs,” Google Threat Analysis Group (TAG) researcher Billy Leonard said in […]

Cyber News
  • by
  • June 10, 2024

Sticky Werewolf Expands Cyber Attack Targets in Russia and Belarus

Cybersecurity researchers have disclosed details of a threat actor known as Sticky Werewolf that has been linked to cyber attacks targeting entities in Russia and Belarus. The phishing attacks were aimed at a pharmaceutical company, a Russian research institute dealing with microbiology and vaccine development, and the aviation sector, expanding beyond their initial focus of […]

Cyber News
  • by
  • June 8, 2024

New PHP Vulnerability Exposes Windows Servers to Remote Code Execution

Details have emerged about a new critical security flaw impacting PHP that could be exploited to achieve remote code execution under certain circumstances. The vulnerability, tracked as CVE-2024-4577, has been described as a CGI argument injection vulnerability affecting all versions of PHP installed on the Windows operating system. According to DEVCORE security researchers, the shortcoming […]

Cyber News