Penetration Testing ROI Calculator: risk3sixty.com/whitepaper/pen...
Week of May 19 Ransomware Stats: / urn:li:activity:720120...
Chrome has 4 Zero-Days in One Month
Executive Summary:
Google has released a new Chrome update to fix its fourth zero-day vulnerability in two weeks. The flaw, identified as CVE-2024-5274, involves a type confusion issue in the V8 JavaScript and WebAssembly engine and has been exploited in the wild. Despite limited details on the exploitation, the vulnerability was reported by Google's Threat Analysis Group and Chrome Security. Users are urged to update to the latest Chrome version to ensure protection against this and other recent vulnerabilities.
Additional Reading:
www.securityweek.com/google-p...
North Korean Threat Actors Increase Fake Professional Opportunities
Executive Summary:
Microsoft released new research on a North Korean threat actor dubbed Moonstone Sleet, known to employ a mix of traditional and innovative attack techniques. Formerly known as Storm-1789, Moonstone Sleet targets organizations with fake job opportunities, trojanized software, malicious games, and custom ransomware called FakePenny. The group is distinct yet overlaps with other North Korean actors like Diamond Sleet.
This new research further demonstrates the tactics, techniques, and procedures (TTPs) used by the Nation-State where professional opportunities such as cold email outreach, business development proposals, and obtaining Western tech jobs are used to advance their agenda.
Additional Reading:
www.microsoft.com/en-us/secur...
arstechnica.com/security/2024...
00:00 Introduction
00:18 Ransomware Activity
02:08 Chrome has 4 Zero-Days in One Month
05:10 North Korean Threat Actors Known as Moonstone Sleet
12:22 Outro
Негізгі бет Ғылым және технология Cybersecurity News: Ransomware Update, Chromium Zero-Days, Moonstone Sleet
Пікірлер