Vulnerabilities
- Microsoft June 2024 Patch Tuesday fixes 51 flaws, 18 RCEs
- Microsoft Urges Windows Admins to Patch Microsoft Message Queuing RCE Flaw
- Critical Microsoft Outlook Zero-Click RCE Flaw Executes as Email is Opened
- New Windows Server KB5039227 and KB5039217 updates fix LSASS crashes
- PHP Updates Urged Over Critical Vuln That Could Lead To RCE
- VLC Media Player Vulnerabilities Allow Remote Code Execution
- JetBrains warns of IntelliJ IDE bug exposing GitHub access tokens
- VS Code Marketplace Flaw Let Attackers Include Malicious Extensions
- TellYouThePass ransomware exploits recent PHP RCE flaw to breach servers
- Popular Biometric Terminal Vulnerable To QR Code SQL Injection
- Check-in terminals used by thousands of hotels leak guest info
- Arm Warns Of Mali GPU Kernel Driver Flaws Exploited In The Wild
- Netgear WNR614 flaws allow device takeover, no fix available
- Quit Using EmailGPT as Vulnerability Risks Users Data
- Exploit for critical Veeam auth bypass available, patch now
- Hackers Attack ThinkPHP By Injecting Payload From Remote Servers
- PoC Exploit Released for High Severity Apache HugeGraph RCE flaw
- CISA Urges Administrators To Review Newly Released Six ICS Advisories
- Bitdefender GravityZone Flaw Let Hackers Launch SSRF Attacks
- Huge Surge in Attacks Exploiting Check Point VPN Zero-Day Vulnerability
TTP
- ComfyUI Users Targeted by Malicious Code Designed to Steal Login Credentials
- Safari, Microsoft Edge, & DuckDuckGo Spoofing Flaws Impacting Millions of Users
- Chinese hackers breached 20,000 FortiGate systems worldwide
- New Warmcookie Windows backdoor pushed via fake job offers
- Hackers Used Homemade Mobile Antenna To Send Thousands Of Smishing Messages
- Gitloker attacks abuse GitHub notifications to push malicious OAuth apps
- Free Android VPNs Suffering Encryption Failures, New Report
- APT Hackers Abusing Google & OneDrive To Host Malicious Scripts
- SSLoad Malware Employs MSI Installer To Kick-Start Delivery Chain
- Chinese Hackers using New Noodle RAT to Attack Linux Servers
- Hackers Weaponizing MSC Files In Targeted Attack Campaign
- Hackers Using OTP Bots To Bypass Two-Factor Authentication
- Beware of Fake Google Chrome Update Pop-Ups that Installs Malware
Breaches
- Pure Storage Data Breach Following Snowflake Hack: LDAP Usernames, Email Addresses Exposed
- Cylance confirms data breach linked to ‘third-party’ platform
- 23andMe data breach under investigation in UK and Canada
- Frontier warns 750,000 of a data breach after extortion threats
- Christie’s Says Ransomware Attack Impacts 45,000 People
Note worthy
- Windows 11 KB5039212 update released with 37 changes, fixes
- Windows 10 KB5039211 update released with new feature, 12 fixes
- Fortinet to Acquire AI-Powered Cloud Security Platform Lacework
- Apple set to launch a new password management app for iPhone and Mac Users
- Microsoft makes Windows Recall opt-in, secures data with Windows Hello
- Spam Blocklist SORBS Closed By Its Owner, Proofpoint
Miscellaneous
- Firefox 127 Released With patch for 15 Vulnerabilities
- Chrome 126 Released With Patch For 21 Security Flaws
- Kali Linux 2024.2 Released With New Hacking Tools
- Parrot Security OS 6.1 Released – What’s New
Stream Link
https://youtube.com/live/qgMnkIK4L7s?list=PLSJyoFloAkDo93fi_o0WJD9-gJzfpWizG