Here’s a fresh take on last week’s key news, articles, interviews, and videos:
August 2024 Patch Tuesday: Anticipating a Calm Month
After a hectic July, which saw an unexpectedly large Patch Tuesday, the CrowdStrike incident, and Azure outages following a DDoS attack, many are hoping for a quieter August.
Critical Vulnerabilities in 1Password: A Risk to Your Passwords (CVE-2024-42219, CVE-2024-42218)
AgileBits confirmed that two vulnerabilities in the macOS version of 1Password could let malware steal data from its vaults and access the account unlock key.
Kickstart Your Cybersecurity Career: Expert Guidance
With the growing need for cybersecurity professionals, this article offers expert advice to help you begin your journey, providing practical tips and valuable insights.
Scaling Data Security: Insights from Bedrock Security’s CEO
Bruno Kurtic discusses the importance of data visibility in cybersecurity, explaining how effective data classification and context help organizations manage potential threats.
Understanding the FCC’s Proposal to Enhance BGP Security
Doug Madory breaks down the FCC’s plan to require major U.S. ISPs to implement RPKI Route Origin Validation (ROV) and discusses the implications for smaller ISPs and global networks.
AI Security in 2024: Staying Ahead of Emerging Threats
Kojin Oshiba shares his experience transitioning from academic research to tackling AI security challenges, providing insights into the industry’s evolving landscape.
MISP: The Open-Source Threat Intelligence Platform
MISP is a versatile platform for collecting, storing, and sharing cybersecurity indicators, aiding in incident and malware analysis.
RustScan: The Fast and Versatile Open-Source Port Scanner
RustScan combines speed and adaptability, making it a powerful tool for network scanning and security analysis.
Traceeshark: Enhancing Wireshark with Open-Source Security Plugins
Traceeshark extends Wireshark’s capabilities, allowing for detailed analysis of kernel-level events and network traffic during security investigations.
SSHamble: Testing SSH Security with an Open-Source Tool
SSHamble, a tool from runZero, helps validate SSH implementations by identifying uncommon yet dangerous misconfigurations and software flaws.
Chinese Hackers Compromise ISP to Deliver Malicious Updates
APT StormBamboo exploited a vulnerable ISP to manipulate DNS queries, allowing them to deliver malware to targeted organizations, according to Volexity researchers.
Critical Apache OFBiz Flaw Fixed: Urgent Update Required (CVE-2024-38856)
A pre-authentication RCE vulnerability in Apache OFBiz, CVE-2024-38856, could be used by remote attackers to execute arbitrary code, emphasizing the need for immediate updates.
Researchers Reveal Years-Old MotW Bypass Exploited by Threat Actors
Threat actors have been exploiting a Windows flaw related to LNK files, allowing them to bypass built-in protections and execute malicious payloads unnoticed.
Ransomware Group Targets IT Workers with New RAT
Hunters International, a ransomware group, is using a new remote access trojan (RAT) disguised as an IP scanner to infiltrate organizations, leveraging typosquatting techniques.
Roundcube Vulnerabilities Expose Email Accounts to Attack (CVE-2024-42009, CVE-2024-42008)
Two XSS vulnerabilities in Roundcube could let attackers steal emails, contacts, and passwords, as well as send messages from compromised accounts.
CrowdStrike’s Outage: Root Cause and Expert Review
CrowdStrike detailed the causes of a widespread outage affecting 8.5 million Windows machines and confirmed that external experts have been brought in to review the Falcon sensor code.
Windows Downgrade Attack Turns Patches into Zero-Days
A new downgrade attack can covertly make fully patched Windows systems vulnerable, effectively turning fixed vulnerabilities into exploitable zero-days.
Microsoft 365 Phishing Alert Disabled with a Simple Trick
A technique has been discovered that allows attackers to erase anti-phishing alerts in Microsoft 365, bypassing a key defense mechanism.
“0.0.0.0-Day” Vulnerability Threatens Chrome, Safari, and Firefox
A newly discovered vulnerability affecting Chrome, Safari, and Firefox has been used by attackers to gain unauthorized access to internal network services.
The Role of AI in Modern Cybersecurity Operations
Security operation centers (SOCs) are increasingly relying on AI to manage the overwhelming volume of data and the complexity of modern cyber threats.
Challenges of Integrating AI into ITSM
The complexities of integrating AI into IT Service Management (ITSM) are highlighted, emphasizing the risks and challenges organizations face in adopting new technologies.
Cybersecurity in Sports: Vetting Vendors for Security
As technology advances in sports, ensuring the security of interconnected systems and suppliers is becoming crucial to protecting sensitive data.
Enhancing OT Network Security with Segmentation
Network segmentation is vital for improving visibility in operational technology (OT) networks, helping to identify and manage potential threats effectively.
NIS2 Directive: Innovation Catalyst or Regulatory Burden?
The NIS2 Directive is set to bring significant cybersecurity regulation across Europe, raising questions about its impact on innovation and compliance.
AI Fills the Cybersecurity Skills Gap in Life Sciences
A growing number of life sciences companies are leveraging AI to address the cybersecurity skills gap, with adoption rates higher than in other sectors.
Securing Against GenAI Weaponization
The rise of generative AI has rendered traditional data privacy practices obsolete, requiring new strategies to protect against AI-driven threats.
AI Expected to Revolutionize IT/OT Network Management
Cisco’s latest report highlights how AI is set to transform the management of IT and OT networks, making security a central focus.
AI-Driven Phishing Scams Surge Ahead of U.S. Election
Research shows a sharp increase in AI-powered phishing scams targeting U.S. citizens as the 2024 presidential election approaches.
Email Attacks Increase by 293% in 2024
Email-based attacks have surged dramatically in 2024, with ransomware and other threats on the rise, signaling a need for stronger defenses.
Rising Cybersecurity Incidents Affecting Developer Platforms
Platforms like GitHub, Bitbucket, GitLab, and Jira are facing an increasing number of cybersecurity incidents, affecting DevSecOps teams globally.
Vulnerabilities Persist in OT/IoT Router Firmware
A report by Forescout reveals ongoing security issues in OT and IoT router firmware, with many devices running outdated software vulnerable to attacks.
Ransomware Operators Continue to Evolve
Ransomware groups are refining their tactics, operating like legitimate businesses with sophisticated strategies and insider recruitment.
Internal Audit Teams Shift Focus to Risk Management
Internal audit teams are increasingly being tasked with risk-related responsibilities, reflecting a broader shift towards proactive cybersecurity measures.
Shorter TLS Certificate Lifespans Pose Management Challenges
The shift to 90-day TLS certificates is expected to complicate security management, with many organizations unprepared for the transition.
Malware-as-a-Service Lowers Barriers for Cybercriminals
The rise of Malware-as-a-Service (MaaS) and Ransomware-as-a-Service (RaaS) is making it easier for cybercriminals to launch sophisticated attacks.
Black Hat USA 2024 Startup City: Inside Look
Take a peek inside Black Hat USA 2024’s Startup City, featuring emerging cybersecurity vendors and their innovative solutions.
Black Hat USA 2024 Arsenal: Showcasing New Security Tools
Explore the latest open-source security tools showcased at Black Hat USA 2024’s Arsenal by ToolsWatch.
Whitepaper: Managing Multicloud Environments
As multicloud solutions become more prevalent, this whitepaper discusses the evolving role of cloud security in driving business success.
Download: CIS Critical Security Controls v8.1
The latest version of the CIS Critical Security Controls offers updated best practices to strengthen your organization’s cybersecurity posture.
New Infosec Products of the Week: August 9, 2024
Check out the newest infosec products from the past week, featuring releases from leading cybersecurity companies like Rapid7, Elastic, and Veza.



