Weekly Recap: Launching Your Cybersecurity Career and Patch Tuesday Insights

Here’s a fresh take on last week’s key news, articles, interviews, and videos:

August 2024 Patch Tuesday: Anticipating a Calm Month

After a hectic July, which saw an unexpectedly large Patch Tuesday, the CrowdStrike incident, and Azure outages following a DDoS attack, many are hoping for a quieter August.

Critical Vulnerabilities in 1Password: A Risk to Your Passwords (CVE-2024-42219, CVE-2024-42218)

AgileBits confirmed that two vulnerabilities in the macOS version of 1Password could let malware steal data from its vaults and access the account unlock key.

Kickstart Your Cybersecurity Career: Expert Guidance

With the growing need for cybersecurity professionals, this article offers expert advice to help you begin your journey, providing practical tips and valuable insights.

Scaling Data Security: Insights from Bedrock Security’s CEO

Bruno Kurtic discusses the importance of data visibility in cybersecurity, explaining how effective data classification and context help organizations manage potential threats.

Understanding the FCC’s Proposal to Enhance BGP Security

Doug Madory breaks down the FCC’s plan to require major U.S. ISPs to implement RPKI Route Origin Validation (ROV) and discusses the implications for smaller ISPs and global networks.

AI Security in 2024: Staying Ahead of Emerging Threats

Kojin Oshiba shares his experience transitioning from academic research to tackling AI security challenges, providing insights into the industry’s evolving landscape.

MISP: The Open-Source Threat Intelligence Platform

MISP is a versatile platform for collecting, storing, and sharing cybersecurity indicators, aiding in incident and malware analysis.

RustScan: The Fast and Versatile Open-Source Port Scanner

RustScan combines speed and adaptability, making it a powerful tool for network scanning and security analysis.

Traceeshark: Enhancing Wireshark with Open-Source Security Plugins

Traceeshark extends Wireshark’s capabilities, allowing for detailed analysis of kernel-level events and network traffic during security investigations.

SSHamble: Testing SSH Security with an Open-Source Tool

SSHamble, a tool from runZero, helps validate SSH implementations by identifying uncommon yet dangerous misconfigurations and software flaws.

Chinese Hackers Compromise ISP to Deliver Malicious Updates

APT StormBamboo exploited a vulnerable ISP to manipulate DNS queries, allowing them to deliver malware to targeted organizations, according to Volexity researchers.

Critical Apache OFBiz Flaw Fixed: Urgent Update Required (CVE-2024-38856)

A pre-authentication RCE vulnerability in Apache OFBiz, CVE-2024-38856, could be used by remote attackers to execute arbitrary code, emphasizing the need for immediate updates.

Researchers Reveal Years-Old MotW Bypass Exploited by Threat Actors

Threat actors have been exploiting a Windows flaw related to LNK files, allowing them to bypass built-in protections and execute malicious payloads unnoticed.

Ransomware Group Targets IT Workers with New RAT

Hunters International, a ransomware group, is using a new remote access trojan (RAT) disguised as an IP scanner to infiltrate organizations, leveraging typosquatting techniques.

Roundcube Vulnerabilities Expose Email Accounts to Attack (CVE-2024-42009, CVE-2024-42008)

Two XSS vulnerabilities in Roundcube could let attackers steal emails, contacts, and passwords, as well as send messages from compromised accounts.

CrowdStrike’s Outage: Root Cause and Expert Review

CrowdStrike detailed the causes of a widespread outage affecting 8.5 million Windows machines and confirmed that external experts have been brought in to review the Falcon sensor code.

Windows Downgrade Attack Turns Patches into Zero-Days

A new downgrade attack can covertly make fully patched Windows systems vulnerable, effectively turning fixed vulnerabilities into exploitable zero-days.

Microsoft 365 Phishing Alert Disabled with a Simple Trick

A technique has been discovered that allows attackers to erase anti-phishing alerts in Microsoft 365, bypassing a key defense mechanism.

“0.0.0.0-Day” Vulnerability Threatens Chrome, Safari, and Firefox

A newly discovered vulnerability affecting Chrome, Safari, and Firefox has been used by attackers to gain unauthorized access to internal network services.

The Role of AI in Modern Cybersecurity Operations

Security operation centers (SOCs) are increasingly relying on AI to manage the overwhelming volume of data and the complexity of modern cyber threats.

Challenges of Integrating AI into ITSM

The complexities of integrating AI into IT Service Management (ITSM) are highlighted, emphasizing the risks and challenges organizations face in adopting new technologies.

Cybersecurity in Sports: Vetting Vendors for Security

As technology advances in sports, ensuring the security of interconnected systems and suppliers is becoming crucial to protecting sensitive data.

Enhancing OT Network Security with Segmentation

Network segmentation is vital for improving visibility in operational technology (OT) networks, helping to identify and manage potential threats effectively.

NIS2 Directive: Innovation Catalyst or Regulatory Burden?

The NIS2 Directive is set to bring significant cybersecurity regulation across Europe, raising questions about its impact on innovation and compliance.

AI Fills the Cybersecurity Skills Gap in Life Sciences

A growing number of life sciences companies are leveraging AI to address the cybersecurity skills gap, with adoption rates higher than in other sectors.

Securing Against GenAI Weaponization

The rise of generative AI has rendered traditional data privacy practices obsolete, requiring new strategies to protect against AI-driven threats.

AI Expected to Revolutionize IT/OT Network Management

Cisco’s latest report highlights how AI is set to transform the management of IT and OT networks, making security a central focus.

AI-Driven Phishing Scams Surge Ahead of U.S. Election

Research shows a sharp increase in AI-powered phishing scams targeting U.S. citizens as the 2024 presidential election approaches.

Email Attacks Increase by 293% in 2024

Email-based attacks have surged dramatically in 2024, with ransomware and other threats on the rise, signaling a need for stronger defenses.

Rising Cybersecurity Incidents Affecting Developer Platforms

Platforms like GitHub, Bitbucket, GitLab, and Jira are facing an increasing number of cybersecurity incidents, affecting DevSecOps teams globally.

Vulnerabilities Persist in OT/IoT Router Firmware

A report by Forescout reveals ongoing security issues in OT and IoT router firmware, with many devices running outdated software vulnerable to attacks.

Ransomware Operators Continue to Evolve

Ransomware groups are refining their tactics, operating like legitimate businesses with sophisticated strategies and insider recruitment.

Internal Audit Teams Shift Focus to Risk Management

Internal audit teams are increasingly being tasked with risk-related responsibilities, reflecting a broader shift towards proactive cybersecurity measures.

Shorter TLS Certificate Lifespans Pose Management Challenges

The shift to 90-day TLS certificates is expected to complicate security management, with many organizations unprepared for the transition.

Malware-as-a-Service Lowers Barriers for Cybercriminals

The rise of Malware-as-a-Service (MaaS) and Ransomware-as-a-Service (RaaS) is making it easier for cybercriminals to launch sophisticated attacks.

Black Hat USA 2024 Startup City: Inside Look

Take a peek inside Black Hat USA 2024’s Startup City, featuring emerging cybersecurity vendors and their innovative solutions.

Black Hat USA 2024 Arsenal: Showcasing New Security Tools

Explore the latest open-source security tools showcased at Black Hat USA 2024’s Arsenal by ToolsWatch.

Whitepaper: Managing Multicloud Environments

As multicloud solutions become more prevalent, this whitepaper discusses the evolving role of cloud security in driving business success.

Download: CIS Critical Security Controls v8.1

The latest version of the CIS Critical Security Controls offers updated best practices to strengthen your organization’s cybersecurity posture.

New Infosec Products of the Week: August 9, 2024

Check out the newest infosec products from the past week, featuring releases from leading cybersecurity companies like Rapid7, Elastic, and Veza.

More Articles & Posts