Catch the latest: KnowBe4 flaws, SEC’s MOVEit probe, SOCRadar hacking response

August 11, 2024
1 min read

TLDR:

  • Chinese hackers exploit old Windows vulnerability
  • Cyber Threat Intelligence Capability Maturity Model created

SecurityWeek’s cybersecurity news roundup covers stories such as Chinese hackers leveraging an old Windows vulnerability, the creation of the Cyber Threat Intelligence Capability Maturity Model, vulnerabilities in Johnson Controls’ exacqVision, and a browser vulnerability dubbed “0.0.0.0 Day.” In addition, the article discusses CrowdStrike’s 2024 Threat Hunting Report, vulnerabilities in KnowBe4 products, police recovering $40 million lost in a BEC scam, the SEC ending the MOVEit probe, and the rebranding of the ransomware group Royal as BlackSuit. SOCRadar responds to hacking claims, and a token exposure in Python repositories is highlighted. Lastly, a man is charged for helping North Korean IT workers, and JFrog discovers a token that could have led to a major Python supply chain attack.

Latest from Blog

Top 20 Linux Admin Tools for 2024

TLDR: Top Linux Admin Tools in 2024 Key points: Linux admin tools streamline system configurations, performance monitoring, and security management. Popular Linux admin tools include Webmin, Puppet, Zabbix, Nagios, and Ansible. Summary

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives