TLDR:
- Chinese hackers exploit old Windows vulnerability
- Cyber Threat Intelligence Capability Maturity Model created
SecurityWeek’s cybersecurity news roundup covers stories such as Chinese hackers leveraging an old Windows vulnerability, the creation of the Cyber Threat Intelligence Capability Maturity Model, vulnerabilities in Johnson Controls’ exacqVision, and a browser vulnerability dubbed “0.0.0.0 Day.” In addition, the article discusses CrowdStrike’s 2024 Threat Hunting Report, vulnerabilities in KnowBe4 products, police recovering $40 million lost in a BEC scam, the SEC ending the MOVEit probe, and the rebranding of the ransomware group Royal as BlackSuit. SOCRadar responds to hacking claims, and a token exposure in Python repositories is highlighted. Lastly, a man is charged for helping North Korean IT workers, and JFrog discovers a token that could have led to a major Python supply chain attack.