Catch the latest: KnowBe4 flaws, SEC’s MOVEit probe, SOCRadar hacking response

August 11, 2024
1 min read

TLDR:

  • Chinese hackers exploit old Windows vulnerability
  • Cyber Threat Intelligence Capability Maturity Model created

SecurityWeek’s cybersecurity news roundup covers stories such as Chinese hackers leveraging an old Windows vulnerability, the creation of the Cyber Threat Intelligence Capability Maturity Model, vulnerabilities in Johnson Controls’ exacqVision, and a browser vulnerability dubbed “0.0.0.0 Day.” In addition, the article discusses CrowdStrike’s 2024 Threat Hunting Report, vulnerabilities in KnowBe4 products, police recovering $40 million lost in a BEC scam, the SEC ending the MOVEit probe, and the rebranding of the ransomware group Royal as BlackSuit. SOCRadar responds to hacking claims, and a token exposure in Python repositories is highlighted. Lastly, a man is charged for helping North Korean IT workers, and JFrog discovers a token that could have led to a major Python supply chain attack.

Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and