OpenAI’s ChatGPT and GPT-4 Used as Lure in Phishing Email, Twitter Scams to Promote Fake OpenAI Tokens
Hoping to cash in on the massive interest around OpenAI’s GPT-4 – ChatGPT’s new multimodal model – scammers have launched phishing campaigns via email and Twitter designed to steal cryptocurrency. Check out how they’re carrying out the scams and how you can avoid becoming a victim.
ملف تصحيح من Microsoft شهر مارس الثلاثاء العناوين 76 CVEs (CVE-2023-23397)
Microsoft addresses 76 CVEs including two zero-days exploited in the wild, one of which was publicly disclosed.
يصدر مكتب التحقيقات الفيدرالي وCISA استشارة بشأن الأمن السيبراني لمجموعة Royal Ransomware Group
The FBI and CISA have released a joint Cybersecurity Advisory discussing the Royal ransomware group.
وكالات كورية جنوبية وأمريكية تنشر استشارة مشتركة بشأن برامج الفدية في كوريا الشمالية
Several South Korean and American agencies have released a joint cybersecurity advisory on North Korean state-sponsored ransomware operators.
Microsoft’s February 2023 Patch Tuesday Addresses 75 CVEs (CVE-2023-23376)
Microsoft addresses 75 CVEs including three zero-day vulnerabilities that were exploited in the wild.
ProxyNotShell، وOWASSRF، وTabShell: صحح Microsoft Exchange Servers الخاصة بك الآن
Several flaws in Microsoft Exchange Server disclosed over the last two years continue to be valuable exploits for attackers as part of ransomware and targeted attacks against organizations that have yet to patch their systems. Patching the flaws outlined below is strongly recommended.
Sandworm APT تنشر برنامج SwiftSlicer Wiper باستخدام سياسة مجموعة Active Directory
Sandworm, the Russian-backed APT responsible for NotPetya in 2017, has recently attacked an Ukrainian organization using a new wiper, SwiftSlicer.
برنامج Critical Patch Update لشهر يناير 2023 من شركة Oracle يُعالج 183 ثغرة أمنية وحالة تعرض للمخاطر شائعة
Oracle addresses 183 CVEs in its first quarterly update of quarterly with 327 patches, including 71 critical updates.
تحديث Patch Tuesday لشهر يناير 2023 من شركة Microsoft يُعالج 98 ثغرة أمنية وحالة تعرض للمخاطر شائعة (CVE-2023-21674)
Microsoft addresses 98 CVEs including a zero-day vulnerability that was exploited in the wild.
CVE-2022-47523: الثغرة الأمنية SQL Injection في ManageEngine Password Manager Pro، وPAM360، وAccess Manager Plus
Zoho patches a newly disclosed high-severity SQL injection flaw in several ManageEngine products; attackers have historically targeted several ManageEngine products over the last three years.
CVE-2022-47939: ثغرة أمنية حرجة في تنفيذ التعليمات البرمجية عن بُعد في نظام التشغيل Linux Kernel
A critical remote code execution vulnerability in the Linux kernel has been publicly disclosed by Trend Micro's Zero Day Initiative in its ZDI-22-1690 advisory. The vulnerability has been given a CVSSv3 of 10.0. There are no reports of active exploitation.
CVE-2022-37958: الأسئلة المتكررة حول الثغرة الأمنية الحرجة لآلية SPNEGO NEGOEX من Microsoft
Microsoft recently reclassified a vulnerability in SPNEGO NEGOEX, originally patched in September, after a security researcher discovered that it can lead to remote code execution. Organizations are urged to apply these patches as soon as possible.