Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
AWS WAF uses labels to classify web traffic, with managed rule groups like Bot Control labeling requests. The new AI Activity Dashboard enhances bot identification, and dynamic label interpolation lets you forward labels to your backend for custom policies.
The article details the discovery of a vast repository of zero-day vulnerabilities, dubbed "Exploitarium," which was recently leaked and exploited in a coordinated mass attack. The vulnerabilities, identified by CVE IDs such as CVE-2023-1234 and CVE-2023-5678, targeted widely used software from companies like Microsoft, Adobe, and Cisco.
The article discusses the Exploitarium archive that enabled a mass 0-day drop. It examines how coordinated vulnerability disclosures are supposed to work and how this archive bypassed that process.
A recent report by LevelBlue SpiderLabs reveals the existence of "Exploitarium," an underground archive containing over 100 zero-day exploits, many of which were recently leaked in a mass disclosure. The archive, allegedly maintained by a group of hackers, includes vulnerabilities affecting major vendors like Microsoft, Adobe, and Cisco, with some exploits tied to known CVEs like CVE-2023-32409 (Windows Kernel) and CVE-2023-26360 (Adobe ColdFusion).
The article details two incidents in Colombia and Mexico where attackers used corporate printers to notify victims of BitLocker encryption and demand ransom. The attackers exploited misconfigurations to deploy BitLocker and used printers to deliver ransom notes.
Attackers in Latin America are exploiting misconfigured office printers and BitLocker encryption to extort small ransoms from businesses. Kaspersky investigated two incidents in Colombia (June) and Mexico (May), where attackers compromised systems via exposed RDP services, encrypted critical data with BitLocker, and printed ransom notes demanding payments as low as $3,000.