Manuka – A Modular OSINT Honeypot For Blue Teamers

From kitploit.com

Manuka is an Open-source intelligence (OSINT) honeypot that monitors reconnaissance attempts by threat actors and generates actionable intelligence for Blue Teamers. It creates a simulated environment consisting of staged OSINT sources, such as social media profiles and leaked credentials, and tracks signs of adversary interest, closely aligning to MITRE’s PRE-ATT&CK framework. Manuka gives Blue Teams additional visibility of the pre-attack reconnaissance phase and generates early-warning signals for defenders.

Read more…

New Chrome 0-day Under Active Attacks – Update Your Browser Now

From thehackernews.com

chrome zero day vulnerability

Attention readers, if you are using Google Chrome browser on your Windows, Mac, or Linux computers, you need to update your web browsing software immediately to the latest version Google released earlier today.

Google released Chrome version 86.0.4240.111 today to patch several security high-severity issues, including a zero-day vulnerability that has been exploited in the wild by attackers to hijack targeted computers.

Read more…

Microsoft did some research. Now it’s angry about what it found

From zdnet.com

microsoft-plans-for-singlescreen-windows-5f184d80ef2c1c64094aab6a-1-jul-27-2020-8-57-14-poster.jpg

I’m quite used to hearing that Microsoft has annoyed someone.

Usually, it’s a Windows user who’s angry about Redmond’s keenness to slip unwanted products onto their screens.

I was rather moved, then, to hear that Microsoft itself is enduring conniptions of the most fundamental kind.

You see, the company recently commissioned research company YouGov to ask 5,000 registered voters about their innermost feelings. One or two deeply felt highlights emerged.

Read more…

Potential Covid-19 Vaccine Pharmacy Company Hit By Cyber Attack

From hackersonlineclub.com

Covid-19 Vaccine Cyberattack

Hackers are trying to steal the Covid-19 Vaccine code. A pharmaceutical company Dr. Reddy’s has suffered a cyber attack.

According to the report, the company is researching on Covid-19 Vaccine. A data breach impacted its laboratory plants in India, Brazil, Russia, UK, and the USA.

Dr. Reddy’s Laboratories is an Indian multinational pharmaceutical company based in INDIA and overseas.

Read more…

HPE fixes maximum severity remote auth bypass bug in SSMC console

From bleepingcomputer.com

HPE fixes maximum severity remote auth bypass bug in SSMC console

Hewlett Packard Enterprise (HPE) has fixed a maximum severity remote authentication bypass vulnerability affecting the company’s HPE StoreServ Management Console (SSMC) data center storage management solution.

HPE SSMC is a management and reporting console for HPE Primera (data storage for mission-critical apps) and HPE 3PAR StoreServ systems (AI-powered storage cloud service providers) data center arrays.

Read more…

YouTube-dl removed from GitHub after RIAA DMCA notice

From bleepingcomputer.com

YouTube-dl

The Recording Industry Association of America, Inc. (RIAA) has taken down YouTube-dl’s GitHub repositories using a DMCA takedown notice.

YouTube-dl is an extremely popular command-line program used to download multimedia content from YouTube.com and other sites. The project used GitHub repositories to host the program’s source code and compiled executables that could be downloaded by users.

Read more…

Five worthy reads: Preparing an incident response plan for the pandemic and beyond

From blogs.manageengine.com

Illustration by Ilamparithi Raju

Five worthy reads is a regular column on five noteworthy items we’ve discovered while researching trending and timeless topics. With the rising concern over cyberattacks in the distributed workforce, this week we explore the concept of cybersecurity incident response during a pandemic.

The new normal of a distributed workforce has given rise to advancements in the cyber threat landscape. Global organizations have seen a 148 percent increase in ransomware attacks, with a majority of them targeting the financial and the healthcare industries. The global effect and influence of popular interests, such as COVID-19 health information or elections in the United States, paves the way for phishing attacks via emails and unsecured devices. 

Read more…