TLDR

TLDR Information Security 2024-03-29

PyPI Halted after Typosquatting attacks 🐍, NVidia's ChatRTX urgent patch 🩹, US Offers $10M Bounty for Change Healthcare Hackers πŸ€‘

πŸ”“
Attacks & Vulnerabilities

PyPI halted new users and projects while it fended off supply-chain attack (4 minute read)

Nvidia's new ChatGPT-like AI chatbot falls victim to high-severity security vulnerabilities - urgent ChatRTX patch issued (3 minute read)

Linux Version of DinodasRAT Spotted in Cyberattacks (3 minute read)

🧠
Strategies & Tactics

How Apple Mitigates Vulnerabilities in Installer Scripts (22 minute read)

Analysis of the MOBOX Security Breach (5 minute read)

Dissecting a complex vulnerability and achieving arbitrary code execution in Ichitaro Word (52 minute read)

πŸ§‘β€πŸ’»
Launches & Tools

FBI-tools (GitHub Repo)

Arsenal (GitHub Repo)

🎁
Miscellaneous

US offers $10M to help catch Change Healthcare hackers (4 minute read)

Diving Deeper into AI Package Hallucinations (9 minute read)

A Look at Software Composition Analysis (3 minute read)

⚑️
Quick Links

Navigating Cyber 2024 report (15 minute read)

Life After Death? IO Campaigns Linked to Notorious Russian Businessman Prigozhin Persist After His Political Downfall and Death (15 minute read)

Vultr’s New Terms of Service Claims Commercial Rights (Mastodon Thread)

Curated news πŸ“°, research πŸ§‘β€πŸ”¬, and tools πŸ”’ for information security professionals
Join 300,000 readers for one daily email