TLDR

TLDR Information Security 2024-05-15

Apple Backports patches 🍏, Build Provenance in homebrew 🍻, Cross platform stalker tracking 🕵️‍♂️

What's next for SASE? Get the inside scoop at InterSECt 2024 (Sponsor)

🔓
Attacks & Vulnerabilities

Apple Backports Fixes for 0-Day Exploited in Attacks to Older iPhones (2 minute read)

Ebury Botnet Infected 400K Linux Servers Since 2009 (4 minute read)

Christie's Art Auctions Hit By A Cyber Attack (2 minute read)

🧠
Strategies & Tactics

LNK File Disguised as Certificate Distributing RokRAT Malware (5 minute read)

Unmasking Tycoon 2FA: A Stealthy Phishing Kit Used to Bypass Microsoft 365 and Google MFA (7 minute read)

Leveraging DNS Tunneling for Tracking and Scanning (13 minute read)

🧑‍💻
Launches & Tools

Keylime (GitHub Repo)

SharpGraphView (GitHub Repo)

A peek into build provenance for Homebrew (7 minute read)

🎁
Miscellaneous

Techniques Learned from the XZ Backdoor (17 minute read)

Black Basta Ransomware Group Is Imperiling Critical Infrastructure (3 minute read)

MITRE Unveils EMB3D: A Threat-Modeling Framework for Embedded Devices (2 minute read)

⚡️
Quick Links

CISA, DHS, FBI, and International Partners Publish Guide for Protecting High-Risk Communities (4 minute read)

Apple and Google Launch Cross-Platform Feature to Detect Unwanted Bluetooth Tracking Devices (3 minute read)

Zscaler Confirms Only Isolated Test Server Was Hacked (2 minute read)

Curated news 📰, research 🧑‍🔬, and tools 🔒 for information security professionals
Join 300,000 readers for one daily email