April 9, 2024 at 11:09PM

■■■□□ Data-Leak: SAR (Saudi Arabia Railways) Allegedly Compromised: 400K Records on a Hacking Forum. According to the post, the database contains data such as first names, middle names, last names, phone numbers, email addresses, ID numbers, and dates of birth. The systems are likely vulnerable to the attack. https://t.me/cKure/13817

April 9, 2024 at 06:03PM

■■■■□ Attackers Using Obfuscation Tools to Deliver Multi-Stage Malware via Invoice Phishing. https://thehackernews.com/2024/04/attackers-using-obfuscation-tools-to.html https://t.me/cKure/13816

April 8, 2024 at 11:54PM

■■■■■ Critical takeover vulnerabilities in 92,000 D-Link devices under active exploitation Initially mentioned here: https://t.me/ckuRED/381 https://arstechnica.com/security/2024/04/hackers-actively-exploit-critical-remote-takeover-vulnerabilities-in-d-link-devices/ https://t.me/cKure/13813

April 8, 2024 at 03:52AM

A new class of vulnerability (on a lighter note). An interesting thread on watching police body cam footages. https://twitter.com/vxunderground/status/1777121604574560462 https://t.me/cKure/13811

April 8, 2024 at 03:29AM

■□□□□ Raw email thread of xz-utils as part of supply chain attack on open source software. https://www.mail-archive.com/search?l=xz-devel%40tukaani.org&q=subject:%22%5C%5Bxz%5C-devel%5C%5D+xz%5C-java+and+newer+java%22&o=newest https://t.me/cKure/13810

April 8, 2024 at 02:36AM

■■■■■ What we know about the xz Utils backdoor that almost infected the world. https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/ https://t.me/cKure/13809

April 8, 2024 at 02:31AM

■■■□□ Why a near-miss cyberattack put US officials and the tech industry on edge. https://www.reuters.com/technology/cybersecurity/why-near-miss-cyberattack-put-us-officials-tech-industry-edge-2024-04-05/ https://t.me/cKure/13808