ICYMI: 2025-01-14
Latest Headlines
- Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation 
- Google OAuth Vulnerability Exposes Millions via Failed Startup Domains 
- Illicit HuiOne Telegram Market Surpasses Hydra, Hits $24 Billion in Crypto Transactions 
- Zero-Day Vulnerability Suspected in Attacks on Fortinet Firewalls with Exposed Interfaces 
- Russian-Linked Hackers Target Kazakhstan in Espionage Campaign with HATVIBE Malware 
- CISA Adds Second BeyondTrust Flaw to KEV Catalog Amid Active Attacks 
- 5 Best VPN Services (2024): For Routers, PC, iPhone, Android, and More 
- The ‘Largest Illicit Online Marketplace’ Ever Is Growing at an Alarming Rate, Report Says 
- Allstate car insurer sued for tracking drivers without permission 
- WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites 
- US govt says North Korea stole over $659 million in crypto last year 
- Windows 10 KB5049981 update released with new BYOVD blocklist 
- Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws 
- Windows 11 KB5050009 & KB5050021 cumulative updates released 
- Google OAuth flaw lets attackers gain access to abandoned accounts 
- FBI wipes Chinese PlugX malware from over 4,000 US computers 
- Hackers use FastHTTP in new high-speed Microsoft 365 password attacks 
- Fortinet warns of auth bypass zero-day exploited to hijack firewalls 
- Microsoft 365 apps crash on Windows Server after Office update 
– MTZ