Author: cyberknight
-
US Department of the Treasury (USDT) breached through BeyondTrust remote support platform
On December 8, 2024, the Department of the Treasury (USDT) detected a cybersecurity breach involving BeyondTrust, a third-party remote support platform. Chinese state-sponsored threat actors exploited this platform to access several Treasury employee workstations and unclassified documents.BeyondTrust, a privileged access management company, offers a Remote Support SaaS platform for remote computer access. The attackers utilized…
-
Fortinet FortiManager security vulnerability (CVE-2024-48889)
CVE-2024-48889 is an OS Command Injection vulnerability (CWE-78) identified in Fortinet’s FortiManager and FortiManager Cloud products. This flaw allows an authenticated remote attacker to execute unauthorized code or commands by sending specially crafted FGFM (FortiGate to FortiManager) requests. Affected Versions: Additionally, older FortiAnalyzer models (1000E, 1000F, 2000E, 3000E, 3000F, 3000G, 3500E, 3500F, 3500G, 3700F, 3700G,…
-
High Performance Computing and Quantum Computing (HPCQC 2024) – Seventh Edition

Cyberknight attended the High Performance Computing and Quantum Computing – Seventh Edition (HPCQC 2024) workshop, held from Thursday, 12 December 2024, at 09:00 to Friday, 13 December 2024, at 18:00 at the Tecnopolo in Bologna. See more details on:
-
Bitcoin
Bitcoin is the first decentralized cryptocurrency characterized as highly speculative, volatile, and vulnerable due to the following reasons: Overall, these characteristics make Bitcoin appealing to high-risk tolerant investors while also emphasizing its speculative, volatile, and vulnerable nature. See more details on:
-
Bootkitty UEFI bootkit malware for Linux
Bootkitty is a type of advanced bootkit malware targeting Linux systems, specifically compromising the Unified Extensible Firmware Interface (UEFI) to achieve persistence and control over the boot process. Bootkitty exploits the Linux security vulnerability (CVE-2023-40238), known as LogoFAIL, to infect computers running on a vulnerable UEFI firmware. Key Features of Bootkitty on Linux: Detection and…
-
Minerva AI

Minerva AI is an advanced language model developed by the Sapienza NLP research group at Sapienza University of Rome, led by Professor Roberto Navigli. It represents Italy’s first family of large language models (LLMs) trained from scratch with a primary focus on the Italian language. The Minerva project encompasses a range of models varying in…
-
Apple zero-day vulnerability (CVE-2024-44309)
CVE-2024-44309 is a zero-day vulnerability addressed in Apple products, including Safari, iOS, iPadOS, macOS, and visionOS. Exploiting this flaw by processing maliciously crafted web content may lead to a cross-site scripting (XSS) attack. It has been actively exploited on Intel-based Mac systems. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS…
-
Apple zero-day vulnerability (CVE-2024-44308)
CVE-2024-44308 is a zero-day vulnerability addressed in Apple products, including Safari, iOS, iPadOS, macOS, and visionOS. Exploiting this flaw by processing maliciously crafted web content could lead to arbitrary code execution. It has been actively exploited on Intel-based Mac systems. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1,…
-
HPC6
The HPC6 supercomputer, developed by Eni S.p.A. and built by Hewlett Packard Enterprise (HPE), is a highly advanced supercomputing system tailored for energy exploration and research, including seismic processing and reservoir modeling. Ranked 5th in the November 2024 TOP500 supercomputer rankings, it is currently the most powerful enterprise-focused supercomputer globally and the fastest in Europe,…
-
U.S. Election 2024 Security Update: U.S. Agencies (ODNI, FBI, and CISA) Unite to Counter Foreign Election Interference Risks.
The joint statement from the Office of the Director of National Intelligence (ODNI), the Federal Bureau of Investigation (FBI), and the Cybersecurity and Infrastructure Security Agency (CISA) focuses on countering foreign influence operations surrounding the U.S. election on November 5, 2024. Key points include: The statement emphasizes a proactive and coordinated response to protect the…
-
Operation Synergia II
Operation Synergia II, led by INTERPOL in 2024, targeted cybercrime infrastructure across 95 countries. The operation focused on 22,000 IP addresses linked to criminal activities, including phishing, malware, and ransomware. Key outcomes included the dismantling of illegal networks, the seizure of 59 servers, 43 electronic devices, and the arrest of 41 suspects. Collaborative efforts between…
-
Critical Vulnerabilities of Blockchain AI (B-AI)
The fusion of blockchain and artificial intelligence (AI) has opened new frontiers in technology. At its core, Blockchain AI can be defined as the convergence of two powerful technologies: a shared, immutable ledger that provides a transparent and tamper-resistant record of transactions, and AI systems that analyze data and make decisions based on complex machine-learning…