> TODAY'S SUMMARY (3 articles)
Today's cyber news highlights significant threats and trends impacting the cybersecurity landscape. CrowdSec reported a breach where an attacker accessed and copied 170 private GitHub repositories using an ex-employee's account, emphasizing risks related to insider threats and account management. Additionally, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild and a continued focus on securing open-source software. Meanwhile, Flock is facing a decline in contracts for its license plate readers, leading to voluntary severance offerings for employees, showcasing the impact of public sentiment on technology adoption.
|
// AI-powered summary generated at 08:00
It was discovered that phpseclib did not perform padding validation in
constant time when using AES in CBC mode. A remote attacker could possibly
use this issue to conduct a padding oracle timing attack and obtain
sensitive information.
The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. B...
The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion.
The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek.
The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base.
The post Cisco warns customers of actively exploited zero-day in email gateways appeared first on CyberScoop.
Florian Stuhlmann discovered that Shibboleth incorrectly escaped input
when using the ODBC storage plugin. A remote attacker could possibly use
this issue to perform SQL injection attacks and obtain sensitive
information.
ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training.
A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.
The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data appeared first on SecurityWeek.
I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems.
The emerging malware family, codenamed BambooToken, is assessed to be active since at lea...
It was discovered that Snapcast incorrectly handled crafted JSON-RPC
requests. A remote attacker could possibly use this issue to execute
arbitrary code or obtain sensitive information.
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations
Guillem Lefait discovered that Suricata-Update did not properly validate
destination paths when extracting files referenced by downloaded rule
archives. An attacker could possibly use this issue to write arbitrary
files outside the configured rules directory.
Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine's National Cybersecurity Coordination Center.
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
A completed import does not guarantee complete visibility. Semantics 21 explains why investigators need to test for hidden blind spots and keep every file visible, accountable and available for review.
SPONSORED FEATURE: DigiCert wants to hand every agent a passport, complete with an expiry date and a named human owner
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]
Cédric Krier discovered that python-sql incorrectly escaped values passed
to unary operators. An attacker could possibly use this issue to perform
SQL injection attacks.
Attackers have opened a new front in their war on software developers: Vite servers, which they are probing for sensitive data including cloud credentials, infrastructure configuration and environment files.
Vite was created as a build tool for Vue, a JavaScript framework f...
It was discovered that polkit incorrectly handled cookie input.
A local
attacker could possibly use this issue to cause polkit
to crash, resulting
in a denial of service, or execute arbitrary code.