> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights several significant threats. A security researcher has identified a KVM guest-host escape flaw in Firecracker MicroVMs, potentially impacting AWS environments. Dell has released patches for 18 critical vulnerabilities in its Container Storage Modules (CSM), which could allow attackers to gain unauthorized access to storage and Kubernetes systems. Additionally, the hacking group ShinyHunters has exploited a zero-day vulnerability in PeopleSoft, raising alarms about increased risks for enterprises using the Oracle software. Organizations are advised to implement stringent security measures in response to these emerging threats.
|
// AI-powered summary generated at 04:00
Les systèmes informatiques des cliniques de district de Moyenne-Franconie ont été ciblés par une cyberattaque, entraînant le chiffrement de données, y compris des documents personnels et internes à l'entreprise. En réponse, tous les systèmes ont été déconnectés pour des raisons de sécurité et les au...
Les services de transfert d'argent de Western Union vers Cuba sont suspendus depuis le 28 janvier, suite à une "incident de cybersécurité" annoncé par le gouvernement cubain. Cela affecte les familles à Miami qui ne peuvent plus envoyer d'argent à leurs proches sur l'île. Bien que le gouvernement cu...
Ukraine’s security services said that the IT specialist from Kharkiv targeted government websites and provided intelligence to Russia to carry out missile strikes
Une cyberattaque a perturbé les systèmes judiciaires du comté de Fulton en Géorgie, où l'ancien président Donald Trump est impliqué dans une affaire pénale liée à des allégations d'ingérence dans les résultats des élections de 2020. Les systèmes affectés par l'attaque incluent les tribunaux, les imp...
L'Institut National du Cancer (INCA) au Brésil a subi une cyberattaque qui a perturbé le service de radiologie et la prise de rendez-vous depuis le samedi 27. L'institut a activé son programme de sécurité interne et interrompu ses services technologiques pour protéger les données et éviter des domma...
Creating reproducible builds for SGX enclaves used in privacy-oriented deployments is a difficult task that lacks a convenient and robust solution. We describe using Nix to achieve reproducible and transparent enclave builds so that anyone can audit whether the enclave is running the source code it...
Recorded Future analyzed leaks describing the close relationship between the Iranian government and Iran-aligned APT groups
Cisco found that privacy and data security risks have led to over a quarter of organizations banning generative AI, at least temporarily, while a majority have instituted controls
Le matin du 26 janvier 2024, les systèmes informatiques de Kunath, une entreprise de taille moyenne spécialisée dans la fabrication de vêtements professionnels et basée à Bretnig-Hauswalde, ont été paralysés par une cyberattaque. L'entreprise, qui emploie 57 personnes et produit principalement des v...
ESET said Blackwood has been actively engaged in cyber-espionage since at least 2018
Bugcrowd’s latest report also recorded a 30% surge in web submissions in 2023
For the past eight months, Trail of Bits has worked with the Python Cryptographic Authority to build cryptography-x509-verification, a brand-new, pure-Rust implementation of the X.509 path validation algorithm that TLS and other encryption and authentication protocols are built on. Our implementatio...
A global drop in DeFi hacking gains prompted North Korean threat actors to diversify and extend their victim portfolio, Chainalysis found
Over 350 million individuals were impacted by data breaches in the US in 2023 and 11% of all publicly traded companies have been compromised
Authors: Axel Boesenach and Erik Schamper In this blog post we will go into a user-friendly memory scanning Python library that was created out of the necessity of having more control during memory scanning. We will give an overview of how this library works, share the thought process and the why’s....
Southern Water confirmed a data breach had occurred after the Black Basta ransomware group purportedly published personal information held by the firm
Authors: Axel Boesenach and Erik Schamper In this blog post we will go into a user-friendly memory scanning Python library that was created out of the necessity of having more control during memory scanning. We will give an overview of how this library works, share the thought process and the why’s....
Authors: Axel Boesenach and Erik Schamper In this blog post we will go into a user-friendly memory scanning Python library that was created out of the necessity of having more control during memory scanning. We will give an overview of how this library works, share the thought process and the why’s....
The Zero Day Initiative’s first Pwn2Own Automotive competition has handed out over $1m for 24 zero-days
Hewlett Packard Enterprise reveals that Russian state APT29 hackers stole data from corporate mailboxes