[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> API Vulnerabilities Discovered in LEGO Marketplace
The vulnerabilities, which are now fixed, could have put sensitive customer data at risk
> Connexus
L'association de logement Connexus a confirmé une cyberattaque impliquant un accès non autorisé à ses systèmes, selon un message publié sur leur page Facebook le 18 décembre. En réaction, Connexus a déconnecté ses systèmes pour protéger les données personnelles des utilisateurs et travaille avec des...
> Agenda Ransomware Switches to Rust to Attack Critical Infrastructure
Victim companies have a combined revenue of around $550m
> Meta's Bug Bounty Program Shows $2m Awarded in 2022
The total amount since the program's establishment in 2011 is reportedly $16m
> Multiples vulnérabilités dans AMI MegaRAC (16 décembre 2022)
Le 05 décembre 2022, trois vulnérabilités respectivement identifiées par les numéros CVE-2022-40259, CVE-2022-40242 et CVE-2022-2827 ont été signalées dans la solution d’administration à distance MegaRAC de l’éditeur AMI. La solution MegaRAC s’appuie sur un BMC (Baseboard Management Controller) :...
> Social Blade Confirms Data Breach Exposing PII on the Dark Web
The company confirmed the data does not include any credit card information
> Two-Thirds of Security Pros Have Burnt Out in Past Year
Excessive workload is the most common contributing factor
> TikTok is a National Security Risk, Not A Privacy One
An analysis of the threat posed by TikTok and why we need to weigh our options carefully.
> Former Twitter Employee Gets 42 Months for Saudi Scheme
Insider was bribed by the Middle East kingdom
> OECD Signs "Landmark" Privacy Agreement
Club of rich countries wants to improve cross-border data flows
> How I gave ManticoreUI a makeover
During my internship at Trail of Bits, I explored the effectiveness of symbolic execution for finding vulnerabilities in native applications ranging from CTF challenges to popular open source libraries like image parsers, focusing on finding ways to enhance ManticoreUI. It is a powerful tool that im...
> Senate Approves Bill Banning TikTok From US Government Devices
The bill still needs to receive approval from the US House of Representatives
> NSA, CISA Warn Against Threats to 5G Network Slicing
Improper network slice management may enable attackers to access data from different network slices
> 2022 Wrap-up
An end of year summary for Hacking the Cloud in 2022.
> Loan Scam Campaign 'MoneyMonger' Exploits Flutter to Hide Malware
Zimperium said the code was part of an existing campaign previously discovered by K7 Security Labs
> Feds Hit DDoS-for-Hire Services with 48 Domain Seizures
Six also charged in connection with booter services
> Manticore GUIs made easy
Trail of Bits maintains Manticore, a symbolic execution engine that can analyze smart contracts and native binaries. While symbolic execution is a powerful technique that can augment the vulnerability discovery process, it requires some base domain knowledge and thus has its own learning curve. Give...
> Over 85% of Attacks Hide in Encrypted Channels
Zscaler reveals 20% increase in malicious use of encryption
> Platforms Flooded with 144,000 Phishing Packages
NuGet, PyPi and npm inundated with malicious packages
> Cheyenne Radiology Group & MRI
Le groupe de radiologie Cheyenne Radiology Group & MRI, âgé de 70 ans, a récemment subi une cyberattaque qui pourrait avoir entraîné l'exposition involontaire des informations personnelles des patients. Bien qu'il n'y ait aucune preuve d'une utilisation abusive des informations sensibles, le groupe...