[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Cobalt Mirage Affiliate Uses GitHub to Relay Drokbk Malware Instructions
Secureworks said the malicious code is written in .NET and comprises a dropper and a payload
> Software Supply Chain Attacks Leveraging Open-Sources Repos Growing
ReversingLabs found an increasing number of malicious packages in three popular repositories
> Hybrid fuzzing: Sharpening the spikes of Echidna
Smart contract fuzzing is an effective bug-finding technique that is largely used at Trail Of Bits during audits. During my internship at Trail of Bits, I contributed to expand our fuzzing capabilities by working on Hybrid Echidna, a “hybrid fuzzer” that couples our smart contract fuzzer, Echidna, w...
> #BHEU: UK Government Calls for Industry Input on its Cybersecurity Strategy
A DCMS official sets out the UK government's cybersecurity strategy during Black Hat Europe 2022
> Government to Fund Security Studies for Hundreds of Students
Latest move shows urgent need to nurture skills pipeline
> 🇬🇧 Integration of Untrusted Software (07 décembre 2022)
Version française: 🇫🇷 Regulatory frameworks of some countries may require companies operating in their territory to use specific software. While their integration does not usually present any technical concern, such software can be used by adversaries as an entry point to a computer network. The...
> Security Concerns Scupper Deals for Two-Thirds of Firms
Global report ties poor security to bottom-line impact
> Government Sets Out New Rules to Enhance App Security
Voluntary code of conduct is designed for developers and app store operators
> Knowledge Base Digest - November 2022
Articles AuthPoint users cannot log in to Windows server after they change a password over RDP DNSWatchGO data storage information and server locations M-series Firebox powered state behavior after a power failure PMKID does not match between AP and client Why does the Firebox generate "Archived lo...
> US Sues TikTok Over Child Safety and Data Security Claims
The Indiana court said TikTok promoted age-restricted content regardless of a user's age
> Iranian APT Agrius Targets Diamond Industry Worldwide With Fantasy Wiper
The group conducted supply chain attacks against the diamond industry across three continents
> Loot Public EBS Snapshots
How to find and take advantage of exposed EBS snapshots.
> Apple Introduces New Data Protections to Increase Cloud Security
The new features will be globally available in 2023, but one of them already is for some US users
> #BHEU: Time for Cyber Pros to Shape the Industry’s Future
Jen Ellis urges the cyber industry to take a leading role in shaping its future, during Black Hat Europe 2022
> ChatGPT: Imagine you are a database server
After reading this post about ChatGPT imitating Linux, I wanted it to be a database server. Let’s try it out! Imagine you are a Microsoft SQL Server. I type commands, and you reply with the result, and no other information or descriptions. Just the result. Start with exec xp_cmdshell ‘whoami’; Wow,...
> Pet Dog Unmasks Drug Trafficker on Encrypted Chat
Police studied photos sent via EncroChat to reveal users
> Investment Fraud Gang May Have Made $500m
CryptosLabs has been operating since 2018, says Group-IB
> From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225)
Introduction You’ve probably enjoyed my previous post about bypassing Intel DCM’s authentication mechanism to gain unauthorized access. This gave us the lowest possible “Guest” privileges in the DCM console. The second part will now show you a possible way to get Remote Code Execution on the underly...
> Cyber-criminals Scammed Each Other Out of Millions in 2022
Sophos report reveals thriving "sub-economy" on underground sites
> Microsoft Warns Cryptocurrency Firms Against Complex Cyber-Attacks
Attacks included fraud, vulnerability exploitation, fake applications and info stealer deployments