> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Report suggests high demand for talent from security sector employers
Phobos is a close second, according to Trellix
TL;DR: Trail of Bits has developed abi3audit, a new Python tool for checking Python packages for CPython application binary interface (ABI) violations. We’ve used it to discover hundreds of inconsistently and incorrectly tagged package distributions, each of which is a potential source of crashes an...
According to Symantec, the targeting of a certificate authority was notable
Spotify ranked the vulnerability as critical, with a CVSS score of 9.8
Over the years, we’ve built many high-impact tools that we use for security reviews. You might know some of them, like Slither, Echidna, Amarna, Tealer, and test-fuzz. All of our tools are open source, and we love seeing the community benefit from them. But mastering our tools takes time and practic...
DTrack has not changed substantially, but Lazarus made some “interesting” modifications
Operation designed to spread malware and generate ad revenue
Trail of Bits recently published a blog post about a signed integer overflow in certain versions of SQLite that can enable arbitrary code execution and result in a denial of service. While working on proof-of-concept exploits for that vulnerability, we noticed that the compiler’s representation of a...
Month-long European operation focused on online fraudsters
Multi-state settlement is largest in US history
La société de prélèvement direct London & Zurich a été victime d'une attaque par ransomware le 10 novembre, entraînant des interruptions de service et des retards de paiement significatifs pour ses clients, certains devant recourir à des prêts pour pallier les problèmes de trésorerie. La communicati...
The feature needs to be manually enabled by repository maintainers
The document describes situations where cyber actors steal sensitive information and other negative impacts
Sigstore announced the general availability of its free and ecosystem-agnostic software signing service two weeks ago, giving developers a way to sign, verify and protect their software projects and the dependencies they rely on. Trail of Bits is absolutely thrilled to be a part of the project, and...
Home affairs minister Clare O'Neil made the announcement on ABC television on Sunday
Threat actors claim they’ll destroy victims' reputation if they don't pay
How to abuse AWS Organizations' default behavior and lateral movement capabilities.
Cyber experts urge consumers to improve online safety
Somnia malware hijacks Telegram and VPN accounts