[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> Most Neurodiverse Women in Tech Feel Unsupported: Study
Report suggests high demand for talent from security sector employers
> LockBit Remains Most Prolific Ransomware in Q3
Phobos is a close second, according to Trellix
> ABI compatibility in Python: How hard could it be?
TL;DR: Trail of Bits has developed abi3audit, a new Python tool for checking Python packages for CPython application binary interface (ABI) violations. We’ve used it to discover hundreds of inconsistently and incorrectly tagged package distributions, each of which is a potential source of crashes an...
> Billbug Targets Government Agencies in Multiple Asian Countries
According to Symantec, the targeting of a certificate authority was notable
> Remote Code Execution Discovered in Spotify's Backstage
Spotify ranked the vulnerability as critical, with a CVSS score of 9.8
> We’re streamers now
Over the years, we’ve built many high-impact tools that we use for security reviews. You might know some of them, like Slither, Echidna, Amarna, Tealer, and test-fuzz. All of our tools are open source, and we love seeing the community benefit from them. But mastering our tools takes time and practic...
> Lazarus Backdoor DTrack Evolves to Target Europe and Latin America
DTrack has not changed substantially, but Lazarus made some “interesting” modifications
> China-Based Campaign Uses 42,000 Phishing Domains
Operation designed to spread malware and generate ad revenue
> Look out! Divergent representations are everywhere!
Trail of Bits recently published a blog post about a signed integer overflow in certain versions of SQLite that can enable arbitrary code execution and result in a denial of service. While working on proof-of-concept exploits for that vulnerability, we noticed that the compiler’s representation of a...
> Police Celebrate Arrest of 59 Suspected Scammers
Month-long European operation focused on online fraudsters
> Google to Pay $392m in Landmark Privacy Case
Multi-state settlement is largest in US history
> London & Zurich
La société de prélèvement direct London & Zurich a été victime d'une attaque par ransomware le 10 novembre, entraînant des interruptions de service et des retards de paiement significatifs pour ses clients, certains devant recourir à des prêts pour pallier les problèmes de trésorerie. La communicati...
> GitHub Now Supports Private Vulnerability Reporting For Public Repositories
The feature needs to be manually enabled by repository maintainers
> NSA Guide Helps Firms Protect Against Memory Safety Vulnerabilities
The document describes situations where cyber actors steal sensitive information and other negative impacts
> We sign code now
Sigstore announced the general availability of its free and ecosystem-agnostic software signing service two weeks ago, giving developers a way to sign, verify and protect their software projects and the dependencies they rely on. Trail of Bits is absolutely thrilled to be a part of the project, and...
> Australia Considers Ban on Ransomware Payments After Medibank Breach
Home affairs minister Clare O'Neil made the announcement on ABC television on Sunday
> Mass Email Extortion Campaign Claims Server Hack
Threat actors claim they’ll destroy victims' reputation if they don't pay
> AWS Organizations Defaults & Pivoting
How to abuse AWS Organizations' default behavior and lateral movement capabilities.
> UK Shoppers Lost ÂŁ15m+ to Scammers Last Winter
Cyber experts urge consumers to improve online safety
> Ukrainian CERT Discloses New Data-Wiping Campaign
Somnia malware hijacks Telegram and VPN accounts