[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> CISA Says Midterm Voting Uncompromised By Cyber-attacks
Election workers will continue to work in the days ahead to certify the election results
> Ukrainian Cyber Cops Bust $200m Fraud Ring
Two-year pan-European operation ends in arrests
> Look out! Divergent representations are everywhere!
Trail of Bits recently published a blog post about a signed integer overflow in certain versions of SQLite that can enable arbitrary code execution and result in a denial of service. While working on proof-of-concept exploits for that vulnerability, we noticed that the compiler’s representation of a...
> Only 30% of Cyber-Insurance Holders Say Ransomware is Covered
Insurers are cutting back on coverage as claims surge
> Qatar World Cup Firms Urged to Upgrade Cyber-Threat Model
Digital Shadows warns of elevated risk from scammers and threat actors
> London & Zurich
La société de prélèvement direct London & Zurich a été victime d'une attaque par ransomware le 10 novembre, entraînant des interruptions de service et des retards de paiement significatifs pour ses clients, certains devant recourir à des prêts pour pallier les problèmes de trésorerie. La communicati...
> New Lenovo Notebook Models Affected By UEFI Firmware Vulnerabilities
The flaws affect various Lenovo Yoga, IdeaPad and ThinkBook devices
> #IRISSCON: Police Officer Urges More Reporting and Engagement to Tackle Cybercrime
Ireland's National Cyber Crime Bureau outlines cybercrime trends being observed in law enforcement
> We sign code now
Sigstore announced the general availability of its free and ecosystem-agnostic software signing service two weeks ago, giving developers a way to sign, verify and protect their software projects and the dependencies they rely on. Trail of Bits is absolutely thrilled to be a part of the project, and...
> Majority of Security Managers Lack Threat Intelligence Skills
The report suggests threat intelligence is a crucial source for vulnerability detection
> The 'Great Resignation' Caused Insider Threats to Peak in Q3 2022, Kroll Finds
Kroll’s Q3 2022 Threat Landscape report showed an unprecedented increase in insider threats
> AWS Organizations Defaults & Pivoting
How to abuse AWS Organizations' default behavior and lateral movement capabilities.
> #IRISSCON: Cyber Professionals Now Tasked with Securing Society, Says Mikko Hyppönen
Mikko Hyppönen discusses how cyber-threats will become even more dangerous as reliance on connectivity grows
> Some 98% of Global Firms Suffer Supply Chain Breach in 2021
Two-fifths still trust suppliers to handle their own security
> Everything you need to know about the OpenSSL 3.0.7 Patch (CVE-2022-3602 & CVE-2022-3786)
> Malware Redirects 15,000 Sites in Malicious SEO Campaign
Campaign designed to improve search engine rankings of spammy sites
> Couple Get 40 Years for Navy Espionage Plot
Duo tried to sell secrets of nuclear propulsion
> Satys
Le groupe aéronautique Satys, sous-traitant d'Airbus, a été victime d'une cyberattaque massive qui a nécessité la mise en place d'une cellule de crise et la restauration de ses systèmes informatiques. L'attaque a impliqué le ransomware Dagon, une évolution de MountLocker et de Quantum.
> High-Risk Vulnerability Found in ABB's Flow Computers
Attackers could exploit it by sending a specially crafted message to an affected system node
> Malicious Package on PyPI Hides Behind Image Files, Spreads Via GitHub
The findings indicate that PyPI malicious packages and their obfuscation techniques are evolving