> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Election workers will continue to work in the days ahead to certify the election results
Two-year pan-European operation ends in arrests
Trail of Bits recently published a blog post about a signed integer overflow in certain versions of SQLite that can enable arbitrary code execution and result in a denial of service. While working on proof-of-concept exploits for that vulnerability, we noticed that the compiler’s representation of a...
Insurers are cutting back on coverage as claims surge
Digital Shadows warns of elevated risk from scammers and threat actors
La société de prélèvement direct London & Zurich a été victime d'une attaque par ransomware le 10 novembre, entraînant des interruptions de service et des retards de paiement significatifs pour ses clients, certains devant recourir à des prêts pour pallier les problèmes de trésorerie. La communicati...
The flaws affect various Lenovo Yoga, IdeaPad and ThinkBook devices
Ireland's National Cyber Crime Bureau outlines cybercrime trends being observed in law enforcement
Sigstore announced the general availability of its free and ecosystem-agnostic software signing service two weeks ago, giving developers a way to sign, verify and protect their software projects and the dependencies they rely on. Trail of Bits is absolutely thrilled to be a part of the project, and...
The report suggests threat intelligence is a crucial source for vulnerability detection
Kroll’s Q3 2022 Threat Landscape report showed an unprecedented increase in insider threats
How to abuse AWS Organizations' default behavior and lateral movement capabilities.
Mikko Hyppönen discusses how cyber-threats will become even more dangerous as reliance on connectivity grows
Two-fifths still trust suppliers to handle their own security
Campaign designed to improve search engine rankings of spammy sites
Duo tried to sell secrets of nuclear propulsion
Le groupe aéronautique Satys, sous-traitant d'Airbus, a été victime d'une cyberattaque massive qui a nécessité la mise en place d'une cellule de crise et la restauration de ses systèmes informatiques. L'attaque a impliqué le ransomware Dagon, une évolution de MountLocker et de Quantum.
Attackers could exploit it by sending a specially crafted message to an affected system node
The findings indicate that PyPI malicious packages and their obfuscation techniques are evolving