[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> Brazilian Police Arrest Lapsus$ Suspect
Noose tightens around notorious cybercrime group
> NCSC Updates Early Warning Threat Intelligence
UK security agency makes it easier to assess credibility of alerts
> TTP Diaries: SSH Agent Hijacking
There are some neat TTPs that I don’t use frequently, and if the time arises, I need to dig up details again. So, I figured to write some of them down, starting with SSH Agent Hijacking. What is SSH Agent Hijacking? Short story, if you have keys added to an SSH Agent an adversary with root permissio...
> Microsoft Misconfiguration Exposes Customer Data
Researchers claim thousands of global customers were impacted
> NSA Cybersecurity Director's Six Takeaways From the War in Ukraine
Rob Joyce was invited to speak during the Mandiant Worldwide Information Security Exchange (mWISE) event on October 18, 2022
> Abusing Elastic Container Registry for Lateral Movement
With ECR permissions you can easily distribute a backdoor to production servers, developer's laptops, or CI/CD pipelines and own the environment by gaining privileged permissions.
> Moola Market Reveals $9m Crypto Exploit
Most of the funds were later returned following negotiations with the hacker
> Digital Natives Are Undermining Corporate Security - Report
EY finds younger workers are prone to engage in risky behavior
> Porting the Solana eBPF JIT compiler to ARM64
Andrew Haberlandt  During my summer internship at Trail of Bits, I worked on the fork of the RBPF JIT compiler that is used to execute Solana smart contracts. The RBPF JIT compiler plays a critical role on the Solana blockchain, as it facilitates the execution of contracts on validator nodes by defa...
> #CyberMonth: ENISA Celebrates 10 Years of European Cybersecurity Month with New, Proactive Slogan
For this year’s edition, ENISA introduced a new slogan for the event, #Choose2BeSafeOnline
> Deadbolt Ransomware Extorts Vendors and Customers
New report provides in-depth look at novel NAS-based threat
> Knowledge Base Digest - August & September 2022
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in August and September. Articles AuthPoint ADFS agent installation fails on secondary server AuthPoint Gateway status is Not Installed or Not Connected after upgrade to...
> Software Supply Chain Attacks Soar 742% in Three Years
Sonatype reveals scale of threats to open source ecosystem
> Zoom Patches High-Severity Flaw in macOS Client
The flaw could allow an attacker to connect to clients and control the Zoom Apps running in it
> Working on blockchains as a Trail of Bits intern
Earlier this year, I successfully completed my internship at Trail of Bits and secured a full-time position as a Blockchain Security Analyst. This post is not intended to be a technical description of the work I did during my internship. Rather, it is intended to describe my general experience as a...
> HelpSystems Patch Falls Short, RCE Vulnerability in Cobalt Strike Remains
Certain components in Java Swing will interpret text as HTML content if it starts with
> Spyder Loader Malware Deployed Against Hong Kong Organizations
The attackers reportedly remained active on some networks for more than a year
> Secure your machine learning with Semgrep
tl;dr: Our publicly available Semgrep ruleset now has 11 rules dedicated to the misuse of machine learning libraries. Try it out now! Picture this: You’ve spent months curating images, trying out different architectures, downloading pretrained models, messing with Kubernetes, and you’re finally read...
> European Police Catch Suspected Car Hackers
Gang exploited keyless entry systems to steal vehicles
> Wine Merchant Among Aussie Firms Breached, Exposing Millions
Vinomofo the latest to suffer a serious security incident