[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> Global Cops Arrest Dozens Linked to Financial Crime Gang
Black Axe syndicate responsible for multimillion-dollar losses
> TTP Diaries: SSH Agent Hijacking
There are some neat TTPs that I don’t use frequently, and if the time arises, I need to dig up details again. So, I figured to write some of them down, starting with SSH Agent Hijacking. What is SSH Agent Hijacking? Short story, if you have keys added to an SSH Agent an adversary with root permissio...
> Mirai Botnet Targeted Wynncraft Minecraft Server, Cloudflare Reports
The multi-vector, 2.5Tbps attack consisted of UDP and TCP floods
> Shein Holding Company Fined $1.9m For Not Disclosing Data Breach
The data breach saw Zoetop allegedly trying to keep the real impact of the leak quiet
> Abusing Elastic Container Registry for Lateral Movement
With ECR permissions you can easily distribute a backdoor to production servers, developer's laptops, or CI/CD pipelines and own the environment by gaining privileged permissions.
> Education Sector Experienced 44% Increase in Cyber-Attacks Over Last Year
An average of 2297 attacks against organizations were recorded every week
> #DTX2022: How to Scam Someone Using Social Media Phishing
Jake Moore, global cybersecurity advisor at ESET, shared at DTX Europe 2022 how he used a fake social media profile to hack employees of a company
> Porting the Solana eBPF JIT compiler to ARM64
Andrew Haberlandt  During my summer internship at Trail of Bits, I worked on the fork of the RBPF JIT compiler that is used to execute Solana smart contracts. The RBPF JIT compiler plays a critical role on the Solana blockchain, as it facilitates the execution of contracts on validator nodes by defa...
> Magniber Ransomware Adopts JavaScript to Attack Individual Users
Consumers should protect themselves by using least-privilege principles
> Report Shows How China Has Been Using Cyber-Attacks Over the Past Decade
Consultancy firm Booz Allen has published a comprehensive report on Chinese-sponsored threat
> Knowledge Base Digest - August & September 2022
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in August and September. Articles AuthPoint ADFS agent installation fails on secondary server AuthPoint Gateway status is Not Installed or Not Connected after upgrade to...
> Chinese APT WIP19 Targets IT Service Providers and Telcos
The group is characterized by the use of a stolen digital certificate issued by DEEPSoft
> Malicious WhatsApp Mod Spotted Infecting Android Devices
YoWhatsApp v2.22.11.75 was distributed via ads on Android apps like Snaptube and VidMate
> Working on blockchains as a Trail of Bits intern
Earlier this year, I successfully completed my internship at Trail of Bits and secured a full-time position as a Blockchain Security Analyst. This post is not intended to be a technical description of the work I did during my internship. Rather, it is intended to describe my general experience as a...
> Budworm Espionage Group Returns, Targets US State Legislature
Budworm leveraged the Log4j vulnerabilities to compromise the Apache Tomcat service on servers
> IP Cameras, VoIP and Video Conferencing Revealed as Riskiest IoT Devices
Warning to orgnaizations to be aware of risky devices across IT, IoT, OT and IoMT
> Secure your machine learning with Semgrep
tl;dr: Our publicly available Semgrep ruleset now has 11 rules dedicated to the misuse of machine learning libraries. Try it out now! Picture this: You’ve spent months curating images, trying out different architectures, downloading pretrained models, messing with Kubernetes, and you’re finally read...
> UK Government Urges Action to Enhance Supply Chain Security
The NCSC guidance has been issued amid a significant increase in supply chain attacks in recent years
> #DTX2022: Cyber Needs to Redress the Defensive-Offensive Balance Following Russia-Ukraine
The Russia-Ukraine conflict highlights the value of defensive cybersecurity, says Dr Alexi Drew
> FormBook Tops Check Point's Most Wanted Malware List For September
Vidar, an infostealer, has entered the top 10 list in eighth place for the first time