> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Fake apps led to account takeovers and spam campaigns
Cypro-thieves target popular cross-chain bridging service
Earlier this year, I successfully completed my internship at Trail of Bits and secured a full-time position as a Blockchain Security Analyst. This post is not intended to be a technical description of the work I did during my internship. Rather, it is intended to describe my general experience as a...
Threat actors trying to compromise elections are unlikely to result in large-scale disruptions
The original RatMilad spyware hid behind a VPN and phone number spoofing app called Text Me
tl;dr: Our publicly available Semgrep ruleset now has 11 rules dedicated to the misuse of machine learning libraries. Try it out now! Picture this: You’ve spent months curating images, trying out different architectures, downloading pretrained models, messing with Kubernetes, and you’re finally read...
Joe Sullivan was charged two years ago with obstruction of justice and misprision
Return to office and improved defenses are having an impact
La Commission des valeurs mobilières de Hong Kong (SFC) a blâmé et sanctionné Six Fook Securities (ou Luk Fook Securities) pour des lacunes importantes dans ses mesures de cybersécurité. L'incident, une attaque par ransomware survenue en septembre 2022, a causé des perturbations majeures aux infrast...
Provider runs 140 hospitals across the nation
UK regulator also slams company for predatory marketing calls
All about the new look for Hacking The Cloud v2.
Sebastien Vachon-Desjardins, 35, was also ordered to forfeit $21.5m
The document was jointly released by CISA with the FBI and NSA
On a network and need credentials? Try password spraying the domain controller directly.
A few years ago, I wrote this password spray tool called gospray that was used succesfully in a couple of engagements since. It does an LDAP bind directly against the domain controller to validate credentials. T...
The data posted on the internet by the hackers was from 2017 and reportedly "basic in nature"
BlackByte delivers new way to circumvent endpoint detection
UK law enforcers should be biggest beneficiaries
Sector-specific hub will look to professionalize the sector
It requires some federal agencies to perform automated asset discovery every seven days