[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (17 articles)

|

// AI-powered summary generated at 20:00

> Kardashian Charged by SEC After Crypto Post
Star failed to disclose payment for promotional content
> Ex-NSA Employee Charged For Trying to Sell US Secrets
Dalke reportedly requested $85,000 in return for additional information in his possession
> Secure your machine learning with Semgrep
tl;dr: Our publicly available Semgrep ruleset now has 11 rules dedicated to the misuse of machine learning libraries. Try it out now! Picture this: You’ve spent months curating images, trying out different architectures, downloading pretrained models, messing with Kubernetes, and you’re finally read...
> Phishing Campaigns Target KFC, McDonald's in Saudi Arabia, UAE, Singapore
Payment details of some of the victims were successfully stolen by the attackers
> Lazarus Group Exploits Dell Driver Vulnerability to Bypass Windows Security
ESET said the vulnerability was exploited at least twice via a specific user-mode module
> Six Fook Securities (Hong Kong) Limited
La Commission des valeurs mobilières de Hong Kong (SFC) a blâmé et sanctionné Six Fook Securities (ou Luk Fook Securities) pour des lacunes importantes dans ses mesures de cybersécurité. L'incident, une attaque par ransomware survenue en septembre 2022, a causé des perturbations majeures aux infrast...
> ICO Fines Four "Predatory" Privacy-Invading Firms
Marketers made over 820,000 illegal calls
> LA Unified School District: Hackers Have Posted Stolen Data Online
School district is investigating authenticity of the trove
> Hacking The Cloud v2: New Look
All about the new look for Hacking The Cloud v2.
> Healthcare Company Owners Get Jail Time for $7m Fraud Scheme
Duo paid bribes and kickbacks to patient marketers
> Hackers Hide Malware in Windows Logo, Target Middle East Governments
The group continued to use the LookBack backdoor, but also several new types of malware
> gospray - Simple LDAP bind-based password spray tool
On a network and need credentials? Try password spraying the domain controller directly. A few years ago, I wrote this password spray tool called gospray that was used succesfully in a couple of engagements since. It does an LDAP bind directly against the domain controller to validate credentials. T...
> Hackers Backdoor Pirated Windows OS With Cryptominer and Xtreme RAT
The behavior of the actors was reportedly identical to what was described by Minerva Labs in 2021
> Lazarus-Associated Hackers Weaponize Open-Source Tools Against Several Countries
The advisory suggests Zinc has targeted media, defense and aerospace, and IT services
> It pays to be Circomspect
In October 2019, a security researcher found a devastating vulnerability in Tornado.cash, a decentralized, non-custodial mixer on the Ethereum network. Tornado.cash uses zero-knowledge proofs (ZKPs) to allow its users to privately deposit and withdraw funds. The proofs are supposed to guarantee that...
> Microsoft Confirms Two Exchange Zero-Day Vulnerabilities
The vulnerabilities were first discovered by Vietnamese cybersecurity firm GTSC
> NCSC: UK Organizations Can Learn from Ukraine's Impressive Cyber Defenses
NCSC CEO, Lindy Cameron, outlines the UK's observations of the cyber dimension of the Russia-Ukraine conflict
> Manufacturers Failing to Address Cybersecurity Vulnerabilities Liable Under New European Rules
The liability rules allow for compensation for damage when manufacturers fail to address cybersecurity vulnerabilities
> Researchers Discover Chaos, a Golang Multipurpose Botnet
The tool was written in Chinese and seemed China-based due to its C2 infrastructure
> Government, Union-Themed Lures Used to Deliver Cobalt Strike Payloads
Cisco Talos discovered the malicious campaign in August 2022