[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 16:01

> ICO Reprimands UK Organizations for GDPR Failings
Subject Access Requests experiencing significant delays
> Cyber-Threats Top Business Leaders' Biggest Concerns
Many are operating under a false sense of security
> Six Fook Securities (Hong Kong) Limited
La Commission des valeurs mobilières de Hong Kong (SFC) a blâmé et sanctionné Six Fook Securities (ou Luk Fook Securities) pour des lacunes importantes dans ses mesures de cybersécurité. L'incident, une attaque par ransomware survenue en septembre 2022, a causé des perturbations majeures aux infrast...
> Meta Takes Down Russian "Smash-and-Grab" Disinformation Campaign
Chinese network targeting US mid-terms also closed down
> Alleged Optus Hacker Apologizes, Deletes Customers' Exposed Data
They claimed responsibility for the attack and said they had deleted the stolen data
> Hacking The Cloud v2: New Look
All about the new look for Hacking The Cloud v2.
> Lazarus Group Targets MacOS Users Seeking Crypto Jobs
The new attacks would be a new instance of a campaign spotted by ESET and Malwarebytes in August
> Microsoft Sway Pages Weaponized to Perform Phishing and Malware Delivery
Most phishing attack vectors observed involved clicking a direct link to a phishing page
> gospray - Simple LDAP bind-based password spray tool
On a network and need credentials? Try password spraying the domain controller directly. A few years ago, I wrote this password spray tool called gospray that was used succesfully in a couple of engagements since. It does an LDAP bind directly against the domain controller to validate credentials. T...
> Global Firms Deal with 51 Security Incidents Each Day
Siloed systems appear to be holding back teams
> TikTok Facing ÂŁ27m UK Regulatory Fine
Social network failed to protect kids, says ICO
> It pays to be Circomspect
In October 2019, a security researcher found a devastating vulnerability in Tornado.cash, a decentralized, non-custodial mixer on the Ethereum network. Tornado.cash uses zero-knowledge proofs (ZKPs) to allow its users to privately deposit and withdraw funds. The proofs are supposed to guarantee that...
> Ukraine Predicts "Massive" Russian Cyber Assault
Kremlin set to intensify attacks on critical infrastructure
> Fitbit Increases Security Requirements, Mandates Google Login From 2023
Users will have the option to log in using their Fitbit account for as long as it is supported
> Toulouse INP
En septembre 2022, Toulouse INP a été victime d'une cyberattaque avec le ransomware AvosLocker. L'attaque a été déclenchée via un compte étudiant compromis et a bloqué l'annuaire, les mécanismes d'authentification et les capacités d'accès physique aux bâtiments. Des mesures ont été prises pour rétab...
> ReasonLabs Unveils Multimillion Dollar Global Credit Card Scam
The victims of the plot were users of Mastercard, Visa, and American Express, among others
> Hackers Use NullMixer and SEO to Spread Malware More Efficiently
The websites are often related to crack, keygen and activators for illegal software
> Malicious Python Packages and Code Execution via pip download
This week I learned about a design flaw with pip download, which allows an adversary to run arbitrary code. I assumed that running pip install means anything could happen, but pip download seems a bit surprising. Both seem useful for red teaming though. Background This post from Yehuda Gelb named Au...
> Ransomware Affiliates Adopt Data Destruction
Concerning signs of escalation in tactics
> US Duo Plead Guilty to $30m Forex Fraud Scheme
Each face a maximum term of five years behind bars