[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 16:01

> NSA Reveals "Hackers' Playbook" for OT Attacks
New report outlines key mitigations for OT owners
> Europol "Hackathon" Identifies Scores of Human Trafficking Victims
Over 100 online platforms checked for illegal activity
> Six Fook Securities (Hong Kong) Limited
La Commission des valeurs mobilières de Hong Kong (SFC) a blâmé et sanctionné Six Fook Securities (ou Luk Fook Securities) pour des lacunes importantes dans ses mesures de cybersécurité. L'incident, une attaque par ransomware survenue en septembre 2022, a causé des perturbations majeures aux infrast...
> Optus Hit By Cyber-Attack, Breach Affects Nearly 10 Million Customers
Home addresses, driver's licenses and passport numbers were potentially accessed by the attacker
> Morgan Stanley Fined $35m By SEC For Data Security Lapse
The improper data disposal reportedly started in 2016 and exposed 15 million customers' data
> Hacking The Cloud v2: New Look
All about the new look for Hacking The Cloud v2.
> Russia-Based Hackers FIN11 Impersonate Zoom to Conduct Phishing Campaigns
Cyfirma said the motive behind the attacks may be financial in nature
> Twitter Password Reset Bug Exposed User Accounts
Social media firm fixes issue that left sessions open
> gospray - Simple LDAP bind-based password spray tool
On a network and need credentials? Try password spraying the domain controller directly. A few years ago, I wrote this password spray tool called gospray that was used succesfully in a couple of engagements since. It does an LDAP bind directly against the domain controller to validate credentials. T...
> Authorized Push Payments Surge to 75% of Banking Fraud
Social engineering tactics bear fruit for digital scammers
> Iranian Hackers Hid in Albanian Networks for Over a Year
CISA report reveals extent of state-backed campaign
> It pays to be Circomspect
In October 2019, a security researcher found a devastating vulnerability in Tornado.cash, a decentralized, non-custodial mixer on the Ethereum network. Tornado.cash uses zero-knowledge proofs (ZKPs) to allow its users to privately deposit and withdraw funds. The proofs are supposed to guarantee that...
> Microsoft Upgrades Windows 11 With New Security Features
The list includes application control enhancements and vulnerable drivers protection, among others
> 350K Open-Source Projects At Risk of Supply Chain Vulnerability
The flaw resides in the tarfile module, automatically installed in any Python project
> Toulouse INP
En septembre 2022, Toulouse INP a été victime d'une cyberattaque avec le ransomware AvosLocker. L'attaque a été déclenchée via un compte étudiant compromis et a bloqué l'annuaire, les mécanismes d'authentification et les capacités d'accès physique aux bâtiments. Des mesures ont été prises pour rétab...
> NCSC: British Retailers Need to Move Beyond Passwords
The UK’s national cybersecurity agency also advised organizations on what steps they should take if their brand has been spoofed online
> Multiple Vulnerabilities Discovered in Dataprobe's iBoot-PDUs
They pose a number of risks to Dataprobe, including giving control of the iBoot-PDU to attackers
> Malicious Python Packages and Code Execution via pip download
This week I learned about a design flaw with pip download, which allows an adversary to run arbitrary code. I assumed that running pip install means anything could happen, but pip download seems a bit surprising. Both seem useful for red teaming though. Background This post from Yehuda Gelb named Au...
> Two-Fifths of US Consumers Suffer Personal Data Theft
Those suffering emotional and physical impact surges
> Video Game Publisher Admits Helpdesk Was Hijacked
Players were sent malicious links disguised as support tickets