[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 16:01

> Quantum Computing Already Putting Data at Risk, Cyber Pros Agree
In the Deloitte poll, 50.2% of respondents said their organization is at risk of ‘harvest now, decrypt later’ attacks
> American Airlines Breach Exposes Customer and Staff Information
An undisclosed number of people have been impacted
> Six Fook Securities (Hong Kong) Limited
La Commission des valeurs mobilières de Hong Kong (SFC) a blâmé et sanctionné Six Fook Securities (ou Luk Fook Securities) pour des lacunes importantes dans ses mesures de cybersécurité. L'incident, une attaque par ransomware survenue en septembre 2022, a causé des perturbations majeures aux infrast...
> Revolut Breach May Have Hit 50,000+ Customers
Major phishing risk as personal details are compromised
> Uber Blames Lapsus$ for Breach
Threat actor bombarded Uber contractor with 2FA requests
> Hacking The Cloud v2: New Look
All about the new look for Hacking The Cloud v2.
> gospray - Simple LDAP bind-based password spray tool
On a network and need credentials? Try password spraying the domain controller directly. A few years ago, I wrote this password spray tool called gospray that was used succesfully in a couple of engagements since. It does an LDAP bind directly against the domain controller to validate credentials. T...
> New Spear Phish Methodology Relies on PuTTY SSH Client to Infect Systems
It tried to trick victims into clicking on malicious files as part of a fake Amazon job assessment
> CISA Expands Vulnerabilities Catalog With Old, Exploited Flaws
Four of the CVEs posted are from 2013, and one is from 2010
> It pays to be Circomspect
In October 2019, a security researcher found a devastating vulnerability in Tornado.cash, a decentralized, non-custodial mixer on the Ethereum network. Tornado.cash uses zero-knowledge proofs (ZKPs) to allow its users to privately deposit and withdraw funds. The proofs are supposed to guarantee that...
> Allies Warn of Iranian Ransom Attacks Using Log4Shell
US authorities indict and sanction in fresh crackdown
> Uber Hacker May Have Compromised Secret Bug Reports
Attacker looks to have admin access to cloud accounts
> Toulouse INP
En septembre 2022, Toulouse INP a été victime d'une cyberattaque avec le ransomware AvosLocker. L'attaque a été déclenchée via un compte étudiant compromis et a bloqué l'annuaire, les mécanismes d'authentification et les capacités d'accès physique aux bâtiments. Des mesures ont été prises pour rétab...
> Crypto Scams Soar as Domains Surge 335%
Most fake domains are registered in Russia
> Webworm Attackers Deploy Modified RATs in Espionage Attacks
The group reportedly developed customized versions of Trochilus, Gh0st RAT and 9002 RAT
> Malicious Python Packages and Code Execution via pip download
This week I learned about a design flaw with pip download, which allows an adversary to run arbitrary code. I assumed that running pip install means anything could happen, but pip download seems a bit surprising. Both seem useful for red teaming though. Background This post from Yehuda Gelb named Au...
> Notepad++ Plugins Allow Attackers to Infiltrate Systems, Achieve Persistence
APT groups have leveraged Notepad++ plugins for nefarious purposes in the past
> YouTube Users Targeted By RedLine Self-Spreading Stealer
RedLine can steal usernames, passwords, cookies, bank card details and autofill data from browsers
> Stealing Data with Zix - Bypassing Data Loss Prevention Policies
Background If you haven’t done so yet, read my first Zix exploitation article: Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT, which established baselines to abuse the native organizational trust that Zix provides to perform spear phishing on the affected company. Shortly...
> User Alert as Phishing Campaigns Exploit Queen's Passing
Experts urge the public not to fall for classic scams