[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 16:01

> Source Code of Over 1800 Android and iOS Apps Gives Access to AWS Credentials
Roughly 50% of all the apps analyzed were seen using the same AWS tokens found in other apps
> Ragnar Locker Ransomware Targets Energy Sector, Cybereason Suggests
The malware can also check if specific products are installed, particularly security software
> Student Loan Breach Exposes 2.5M Records
2.5 million people were affected, in a breach that could spell more trouble down the line.
> Apple Releases Update for iOS 12 to Patch Exploited Vulnerability
The flaw would allow the processing of maliciously crafted web content and arbitrary code execution
> Standards Body Publishes Guidelines for IoT Security Testing
Document will help testers create benchmarks for security products
> Watering Hole Attacks Push ScanBox Keylogger
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
> Detected Cyber-Threats Surge 52% in 1H 2022
Trend Micro warns of Linux-based ransomware
> Microsoft Finds Account Takeover Bug in TikTok
Vulnerability impacted social media firm’s Android app
> Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
> Golang-based Malware Campaign Relies on James Webb Telescope's Image
Initial infection begins with a phishing email containing a Microsoft Office attachment
> Evil Corp and Conti Linked to Cisco Data Breach, eSentire Suggests
The firm said the tools used to attack Cisco were also deployed to compromise one of its clients
> Machine Learning Attack Series: Backdooring Pickle Files
Recently I read this excellent post by Evan Sultanik about exploiting pickle files on Trail of Bits. There was also a DefCon30 talk about backdooring pickle files by ColdwaterQ. This got me curious to try out backdooring a pickle file myself. Pickle files - the surprises Surprisingly Python pickle f...
> UK Imposes Tough New Cybersecurity Rules for Telecom Providers
Ofcom will be able to issue fines for non-compliance of up to 10% of turnover
> Intel Selects Check Point Quantum IoT Protect for RISC-V Platform
IoT device manufacturers can now incorporate security at the start of the product life-cycle
> GCP Goat
GCP Goat is the Vulnerable application for learning the GCP Security
> Initiative Aims to Encourage Diverse Talent into Cyber
National Cybersecurity Alliance launches HBCU career program
> Ukrainian Police Bust Crypto Fraud Call Centers
Scammers spoofed legitimate banks’ phone numbers
> Thunder CTF
GCP themed CTF
> ICO Pursues Traffic Accident Data Thieves
Data protection regulator begins criminal proceedings
> ModernLoader Delivers Stealers, Cryptominers and RATs Via Fake Amazon Gift Cards
The association between the three apparently unrelated campaigns was made by Cisco Talos