[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 16:01

> FBI: Hackers Are Exploiting DeFi Bugs to Steal Funds
Users of decentralized finance platforms at risk
> UK Spies Fund New Course for Female Coders
GCHQ wants to improve diversity for better results
> Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
> Global Ransomware Damages to Exceed $30bn by 2023
Six hundred malicious email campaigns made their way across the internet in the first half of 2022
> US Cyber Command and NSA Partner On Defence Efforts For Midterms Elections
The group's main goal is to monitor foreign adversaries who may interfere with elections
> Machine Learning Attack Series: Backdooring Pickle Files
Recently I read this excellent post by Evan Sultanik about exploiting pickle files on Trail of Bits. There was also a DefCon30 talk about backdooring pickle files by ColdwaterQ. This got me curious to try out backdooring a pickle file myself. Pickle files - the surprises Surprisingly Python pickle f...
> GCP Goat
GCP Goat is the Vulnerable application for learning the GCP Security
> Thunder CTF
GCP themed CTF
> Ransomware Attacks are on the Rise
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
> Hunting GCP Buckets
How to find valid and invalid GCP Buckets using tools
> Iran-Based MuddyWater Targets Log4j 2 Vulnerabilities in SysAid Apps in Israel
It is the first campaign in which the hacker group exploits SysAid apps as a vector for initial access
> TeamTNT Targeted Cloud Instances and Containerized Environments For Two Years
The hacking group most likely originates from Germany
> Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
> 0ktapus Phishing Campaign Targets Okta Identity Credentials
Despite using low-skill methods, the campaign compromised a large number of well-known companies
> Cosmetics Giant Sephora to Pay $1m+ Privacy Settlement
California’s data protection law bares its teeth
> Magnifier: An Experiment with Interactive Decompilation
Today, we are releasing Magnifier, an experimental reverse engineering user interface I developed during my internship. Magnifier asks, “What if, as an alternative to taking handwritten notes, reverse engineering researchers could interactively reshape a decompiled program to reflect what they would...
> Block Faces Class Action Suit After 2021 Breach
Plaintiffs argue firm’s security posture was ineffective
> LastPass Hackers Stole Source Code
Password management firm reveals incident in early August
> Twitter Whistleblower Complaint: The TL;DR Version
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
> Microsoft Attributes New Post-Compromise Capability to Nobelium
MagicWeb improves on FoggyWeb by facilitating covert access directly via a malicious DLL