[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 12:00

> Ransomware Group Demands ÂŁ500,000 From School
The Hive ransomware group claims it has home addresses, bank details, medical records and even students’ psychological reviews
> US Expands Cybersecurity Partnership With Ukraine
Under the agreement, the two organizations will exchange information and best practices relating to cyber incidents
> Shedding smart contract storage with Slither
You think you’ve found a critical bug in a Solidity smart contract that, if exploited, could drain a widely used cryptocurrency exchange’s funds. To confirm that it’s really a bug, you need to figure out the value at an obscure storage slot that has no getter method. Adrenaline courses […]
> NCSC Startup Program Seeking Candidates to Help Protect Critical Infrastructure
Successful applicants will work with experts from within the NCSC to develop, adapt or pilot technology
> Hackers Change Tactics for New Post-Macro Era
Microsoft announcement forced threat actors to adapt once again
> 'WannaCry' ransomware: guidance updates
Jon L provides an update on the NCSC's guidance on the 'WannaCry' ransomware.
> Social Media Accounts Hijacked to Post Indecent Images
UK police urge users to switch on two-factor authentication
> European Police Arrest 100 Suspects in BEC Crackdown
Invoice fraud ring targeted state-owned organizations
> CVE-2022-22256: Huawei HWLog KASLR Leak
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to learn the value of randomized kernel pointers. The vulnerability can be used to defeat KASLR mitigation. Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlo...
> Cyber-Criminal Offers 5.4m Twitter Users’ Data
The seller advertised the data on the Breached Forums site and demanded at least $30,000 for it
> Senators Introduce Quantum Encryption Preparedness Law
Lawmakers introduced the bill because they’re worried about the potential for quantum computers to easily crack current cryptographic algorithms
> CVE-2022-22252: Huawei HWLog Vmalloc Use-After-Free
In this advisory we are disclosing a vulnerability in the Huawei log device that allows any unprivileged process to disclose sensitive information from the kernel. Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that facilitate better s...
> Criminals Use Malware as Messaging Bots to Steal Data
Cyber-criminals are using the Telegram and Discord messaging apps as command and control mechanisms
> US Doubles Reward for Info on North Korean Hackers
State Department hopes financial inducement will unmask threat actors
> CVE-2022-22253: Huawei HWLog Memory Corruption Via Race Condition
In this advisory we are disclosing a memory corruption vulnerability in the Huawei log device that allows any unprivileged process to trigger a kernel crash and reboot the device. Huawei kernels are shipped with custom log devices (/dev/hwlog_dubai, /dev/hwlog_exception and /dev/hwlog_jank) that fac...
> No More Ransom Has Helped Over 1.5m Victims
European initiative celebrates sixth birthday
> Data Breach Costs Reach New Record High
Most impacted companies raise product prices following incident
> WordPress Transposh: Exploiting a Blind SQL Injection via XSS
Introduction You probably have read about my recent swamp of CVEs affecting a WordPress plugin called Transposh Translation Filter, which resulted in more than $30,000 in bounties: [CVE-2021-24910] Transposh <= 1.0.7 “tp_tp” Unauthenticated Reflected Cross-Site Scripting [CVE-2021-24911] Transpos...
> Phishers Targeted Financial Services Most During H1 2022
The report found Microsoft was the most impersonated brand overall
> Poor Training and Communications Hindering Cybersecurity Efforts
Over a third (36%) of employees consider security training boring