[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 08:00

> Marriott Plays Down 20GB Data Breach
Global hotel chain compromised yet again
> North Korean Hackers Target US Health Providers With 'Maui' Ransomware
According to CISA, the threat actors have been engaging in these campaigns since May 2021
> Knowledge Base Digest - June 2022
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in June: Articles Configure a BOVPN virtual interface in Fireware v11.11.x that uses GRE for dynamic routing to a Cisco endpoint Geoblocking can block connections to inte...
> APT Hacker Group Bitter Continues to Attack Military Targets in Bangladesh
The weaponized Excel document would likely be distributed by means of a spear-phishing email
> Hive Ransomware Upgraded to Rust to Deliver More Sophisticated Encryption
Hive is not the first ransomware written in Rust, and follows in the footsteps of BlackCat
> libmagic: The Blathering
A couple of years ago we released PolyFile: a utility to identify and map the semantic structure of files, including polyglots, chimeras, and schizophrenic files. It’s a bit like file, binwalk, and Kaitai Struct all rolled into one. PolyFile initially used the TRiD definition database for file ident...
> Google Patches Chrome Zero Day Under Attack
Rapid fix for vulnerability being exploited in the wild
> NCSC: Prepare for Protected Period of Heightened Cyber-Risk
Agency warns Russian threat will remain elevated for a long time
> Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT
Background Typically, organizations utilize Zix Secure Messaging as a convenient alternative to Dropbox or other file sharing related tools because it’s easier to share sensitive information with users outside of the organization. Shadow IT has always been a standing issue among large enterprises an...
> Software Supply Chain Attack Hits Thousands of Apps
Researchers discover malicious npm packages
> NIST Acknowledges First Four Quantum-Resistant Encryption Tools
The four algorithms will now become part of NIST’s post-quantum cryptographic standard
> A Typical Day as a Trail of Bits Engineer-Consultant
Wherever you are in the world, a typical day as a Trail of Bits Engineer-Consultant means easing into your work. Here’s a short video showing some of our European colleagues describing a typical day as a Trail of Bits Engineer-Consultant: You generally set your own hours, to provide at least a coupl...
> TikTok CEO Addresses US Security Concern
Shou Zi Chew claims Project Texas is intended to strengthen the company’s data security posture
> Advanced Phishing Scams Target Middle East and Impersonate UAE Ministry of Human Resources
The phishing campaign mainly targets individual job seekers and businesses
> The Trail of Bits Hiring Process
When engineers apply to Trail of Bits, they’re often surprised by how straightforward and streamlined our hiring process is. After years of experience, we’ve cut the process to its bedrock, so that it’s candidate focused, quick, and effective. Here’s a short video showing some of our European collea...
> Hacker Claims to Have Personal Data of 1 Billion Chinese Citizens
An anonymous hacker said they obtained the information from a leaked Shanghai National Police Database
> UK Councils and Hospitals Vulnerable to Cyber Hackers
Investigation found hundreds of vulnerabilities on UK public service websites
> Post Exploitation: Sniffing Logon Passwords with PAM
Pluggable Authentication Modules (PAM) on Unix based systems are useful to change logon behavior and enforce authentication via various means. In “Red Team Strategies” the chapter “Protecting the Pentester” walks the reader through the configuration of a PAM module to get notified in real-time via a...
> NATO to Develop Rapid Cyber Response Capabilities
NATO member nations unveil plans to build and exercise a virtual rapid response cyber capability
> British Army Social Media Accounts Hijacked
Hackers used them to promote crypto scams