[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Major League Baseball Players’ Personal Data Stolen
Sports stars’ information swiped in cyber-attack on third-party vendor
> Utah Becomes Latest US State to Pass a Data Privacy Law
The Utah Consumer Privacy Act (UCPA) follows in the footsteps of laws passed in California, Virginia and Colorado
> Towards Practical Security Optimizations for Binaries
To be thus is nothing, but to be safely thus. (Macbeth: 3.1) It’s not enough that compilers generate efficient code, they must also generate safe code. Despite the extensive testing and correctness certification that goes into developing compilers and their optimization passes, they may inadvertentl...
> EU and US Agree Deal to Reopen Seamless Transatlantic Data Flows
The new framework is designed to revamp the previous Privacy Shield arrangement between the EU and US
> London DJ Surrenders ÂŁ214,000 of Music Kit in Money Laundering Case
Nightclub owner’s equipment linked to infamous QQAAZZ group
> Anonymous Blob Access
Finding and accessing files stored in Azure Storage Accounts without authentication.
> Four Russians Charged with Dragonfly Attacks on Critical Infrastructure
Six-year campaign targeted thousands of machines in global energy sector
> UK Teen Arrested in Lapsus Crackdown
Seven youngsters held in coordinated police operation
> Flipper Zero - Initial Thoughts
After a bit of a delay my Flipper Zero finally arrived in the mail. If you are not familiar with Flipper Zero at all, check out the original Kickstarter page from a few years back. This is what the package looks like after opening. It contains the device, a USB cable, a quick start manual (mostly po...
> Mitek Acquires HooYu for $129m
Pioneering British KYC tech company acquired by American ID verification firm
> Indian Police Bust Online Helicopter Scam
Arrests made over fake websites selling forged helicopter ride tickets to pilgrims
> CVE-2022-27226: CSRF to RCE in iRZ Mobile Routers through 2022-03-16
Credits Vulnerability Discovery John Chris Mack Exploit Development Stephen Chavez Robert Willis Identification Default credentials were discovered on an iRZ Mobile Router login page. Utilizing root:root gave us access to the administrative functionality for the device. Having administrative access...
> US Indicts Russian Over "Carding Shop"
Russian allegedly operated darknet store, selling stolen PII, credentials and authentication tools
> ISACA: Two-Thirds of Cybersecurity Teams Are Understaffed
ISACA's State of Cybersecurity 2022 report revealed ongoing struggles to hire and retain skilled cybersecurity professionals
> Soft Deleted Blobs
Recovering and accessing files in private Storage Accounts that have been deleted.
> Ransomware Payments Hit Record Highs in 2021
Palo Alto claims Conti was most prolific actor last year
> Okta CSO: Lapsus Incident Was “Embarrassing”
Firm confirms hackers accessed internal systems via RDP
> AWS API Call Hijacking via ACM-PCA
By modifying the route53 entries and utilizing the acm-pca private CA one can hijack the calls to AWS API inside the AWS VPC
> Investment Fraud Surges as Cybercrime Losses Hit $7bn in 2021
FBI report finds BEC still the biggest earner for cyber-criminals
> Prison for New Orleanian who Exploited Patients’ Stolen Data
Convict bought stolen data and used it to fraudulently obtain at least $200K