[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Arkansas Sues Health System for Abandoning Patient Files
Suit alleges Eastern Ozarks Regional Health System failed to protect patient and employee data
> Netflix to Charge Password Sharers
Streaming service to charge Latin American users who share password with non-householders
> Soft Deleted Blobs
Recovering and accessing files in private Storage Accounts that have been deleted.
> NCSC Launches Awareness Campaign to Strengthen Password Practices
The campaign recommends using passwords containing three random words and enabling two-factor authentication
> Cyclops Blink Malware Expands to Target Asus
Researchers warn that large-scale campaign may be building
> AWS API Call Hijacking via ACM-PCA
By modifying the route53 entries and utilizing the acm-pca private CA one can hijack the calls to AWS API inside the AWS VPC
> Aircraft Disrupted by Satellite Jamming Following Russian Invasion
EU issues urgent bulletin for aviation companies and authorities
> Cloud-Based Email Threats Surge 50% in 2021
Drop in ransomware and BEC indicates more targeted attacks
> AWS Scaled Command Bash Script - Run AWS commands for many profiles
One area that I have encountered quite often over the years is that during recon phase of a bug bounty hunt or pentest a set of AWS access keys are being discovered. Let’s say you found 50 AWS access keys by drooling and hunting through public Github repos and using other nifty tricks and means. How...
> Phishers Using Ukraine Invasion to Solicit Cryptocurrency
Cyber-criminals impersonate aid organizations to steal crypto intended for Ukraine
> FBI Launches Virtual Assets Unit
New resource to address need for virtual asset expertise in law enforcement and intelligence communities
> Common Cyber Attacks: Reducing the Impact
This white paper explains how basic security controls can protect organisations from the most common cyber attacks.
> US Passes "Game-Changing" Cyber Incident Reporting Legislation
The new law will force US critical infrastructure organizations to report cyber incidents within 72 hours
> Landmark Online Safety Bill Introduced to UK Parliament
New obligations will be placed on social media firms to prevent and remove harmful content on their platforms
> [BugTales] Exploiting CSN.1 Bugs in MediaTek Basebands
This summer at Black Hat, we have published research about exploiting Huawei basebands (video recording also available here). The remote code execution attack surface explored in that work was the Radio Resource stack’s CSN.1 decoder. Searching for bugs in CSN.1 decoding turned out to be very fruitf...
> Conversation Hijacking Soars 270% to Enable BEC
A bigger payout encourages threat actors to put more time in
> Raspberry Pi Users Urged to Change Default Passwords as Attacks Surge
Honeypot data highlights importance of good IT hygiene
> CVE-2021-32484: Heap Buffer overflow in GSM RRM E-UTRAN Individual Priority Parameters
Summary In this advisory we are disclosing a heap overflow vulnerability in the MediaTek baseband. The vulnerability can be exploited to gain arbitrary code execution in the context of the baseband runtime. The vulnerability was fixed in 2020 in some models, and received a CVE and more widely deploy...
> Russia Uses Deepfake of Zelensky to Spread Disinformation
Meta acts fast to remove fake clip of Ukrainian President
> Sioux Falls Funds DSU Cybersecurity Lab
City council approves $10m appropriation toward Dakota State University cybersecurity lab