Suit alleges Eastern Ozarks Regional Health System failed to protect patient and employee data
Streaming service to charge Latin American users who share password with non-householders
Recovering and accessing files in private Storage Accounts that have been deleted.
The campaign recommends using passwords containing three random words and enabling two-factor authentication
Researchers warn that large-scale campaign may be building
By modifying the route53 entries and utilizing the acm-pca private CA one can hijack the calls to AWS API inside the AWS VPC
EU issues urgent bulletin for aviation companies and authorities
Drop in ransomware and BEC indicates more targeted attacks
One area that I have encountered quite often over the years is that during recon phase of a bug bounty hunt or pentest a set of AWS access keys are being discovered.
Let’s say you found 50 AWS access keys by drooling and hunting through public Github repos and using other nifty tricks and means.
How...
Cyber-criminals impersonate aid organizations to steal crypto intended for Ukraine
New resource to address need for virtual asset expertise in law enforcement and intelligence communities
This white paper explains how basic security controls can protect organisations from the most common cyber attacks.
The new law will force US critical infrastructure organizations to report cyber incidents within 72 hours
New obligations will be placed on social media firms to prevent and remove harmful content on their platforms
This summer at Black Hat, we have published research about exploiting Huawei basebands (video recording also available here). The remote code execution attack surface explored in that work was the Radio Resource stack’s CSN.1 decoder. Searching for bugs in CSN.1 decoding turned out to be very fruitf...
A bigger payout encourages threat actors to put more time in
Honeypot data highlights importance of good IT hygiene
Summary In this advisory we are disclosing a heap overflow vulnerability in the MediaTek baseband. The vulnerability can be exploited to gain arbitrary code execution in the context of the baseband runtime. The vulnerability was fixed in 2020 in some models, and received a CVE and more widely deploy...
Meta acts fast to remove fake clip of Ukrainian President
City council approves $10m appropriation toward Dakota State University cybersecurity lab