WikiLeaks founder’s appeal against extradition to US refused by UK Supreme Court
Cyber-attack on German subsidiary of Russian state-backed energy company
By modifying the route53 entries and utilizing the acm-pca private CA one can hijack the calls to AWS API inside the AWS VPC
PHI of 287K patients at risk after cyber-attack on South Denver Cardiology Associates
The widescale DDoS attack is suspected to have been conducted by a nation-state actor
One area that I have encountered quite often over the years is that during recon phase of a bug bounty hunt or pentest a set of AWS access keys are being discovered.
Let’s say you found 50 AWS access keys by drooling and hunting through public Github repos and using other nifty tricks and means.
How...
Zimperium report warns of bugs, malware and misconfigurations
CaddyWiper looks like nothing else, says ESET
This white paper explains how basic security controls can protect organisations from the most common cyber attacks.
Facial recognition company lists multiple ways tech could be used by Kyiv
Alleged DDoS attacker arrested at home while apparently 3D printing a gun
This summer at Black Hat, we have published research about exploiting Huawei basebands (video recording also available here). The remote code execution attack surface explored in that work was the Radio Resource stack’s CSN.1 decoder. Searching for bugs in CSN.1 decoding turned out to be very fruitf...
People who send unsolicited sexual images could serve two years in prison
Research finds “startlingly low understanding” of cybersecurity risks among school leaders
Summary In this advisory we are disclosing a heap overflow vulnerability in the MediaTek baseband. The vulnerability can be exploited to gain arbitrary code execution in the context of the baseband runtime. The vulnerability was fixed in 2020 in some models, and received a CVE and more widely deploy...
From today, UK shoppers will have to provide a combination of two forms of identification at checkout when making an online purchase
Accenture says cybercrime underground is split down ideological lines
Summary In this advisory we are disclosing a heap overflow vulnerability in the MediaTek baseband. The vulnerability can be exploited to gain arbitrary code execution in the context of the baseband runtime. The vulnerability was fixed in 2020 in some models, and received a CVE and more widely deploy...
Security failings led to serious data breach at Tuckers Solicitors
Regulator warns consumers it is planning to shut them down