[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> UK Announces Legislation to Govern Digital Identity Security
The new rules are designed to improve trust in digital identity solutions
> #DSbD: Cybersecurity Advances Must Focus on Building Trust in Technologies
Cybersecurity must be about growing trust in technologies rather than surveillance and control, argues Prof Adam Joinson
> Common Cyber Attacks: Reducing the Impact
This white paper explains how basic security controls can protect organisations from the most common cyber attacks.
> Ukrainian IT Army Hijacked by Info-stealing Malware
DDoS tools may be booby-trapped, warns Cisco
> SEC Proposes Four-Day Breach Notification Rules
Move is aimed at driving accountability and transparency
> [BugTales] Exploiting CSN.1 Bugs in MediaTek Basebands
This summer at Black Hat, we have published research about exploiting Huawei basebands (video recording also available here). The remote code execution attack surface explored in that work was the Radio Resource stack’s CSN.1 decoder. Searching for bugs in CSN.1 decoding turned out to be very fruitf...
> Vodafone and Mercado Libre Likely Hit by Ransomware Attacks
Lapsus group appears to have compromised new targets
> Colorado Elections Clerk Charged with Identity Theft
Grand jury indicts two women on suspicion of tampering with election equipment
> CVE-2021-32484: Heap Buffer overflow in GSM RRM E-UTRAN Individual Priority Parameters
Summary In this advisory we are disclosing a heap overflow vulnerability in the MediaTek baseband. The vulnerability can be exploited to gain arbitrary code execution in the context of the baseband runtime. The vulnerability was fixed in 2020 in some models, and received a CVE and more widely deploy...
> Qakbot Debuts New Technique
Old botnet performs new trick by inserting itself into the middle of email threads
> Alleged Kaseya Attacker Extradited to US
Defendant indicted over deployment of REvil ransomware arrives in America
> CVE-2021-32485: Heap Buffer overflow in GSM RRM UTRAN Individual Priority Parameters
Summary In this advisory we are disclosing a heap overflow vulnerability in the MediaTek baseband. The vulnerability can be exploited to gain arbitrary code execution in the context of the baseband runtime. The vulnerability was fixed in 2020 in some models, and received a CVE and more widely deploy...
> AI Accountability Framework Created to Guide Use of AI in Security
The framework aims to mitigate ethical issues surrounding use of AI in security
> 90% of MSPs Hit By a Successful Cyber-Attack in the Past 18 Months
The research indicates that MSPs are becoming more of a primary target for cyber-criminals than their customers
> CVE-2021-32486: Heap Buffer overflow in GSM RRM E-UTRAN IPP with extended EARFCNs
Summary In this advisory we are disclosing a heap overflow vulnerability in the MediaTek baseband. The vulnerability can be exploited to gain arbitrary code execution in the context of the baseband runtime. The vulnerability was fixed in 2020 in some models, and received a CVE and more widely deploy...
> UK Security Agency Issues New Guidance on Data Center Protection
As bombs fly in Ukraine, datacenter owners are urged to take action
> Conti Group Spent $6m on Salaries, Tools and Services in a Year
Report dives into recent leak of internal data on ransomware group
> CVE-2021-32487: Heap Buffer overflow in GSM RRM Channel Release, Cell Selection Indicator
Summary In this advisory we are disclosing a heap overflow vulnerability in the MediaTek baseband. The vulnerability can be exploited to gain arbitrary code execution in the context of the baseband runtime. The vulnerability was fixed in 2020 in some models, and received a CVE and more widely deploy...
> Over 90% of Exposed Russian Cloud Databases Compromised
Researcher finds pro-Ukraine hacktivists are having an impact
> Consumers Worried About Digital Banking Security
Study finds most consumers prefer to bank online, but are concerned about potential fraud