> TODAY'S SUMMARY (114 articles)
Today's cybersecurity landscape highlights several critical concerns. The Warlock ransomware group has escalated its attacks on critical infrastructure, exploiting SharePoint vulnerabilities across various sectors. A significant breach at Frontline Education has exposed sensitive employee data from multiple school districts, raising alarms about third-party software vulnerabilities. Additionally, a zero-day vulnerability in Fortinet's FortiMail is currently being exploited, prompting urgent calls for patches. On the legislative front, bipartisan efforts are underway to regulate automated license plate readers (ALPRs) and site-blocking measures, indicating growing scrutiny over surveillance technologies. As AI continues to advance, concerns about its misuse in cyberattacks are surfacing, with reports of AI agents attempting SQL injection on government sites. Overall, the interplay of AI advancements and critical infrastructure vulnerabilities remains a pressing issue in the cybersecurity domain.
|
// AI-powered summary generated at 20:00
Document published on government website revealed unidentified hackers infiltrated Foreign Office systems
Time for reflection may also increase anxiety and improve awareness
During an assessment you may find AWS IAM credentials. Use these tactics to identify the principal of the keys.
All vulnerabilities rated “important” with one publicly disclosed
CIISec’s Extended Project Qualification is open to anyone over 14
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in January:
Articles
AuthPoint Gateway continuously loses connection to WatchGuard Cloud
Change the Admin and Status passwords on a Firebox
Connect to a Wi-Fi in WatchGua...
Katie Arrington steps down in protest over movement of CMMC Program to DOD CIO’s office
Vintage cyber-attack tactic revived to phish Microsoft 365 users
Let’s implement crypto! Welcome to the second part of our posts on the challenges of implementing constant-time Rust code. Part 1 discussed challenges with constant-time implementations in Rust and WebAssembly and how optimization barriers can mitigate risk. The Rust crypto community has responded w...
Hytera Communications Corp accused of hiring Motorola employees to steal DMR technology
The salary guide provided the median salaries across 10 major job roles in cybersecurity
Modify existing GuardDuty configurations in the target account to hinder alerting and remediation capabilities.
Ofcom is likely to recommend using age verification technologies that minimize handling of users’ data
Redmond giant blocks VBA macros downloaded from the internet
Many engineers choose Rust as their language of choice for implementing cryptographic protocols because of its robust security guarantees. Although Rust makes safe cryptographic engineering easier, there are still some challenges to be aware of. Among them is the need to preserve constant-time prope...
A fifth of online traffic last year was malicious, as fraud mounts
Six individuals are accused of involvement in card fraud
...and that's why we are making some changes. Anne W summarises what they are, and explains the thinking behind them.
Facebook and Instagram to be shuttered in Europe unless new agreement reached over data sharing, processing and storage
CTO says “limited number” of journalist and staff email accounts and documents compromised