[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (82 articles)

|

// AI-powered summary generated at 16:01

> Log4Shell and Request Forgery Attacks
The last weeks of 2021 got quite interesting for security professionals and software engineers. Apache’s log4j library and its now prominent Java Naming and Directory Interface support, which enables easy remote code execution, made the news across the industry. What makes Log4Shell scary is the wid...
> Investigation Launched into App “Selling” Women
App sharing photos of Muslim women who are “for sale” reported to Indian police
> Google Acquires its First Non-American Cybersecurity Firm
Israel-based cybersecurity specialist Siemplify bought out by American tech company
> Celebrating our 2021 Open Source Contributions
At Trail of Bits, we pride ourselves on making our best tools open source, such as algo, manticore, and graphtage. But while this post is about open source, it’s not about our tools… In 2021, Trail of Bits employees submitted over 190 pull requests (PRs) that were merged into non-Trail of Bits repos...
> UWO Opens New Cybersecurity Center
Users can learn how to tackle real-world threats at new Wisconsin cybersecurity facility
> Money Launderers Get 33 Years for ÂŁ70m Criminal Scheme
Duo stole £10m from UK’s pandemic loan scheme
> Terraform Enterprise: Attack the Metadata Service
Leverage a default configuration in Terraform Enterprise to steal credentials from the Metadata Service
> UK Defence Academy Attack Forced IT Rebuild – Report
Senior military official claims “significant” operational impact
> Microsoft Fixes New Year's Day Exchange Server Bug
Issue led to empty inboxes on first day back at work
> Disclosing Shamir’s Secret Sharing vulnerabilities and announcing ZKDocs
Trail of Bits is publicly disclosing two bugs that affect Shamir’s Secret Sharing implementation of Binance’s threshold signature scheme library (tss-lib) and most of its active forks. Here is the full list of affected repositories: Binance’s tss-lib Clover Network’s threshold-crypto Keep Network’s...
> Albania's Prime Minister Issues Data Leak Apology
Personal data of hundreds of thousands of Albanian citizens leaked on social media
> Russia Fines Google $100m Over "Illegal" Content
Moscow slaps American tech giant with largest ever penalty relating to banned content
> Zero Trust migration: where do I start?
How to start the journey to zero trust architecture once you have decided it meets your business requirements.
> NY Makes Falsifying Vaccination Cards a Crime
Falsifying COVID-19 vaccination card data is now a Class D felony in the state of New York
> Hellmann Warns Customers They Could Face Malicious Communications Following Attack
Hellmann confirmed that data was extracted from its systems during the ransomware attack earlier this month
> Why vulnerabilities are like buses
How organisations can address the growing trend in which multiple vulnerabilities within a single product are exploited over a short period.
> Former Uber CSO Faces New Charge for 2016 Breach
US feds accuse Joe Sullivan of using bug bounty to conceal 2016 hack and breach
> Unique Cyber-Attacks Fall for First Time Since 2018
The researchers recorded a 4.8% decline in unique attacks in Q3 compared to Q2 2021
> Detecting MISO and Opyn’s msg.value reuse vulnerability with Slither
On August 18, 2021, samczsun reported a critical vulnerability in SushiSwap’s MISO smart contracts, which put ~350 million USD (109 thousand ETH) at risk. This issue is similar to an attack that was conducted on the Opyn codebase in August of 2020. At the time of the report, I was finishing my […]
> Russian Hacker’s $1.7M Restitution Order Overturned
Ninth Circuit rules Yevgeniy Nikulin will not have to compensate tech companies for 2012 data breach