> TODAY'S SUMMARY (82 articles)
Today's cybersecurity news highlights several significant threats and trends. A Californian individual has been accused of illegally exporting $300 million worth of Nvidia chips to China, potentially aiding advancements in AI technology. The U.S. Treasury has sanctioned members of the Tren de Aragua gang linked to ATM jackpotting attacks, emphasizing ongoing concerns over organized cybercrime. A critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent patching efforts. Additionally, AI agents are increasingly being used in cyberattacks, including SQL injection attempts against government websites. The rise of AI in both offensive and defensive roles continues to shape the cybersecurity landscape, with Microsoft warning that attackers are gaining significant advantages through AI.
|
// AI-powered summary generated at 16:01
The last weeks of 2021 got quite interesting for security professionals and software engineers.
Apache’s log4j library and its now prominent Java Naming and Directory Interface support, which enables easy remote code execution, made the news across the industry.
What makes Log4Shell scary is the wid...
App sharing photos of Muslim women who are “for sale” reported to Indian police
Israel-based cybersecurity specialist Siemplify bought out by American tech company
At Trail of Bits, we pride ourselves on making our best tools open source, such as algo, manticore, and graphtage. But while this post is about open source, it’s not about our tools… In 2021, Trail of Bits employees submitted over 190 pull requests (PRs) that were merged into non-Trail of Bits repos...
Users can learn how to tackle real-world threats at new Wisconsin cybersecurity facility
Duo stole £10m from UK’s pandemic loan scheme
Leverage a default configuration in Terraform Enterprise to steal credentials from the Metadata Service
Senior military official claims “significant” operational impact
Issue led to empty inboxes on first day back at work
Trail of Bits is publicly disclosing two bugs that affect Shamir’s Secret Sharing implementation of Binance’s threshold signature scheme library (tss-lib) and most of its active forks. Here is the full list of affected repositories: Binance’s tss-lib Clover Network’s threshold-crypto Keep Network’s...
Personal data of hundreds of thousands of Albanian citizens leaked on social media
Moscow slaps American tech giant with largest ever penalty relating to banned content
How to start the journey to zero trust architecture once you have decided it meets your business requirements.
Falsifying COVID-19 vaccination card data is now a Class D felony in the state of New York
Hellmann confirmed that data was extracted from its systems during the ransomware attack earlier this month
How organisations can address the growing trend in which multiple vulnerabilities within a single product are exploited over a short period.
US feds accuse Joe Sullivan of using bug bounty to conceal 2016 hack and breach
The researchers recorded a 4.8% decline in unique attacks in Q3 compared to Q2 2021
On August 18, 2021, samczsun reported a critical vulnerability in SushiSwap’s MISO smart contracts, which put ~350 million USD (109 thousand ETH) at risk. This issue is similar to an attack that was conducted on the Opyn codebase in August of 2020. At the time of the report, I was finishing my […]
Ninth Circuit rules Yevgeniy Nikulin will not have to compensate tech companies for 2012 data breach