> TODAY'S SUMMARY (82 articles)
Today's cybersecurity news highlights several significant threats and trends. A Californian individual has been accused of illegally exporting $300 million worth of Nvidia chips to China, potentially aiding advancements in AI technology. The U.S. Treasury has sanctioned members of the Tren de Aragua gang linked to ATM jackpotting attacks, emphasizing ongoing concerns over organized cybercrime. A critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent patching efforts. Additionally, AI agents are increasingly being used in cyberattacks, including SQL injection attempts against government websites. The rise of AI in both offensive and defensive roles continues to shape the cybersecurity landscape, with Microsoft warning that attackers are gaining significant advantages through AI.
|
// AI-powered summary generated at 16:01
The research found that over a third of UK retailers have no published DMARC record at all
Much work still to do on diversity and inclusion, says NCSC
During my summer internship, I had the wonderful opportunity to work on the Manticore User Interface (MUI). The MUI project aims to combine the strength of both Manticore, a powerful symbolic execution library, and Binary Ninja, a popular binary analysis tool, to provide a more intuitive and visual...
UK firms struggling to turn increased spending into better outcomes
NCSC notifies SMBs after proactive scanning program
Trent Brunson, Head of Research & Engineering Originally published on October 15, 2021 Come join our team today! Trail of Bits is hiring full-time Senior Software Engineers and Software Security Research Engineers. Over the last nine years, I’ve interviewed hundreds of applicants for research an...
Newly discovered bug in two Cisco devices could lead to denial of service
Arrest made in biggest ever Bitcoin heist involving a single victim
Originally published on October 12, 2021 Consensus protocols have come to play a critical role in many applications. Fischer, Lynch, and Paterson’s classic impossibility result showed that under reasonable assumptions, it can be impossible for a protocol to reach consensus. In Dwork, Lynch, and Stoc...
Web-hosting company says unauthorized third party accessed email addresses of WordPress customers
Online shoppers have been warned to take extra care to check payment pages are secure this Black Friday
Originally published on October 6, 2021 TL;DR: Version 5.0.1 of osquery, a cross-platform, open-source endpoint visibility agent, is now available. This release is an exciting milestone for the project, as it introduces an EndpointSecurity-based process events table for macOS. Read on to learn how w...
Exchange Server compromise enables them to send convincing internal emails
Regulator claims some scammers are using real identities of its staff
Originally published August 11, 2021 TL;DR: These simpler, step-by-step methods equip you to apply BPF tracing technology to real-word problems—no specialized tools or libraries required. BPF, a tracing technology in the Linux kernel for network stack tracing, has become popular recently thanks to n...
Vestas shuts IT systems in multiple locations
Entertainment company repeatedly pushed back updates after being notified of serious vulnerability
Originally published August 3, 2021 During my Trail of Bits winternship and springternship, I had the pleasure of working with Suha Hussain and Jim Miller on PrivacyRaven, a Python-based tool for testing deep-learning frameworks against a plethora of privacy attacks. I worked on improving PrivacyRav...
Sparks Group member pleads guilty to illegally distributing movies and TV shows on the internet
Hackers allegedly posed as Proud Boys to influence 2020 presidential election