> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities. A major incident involved hackers hijacking Microsoft's official X account to promote a cryptocurrency scheme, showcasing the ongoing risks of social media exploitation. Additionally, a critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent action from users and inclusion in the U.S. CISA's Known Exploited Vulnerabilities catalog. On the espionage front, a China-aligned group has been phishing AI policy experts by impersonating US officials, emphasizing the trend of targeting high-profile individuals. Meanwhile, AI agents are increasingly being linked to SQL injection attacks against government sites, raising concerns about the security of AI applications. Lastly, law enforcement has made arrests in the KillSec ransomware group, reflecting ongoing efforts to combat cybercrime.
|
// AI-powered summary generated at 12:00
The possibility hackers accessed medical information “cannot be ruled out"
Adam Laurie explains why we should be worried by the risk of time synchronization being targeted by hackers
Originally published on October 6, 2021 TL;DR: Version 5.0.1 of osquery, a cross-platform, open-source endpoint visibility agent, is now available. This release is an exciting milestone for the project, as it introduces an EndpointSecurity-based process events table for macOS. Read on to learn how w...
Void Balaur has been operating since 2015
Trio charged with fraud and money laundering
Originally published August 11, 2021 TL;DR: These simpler, step-by-step methods equip you to apply BPF tracing technology to real-word problems—no specialized tools or libraries required. BPF, a tracing technology in the Linux kernel for network stack tracing, has become popular recently thanks to n...
On average, victims face bill of over $6m
Distributed Denial of Secrets group posts online video stolen from DPD and Georgia State Patrol
Originally published August 3, 2021 During my Trail of Bits winternship and springternship, I had the pleasure of working with Suha Hussain and Jim Miller on PrivacyRaven, a Python-based tool for testing deep-learning frameworks against a plethora of privacy attacks. I worked on improving PrivacyRav...
Fishing fans shown tackle of a very different kind after cyber-attack on angling store
Until more organizations act on the severity of the threat, “consistent attacks are expected"
Originally published May 20, 2021 This blog post introduces Dylint, a tool for loading Rust linting rules (or “lints”) from dynamic libraries. Dylint makes it easy for developers to maintain their own personal lint collections. Previously, the simplest way to write a new Rust lint was to fork Clippy...
Leveraging 'ego-centrism' is key to cultivating individuality within a team context
Claim alleging Google unlawfully tracked iPhone users’ personal data is rejected by UK’s Supreme Court
Originally published May 10, 2021 While learning how to write multithreaded code in Java or C++ can make computer science students reconsider their career choices, calling a function asynchronously in Go is just a matter of prefixing a function call with the go keyword. However, writing concurrent G...
Too much of what goes on in the digital space is unaccountable and insecure, according to Marrietje Schaake
The Black Hat Europe 2021 session discussed the state of cybersecurity and why zero trust is crucial
Cybersecurity breaches follow common patterns and stages - from an initial Beachhead to accomplishing Objectives.
This video gives an overview of the anatomy of a compromise:
Cheers.
@wunderwuzzi23
Campaign follows separate CISA warning in September
Research warns of complacency among senior IT decision-makers