> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities. A major incident involved hackers hijacking Microsoft's official X account to promote a cryptocurrency scheme, showcasing the ongoing risks of social media exploitation. Additionally, a critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent action from users and inclusion in the U.S. CISA's Known Exploited Vulnerabilities catalog. On the espionage front, a China-aligned group has been phishing AI policy experts by impersonating US officials, emphasizing the trend of targeting high-profile individuals. Meanwhile, AI agents are increasingly being linked to SQL injection attacks against government sites, raising concerns about the security of AI applications. Lastly, law enforcement has made arrests in the KillSec ransomware group, reflecting ongoing efforts to combat cybercrime.
|
// AI-powered summary generated at 12:00
Most computer code compilers are at risk of âTrojan sourceâ attacks in which adversaries can introduce targeted vulnerabilities into any software
Facebook prioritizes profits over user safety, according to whistleblower and former Facebook employee, Frances Haugen
Le dĂ©partement amĂ©ricain de la SantĂ© et des Services sociaux (HHS) a conclu un accord de rĂšglement de 90 000 dollars avec Virtual Private Network Solutions (VPN Solutions) pour une violation potentielle de la rĂšgle de sĂ©curitĂ© HIPAA suite Ă une attaque de ransomware en 2021. L'enquĂȘte a rĂ©vĂ©lĂ© que V...
Colleton County School Board votes to spend nearly $200K investigating âcyber-incidentâ
PHI of more than 650K patients of Community Medical Centers may have been exposed
Information about the data an attacker can access via GCP's API endpoints
Mobile payment service aids couple whose bank account was drained by hackers
Exmatter delivers custom exfiltration to accelerate ransomware attacks
This post is part of a series about Offensive BPF to learn how BPFs use will impact offensive security, malware, and detection engineering.
Click the âebpfâ tag to see all relevant posts.
Building advanced BPF programs So far in this Offensive BPF series the focus was on bpftrace to build and run BP...
London-headquartered Graff plays down impact of data theft
Joint international operation began in 2019
RĂ©sumĂ© Le protocole dâauthentification NTLM souffre de faiblesses permettant, sous conditions, Ă un attaquant de relayer une authentification quâil reçoit dâune victime vers un serveur cible. Ceci peut potentiellement permettre Ă cet attaquant dâĂ©lever ses privilĂšges ou dâenvoyer des commandes Ă ...
Allegations include illegal streaming and an attempt to extort $150K from Major League Baseball
Cerberus Cyber Sentinel Corporation snaps up New Jersey-based managed security services provider
This post is part of a series about Offensive BPF that Iâm working on to learn how BPFs use will impact offensive security, malware, and detection engineering.
Click the âebpfâ tag to see all relevant posts.
One of the issues I ran into when trying out sslsniff-bpfcc was that it did not work with Fi...
Pax Technologyâs Florida warehouse searched by FBI and other US agencies
One in 10 professionals will exit the industry in 2022, analyst claims
Problem was fixed promptly by healthcare AI company
Russian national extradited to the US from South Korea
Roughly 30,000 CU Boulder affiliates impacted by exploitation of software vulnerability