> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities. A major incident involved hackers hijacking Microsoft's official X account to promote a cryptocurrency scheme, showcasing the ongoing risks of social media exploitation. Additionally, a critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent action from users and inclusion in the U.S. CISA's Known Exploited Vulnerabilities catalog. On the espionage front, a China-aligned group has been phishing AI policy experts by impersonating US officials, emphasizing the trend of targeting high-profile individuals. Meanwhile, AI agents are increasingly being linked to SQL injection attacks against government sites, raising concerns about the security of AI applications. Lastly, law enforcement has made arrests in the KillSec ransomware group, reflecting ongoing efforts to combat cybercrime.
|
// AI-powered summary generated at 12:00
Two Eastern Europeans receive prison sentences for helping cyber-criminals to distribute malware
US seeks to recover $9.9m from Montanan fined for making nearly 5,000 illegal and malicious robocalls
This post is part of a series about Offensive BPF to learn how BPFs use will impact offensive security, malware, and detection engineering.
Click the “ebpf” tag to see all relevant posts.
Building advanced BPF programs So far in this Offensive BPF series the focus was on bpftrace to build and run BP...
NPower and CyberWarrior receive funding to train unemployed and underemployed
Of those organizations impacted by DNS attacks, 61% were targeted on multiple occasions
Résumé Le protocole d’authentification NTLM souffre de faiblesses permettant, sous conditions, à un attaquant de relayer une authentification qu’il reçoit d’une victime vers un serveur cible. Ceci peut potentiellement permettre à cet attaquant d’élever ses privilèges ou d’envoyer des commandes à ...
The changing nature of insider threats and how to mitigate them were topics of a talk by Lisa Forte
Check Point researchers warn platform needs more in-built protections
This post is part of a series about Offensive BPF that I’m working on to learn how BPFs use will impact offensive security, malware, and detection engineering.
Click the “ebpf” tag to see all relevant posts.
One of the issues I ran into when trying out sslsniff-bpfcc was that it did not work with Fi...
Latest commerce department rule will include exemptions
Information was found in a misconfigured Elasticsearch server
Credits John
Github: https://github.com/johnjhacking
Molly White
Twitter: https://twitter.com/molly0xFFF
Zultan
Twitter: https://twitter.com/orpheus9001
Summary First and foremost, we may have taken the phrase “Hack the Planet” a little too serious.
Google Earth Enterprise is an application that is...
New study reveals changing tactics of Russian-speaking threat actors from 2015 to now
New York Metro InfraGard Members Alliance and the Space Information Sharing and Analysis Center announce cybersecurity MOU
Today you are in for a special treat. Did you know that an adversary can hide a smaller image within a larger one?
This video demonstrates how a small image becomes magically visible when the computer resizes the large image, and also how to mitigate the vulnerability.
This is possible when vulnerab...
Show-Me State facing big bill after making personal data of school employees vulnerable
65% of respondents believe a cyber attack on their organization could lead to loss of life
Tabnabbing is a web application security vulnerability that can be used to perform phishing attacks, so its important to be aware of it as a developer and penetration tester.
It is easy to mitigate and in this short video we cover both attacks and mitigations.
Thanks for reading and happy hacking!
@...
Individual purports to have ID card details of entire population
The Supply Chain Security group will bring in experts from across the tech sphere