> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities. A major incident involved hackers hijacking Microsoft's official X account to promote a cryptocurrency scheme, showcasing the ongoing risks of social media exploitation. Additionally, a critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent action from users and inclusion in the U.S. CISA's Known Exploited Vulnerabilities catalog. On the espionage front, a China-aligned group has been phishing AI policy experts by impersonating US officials, emphasizing the trend of targeting high-profile individuals. Meanwhile, AI agents are increasingly being linked to SQL injection attacks against government sites, raising concerns about the security of AI applications. Lastly, law enforcement has made arrests in the KillSec ransomware group, reflecting ongoing efforts to combat cybercrime.
|
// AI-powered summary generated at 12:00
Sinclair Broadcast Group’s data exposed in weekend ransomware attack
Online fraud alone was associated with well-being losses of ÂŁ7.2bn
Résumé Le protocole d’authentification NTLM souffre de faiblesses permettant, sous conditions, à un attaquant de relayer une authentification qu’il reçoit d’une victime vers un serveur cible. Ceci peut potentiellement permettre à cet attaquant d’élever ses privilèges ou d’envoyer des commandes à ...
Police launch new operation to tackle anticipated financial crime
Firm claims only a “small fraction” of users were impacted
This post is part of a series about Offensive BPF that I’m working on to learn how BPFs use will impact offensive security, malware, and detection engineering.
Click the “ebpf” tag to see all relevant posts.
One of the issues I ran into when trying out sslsniff-bpfcc was that it did not work with Fi...
Figure relates only to top 10 variants and Bitcoin payments
New research finds average global cyber-attack response time is 20.09 hours
Credits John
Github: https://github.com/johnjhacking
Molly White
Twitter: https://twitter.com/molly0xFFF
Zultan
Twitter: https://twitter.com/orpheus9001
Summary First and foremost, we may have taken the phrase “Hack the Planet” a little too serious.
Google Earth Enterprise is an application that is...
Strategies to monitor phones for illicit content branded invasive, ineffective and dangerous
American Osteopathic Association notifies nearly 27,500 individuals of summertime data swipe
Today you are in for a special treat. Did you know that an adversary can hide a smaller image within a larger one?
This video demonstrates how a small image becomes magically visible when the computer resizes the large image, and also how to mitigate the vulnerability.
This is possible when vulnerab...
Prolific Russian actors responsible for spike in alerts this year
Facilities on alert after multiple attacks over past two years
Tabnabbing is a web application security vulnerability that can be used to perform phishing attacks, so its important to be aware of it as a developer and penetration tester.
It is easy to mitigate and in this short video we cover both attacks and mitigations.
Thanks for reading and happy hacking!
@...
Reporter responsibly disclosed vulnerability in education website
Possible cybersecurity incident impacts Japanese reprography giant’s IT system in the Americas
This post is part of a series about Offensive BPF that I’m working on to learn about BPF to understand attacks and defenses. Click the “ebpf” tag to see all relevant posts.
In the previous posts I spend time learning about bpftrace which is quite powerful. This post is focused on basics and using ex...
Social media company will decide on a case-by-case basis which notable users to protect
Breach confirmed after hackers list Taiwanese computer manufacturer’s data for sale on dark web