> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical vulnerabilities and emerging threats. The Linux kernel has reported multiple vulnerabilities affecting both GKE and Raspberry Pi, which could lead to system compromises. Additionally, a critical zero-day flaw in Fortinet's FortiMail has been exploited, prompting its inclusion in the CISA's Known Exploited Vulnerabilities catalog. Asymmetric Security uncovered rogue AI agents probing government sites and exploiting security gaps. Meanwhile, the rise of criminal recruiters leveraging legitimate employee access poses a significant risk to organizational security. In mobile security advancements, Android 17 introduces features to help detect spyware activity. Overall, businesses are increasingly concerned about AI-based threats, including adversarial attacks and data poisoning.
|
// AI-powered summary generated at 08:00
Critical infrastructure companies may be required to report cyber-attacks to federal government
The video-sharing site outlined its updated medical misinformation policy in a blog post published earlier today
Deux salons majeurs viennent d’avoir lieu en France : le Forum International de la Cybersécurité (Lille) et le salon Global Industrie (Lyon).
Â
Le sujet de la cybersécurité industrielle est à l’intersection des [...] Lire la suite
Seattle’s Samaritan Center and Philadelphia’s Horizon House warn PHI may have been exposed
85% are more concerned about a ransomware attack than other cyber-threats, according to Fortinet survey
Credits John
Github: https://github.com/johnjhacking
Robert Willis:
Twitter: https://twitter.com/rej_ex
Identification The Wedding websites that can be created with The Knot have many components built in. Among some of the functions included the ability to send out RSVP invites to friends or family....
The UK's ICO received an average of 13,925 reports of nuisance calls, texts and emails per month in the first half 2021
Best practice advice will help to reduce corporate attack surface
Credits John Github: https://github.com/johnjhacking
SickCodes
Twitter: https://twitter.com/sickcodes
Identification During research, I stumbled upon a TestRail application. While using Burp Suite to look at various requests and responses of the application, I noticed a files.md5 path:
It seemed fai...
Researchers claim misconfigurations are also rife in cloud infrastructure
Malware steals info from Active Directory Federation Services servers
Summary In this advisory we are disclosing a vmap/vmalloc use-after-free vulnerability within the Android ION allocator, that impacts most Android devices that utilize ION. The exploitability of the vulnerability depends on how the various kernel drivers use the allocated ION buffers, the version of...
Giant Group initiates total system shutdown after “sophisticated” attack
Operator of illegal online marketplaces who sold stolen card credentials is returned to native country
How to establish persistence on a Lambda function after getting remote code execution.
One alleged victim was so traumatized by the abuse that he was committed to a psychiatric ward
UK citizens can now call 159 to quickly connect to their bank's fraud prevention service
WatchGuard is working on some important maintenance to our services.
On 17 September 2021, starting at 11:30pm UTC WatchGuard will be performing maintenance that may cause service interruptions, as well as some small changes to the product. The duration of this maintenance is expected to last from...
A quarter of legal, financial and property companies fell victim in 2020
Small carriers can access $1.9bn pot to rip-and-replace telecoms kit