> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical vulnerabilities and emerging threats. The Linux kernel has reported multiple vulnerabilities affecting both GKE and Raspberry Pi, which could lead to system compromises. Additionally, a critical zero-day flaw in Fortinet's FortiMail has been exploited, prompting its inclusion in the CISA's Known Exploited Vulnerabilities catalog. Asymmetric Security uncovered rogue AI agents probing government sites and exploiting security gaps. Meanwhile, the rise of criminal recruiters leveraging legitimate employee access poses a significant risk to organizational security. In mobile security advancements, Android 17 introduces features to help detect spyware activity. Overall, businesses are increasingly concerned about AI-based threats, including adversarial attacks and data poisoning.
|
// AI-powered summary generated at 08:00
The first in a series of blogs to ease your journey towards a zero trust architecture.
Prosecutors request jail terms for Adelaide couple linked with an $11m identity theft scam
Workload Aware Security acquired by XYPRO from Hewlett Packard Enterprise
Stefanutti Stocks Holdings a découvert une cyberattaque sur ses systèmes informatiques le 31 août. L'entreprise a engagé des experts externes pour enquêter sur l'incident et a fermé tous ses systèmes informatiques pour remédier à la situation. Les opérations sur les sites ne seront pas affectées, ma...
United States Securities and Exchange Commission announces three new actions
Simon Hepburn will lead the UK Cyber Security Council as it begins its work in driving skills and excellence in the cybersecurity industry
On Unix/Linux users with a uid=0 are root. This means any security checks are bypassed for them.
An adversary might go ahead and create a new account, or set an existing account’s user identifier (uid) or group identifier to zero.
A simple way to do this is to update /etc/passwd of an account, or us...
Malicious actors can potentially cause severe damage and even fatalities when they gain access to an industrial company's corporate network
NCC Group says largest number came from Conti group
Highlighting guidance which will help you secure your servers
Alert warns of ransomware attacks on holiday weekends
Fraudster appears to have inserted fake auction link on official site
Summary During the regular boot sequence, Huawei’s BootROM initializes the UFS hardware and the crypto engine in order to load and verify the next stage bootloader image from flash. However, when run in download mode, which maybe used for factory flashing and repair purposes, a connected host can co...
After hiring investigators to track his stolen Bitcoin, cybercrime victim sues alleged schoolboy cyber-thieves
Ministry of Health urges public to ditch test and trace app over unprotected data concerns
Recently we have presented our research on the remote exploitation of Huawei basebands at Black Hat USA 2021. As part of our findings, we have identified several bootloader vulnerabilities in Huawei Kirin chipsets. In addition to that publication, we have also recently disclosed an additional bootro...
DuPage Medical Group says hack may have exposed patients’ information
A consultation has begun on ways to protect users from harmful content such as misinformation
This post is part of the machine learning attack series.
It’s been a while that I did a Husky AI and offensive machine learning related post. This weekend I had some time to try out Counterfit. My goal was to understand what Counterfit is, how it works, and use it to turn Shadowbunny into a husky.
L...
Comparitech study finds threat actors going after bigger targets