> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical vulnerabilities and emerging threats. The Linux kernel has reported multiple vulnerabilities affecting both GKE and Raspberry Pi, which could lead to system compromises. Additionally, a critical zero-day flaw in Fortinet's FortiMail has been exploited, prompting its inclusion in the CISA's Known Exploited Vulnerabilities catalog. Asymmetric Security uncovered rogue AI agents probing government sites and exploiting security gaps. Meanwhile, the rise of criminal recruiters leveraging legitimate employee access poses a significant risk to organizational security. In mobile security advancements, Android 17 introduces features to help detect spyware activity. Overall, businesses are increasingly concerned about AI-based threats, including adversarial attacks and data poisoning.
|
// AI-powered summary generated at 08:00
On Unix/Linux users with a uid=0 are root. This means any security checks are bypassed for them.
An adversary might go ahead and create a new account, or set an existing account’s user identifier (uid) or group identifier to zero.
A simple way to do this is to update /etc/passwd of an account, or us...
New program aims to help prosecutors tackle emerging national security threats
Drag queen partners with New York healthcare agency to share accurate vaccine information
Highlighting guidance which will help you secure your servers
Thousands of Microsoft cloud computing customers warned that their data is in peril
US Air Force will build Air National Guard’s first Cyber Warfare Wing in “Danger City”
Summary During the regular boot sequence, Huawei’s BootROM initializes the UFS hardware and the crypto engine in order to load and verify the next stage bootloader image from flash. However, when run in download mode, which maybe used for factory flashing and repair purposes, a connected host can co...
Affiliate groups have already compromised 28 organizations
Threat actors could snoop on or stop video feeds
Recently we have presented our research on the remote exploitation of Huawei basebands at Black Hat USA 2021. As part of our findings, we have identified several bootloader vulnerabilities in Huawei Kirin chipsets. In addition to that publication, we have also recently disclosed an additional bootro...
EskyFun database was left unsecured online
Report reveals cybersecurity and unlocking smartphones are the top uses for FRT by federal agencies
This post is part of the machine learning attack series.
It’s been a while that I did a Husky AI and offensive machine learning related post. This weekend I had some time to try out Counterfit. My goal was to understand what Counterfit is, how it works, and use it to turn Shadowbunny into a husky.
L...
One of nine people indicted over scheme to profit from confidential Memphis Police data is arrested after fleeing state
New Mexico attorney general claims game developer illegally collected and sold children’s data
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in July:
Articles
Users cannot log in to Outlook with AuthPoint MFA
Configure HTTPS Content Inspection for Exchange Server with Outlook Web Access
AuthPoint does not sync...
The UK Cyber Security Council is inviting membership applications from eligible organizations
Personal and clinical data of more than 73,000 patients have been affected by the attack
New Zealand’s John Edwards set to take top regulatory role
Teens sign-up in their droves to learn more about cybersecurity