> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical vulnerabilities and emerging threats. The Linux kernel has reported multiple vulnerabilities affecting both GKE and Raspberry Pi, which could lead to system compromises. Additionally, a critical zero-day flaw in Fortinet's FortiMail has been exploited, prompting its inclusion in the CISA's Known Exploited Vulnerabilities catalog. Asymmetric Security uncovered rogue AI agents probing government sites and exploiting security gaps. Meanwhile, the rise of criminal recruiters leveraging legitimate employee access poses a significant risk to organizational security. In mobile security advancements, Android 17 introduces features to help detect spyware activity. Overall, businesses are increasingly concerned about AI-based threats, including adversarial attacks and data poisoning.
|
// AI-powered summary generated at 08:00
A panel of experts discuss why hiring practices for cyber roles need to change
Encrypted chat service was infiltrated by police last year
Highlighting guidance which will help you secure your servers
Action Fraud figures show cases increased more than six-fold from 1H 2020
Report suggests supply chains and critical infrastructure could be on the agenda
Summary During the regular boot sequence, Huawei’s BootROM initializes the UFS hardware and the crypto engine in order to load and verify the next stage bootloader image from flash. However, when run in download mode, which maybe used for factory flashing and repair purposes, a connected host can co...
Scammers posed as local school district and contractor to steal 14% of town’s annual budget
New ransomware group OnePercent has been attacking US companies since November
Recently we have presented our research on the remote exploitation of Huawei basebands at Black Hat USA 2021. As part of our findings, we have identified several bootloader vulnerabilities in Huawei Kirin chipsets. In addition to that publication, we have also recently disclosed an additional bootro...
Singapore and US will collaborate on cybersecurity and climate change
NTT Application Security warns of “systemic failure” to address bugs
This post is part of the machine learning attack series.
It’s been a while that I did a Husky AI and offensive machine learning related post. This weekend I had some time to try out Counterfit. My goal was to understand what Counterfit is, how it works, and use it to turn Shadowbunny into a husky.
L...
The study demonstrates a worrying lack of security hygiene among British smart device owners
Configuration muddle has now been largely resolved by Redmond
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in July:
Articles
Users cannot log in to Outlook with AuthPoint MFA
Configure HTTPS Content Inspection for Exchange Server with Outlook Web Access
AuthPoint does not sync...
Experts urge sysadmins to patch immediately
Threat actor says AT&T will admit breach when personal data of 70 million customers is leaked
I like using procdump on Windows.
It’s quite handy for software development when systems have memory leaks or performance issues, procdump allows to set thresholds to trigger creation of a core dump.
BUT, it’s also super useful to search processes for secrets and other information.
For instance, thi...
Hacker hands back all the tokens stolen in biggest ever crypto-currency heist
Bleak lives of Evin’s prisoners shown to press by hacking group