[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 08:00

> Innovative Recruitment Practices Can Close the Cyber Skills Gap
A panel of experts discuss why hiring practices for cyber roles need to change
> Drug Dealers Get 27 Years After Police Crack EncroChat Comms
Encrypted chat service was infiltrated by police last year
> Serving up some server advice
Highlighting guidance which will help you secure your servers
> Cybercrime Losses Triple to ÂŁ1.3bn in 1H 2021
Action Fraud figures show cases increased more than six-fold from 1H 2020
> Tech CEOs to Discuss Cybersecurity with Biden Today
Report suggests supply chains and critical infrastructure could be on the agenda
> CVE-2021-22434: Huawei Arbitrary Write in BootROM USB Stack
Summary During the regular boot sequence, Huawei’s BootROM initializes the UFS hardware and the crypto engine in order to load and verify the next stage bootloader image from flash. However, when run in download mode, which maybe used for factory flashing and repair purposes, a connected host can co...
> Cyber-thieves Scam New Hampshire Town Out of $2.3m
Scammers posed as local school district and contractor to steal 14% of town’s annual budget
> FBI Issues Ransomware Group Flash Alert
New ransomware group OnePercent has been attacking US companies since November
> Test Point Break: Analysis of Huawei’s OTA Fix For BootROM Vulnerabilities
Recently we have presented our research on the remote exploitation of Huawei basebands at Black Hat USA 2021. As part of our findings, we have identified several bootloader vulnerabilities in Huawei Kirin chipsets. In addition to that publication, we have also recently disclosed an additional bootro...
> US Signs Cybersecurity Agreements with Singapore
Singapore and US will collaborate on cybersecurity and climate change
> Time to Fix High Severity Apps Increases by Ten Days
NTT Application Security warns of “systemic failure” to address bugs
> Using Microsoft Counterfit to create adversarial examples for Husky AI
This post is part of the machine learning attack series. It’s been a while that I did a Husky AI and offensive machine learning related post. This weekend I had some time to try out Counterfit. My goal was to understand what Counterfit is, how it works, and use it to turn Shadowbunny into a husky. L...
> Over a Third of Smart Device Owners Do Not Take Security Measures
The study demonstrates a worrying lack of security hygiene among British smart device owners
> Microsoft Power Apps Tool Exposed 38 Million Records by Default
Configuration muddle has now been largely resolved by Redmond
> Knowledge Base Digest - July 2021
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in July: Articles Users cannot log in to Outlook with AuthPoint MFA Configure HTTPS Content Inspection for Exchange Server with Outlook Web Access AuthPoint does not sync...
> Mass Exploitation of Exchange Server ProxShell Bugs
Experts urge sysadmins to patch immediately
> AT&T Denies Data Breach
Threat actor says AT&T will admit breach when personal data of 70 million customers is leaked
> Using procdump on Linux to dump credentials
I like using procdump on Windows. It’s quite handy for software development when systems have memory leaks or performance issues, procdump allows to set thresholds to trigger creation of a core dump. BUT, it’s also super useful to search processes for secrets and other information. For instance, thi...
> Poly Network Hacker Returns Remaining Funds
Hacker hands back all the tokens stolen in biggest ever crypto-currency heist
> Hackers Leak Footage of Iranian Prison
Bleak lives of Evin’s prisoners shown to press by hacking group