> TODAY'S SUMMARY (143 articles)
Today's cybersecurity news highlights several critical threats and trends:
1. A breach of the Dutch Institute for Vulnerability Disclosure was enabled by two zero-day vulnerabilities in the Zammad ticketing system, emphasizing the risks associated with open-source software.
2. The Pentagon is under scrutiny following a data breach that exposed personal records of millions of military personnel, raising concerns over data security practices.
3. WatchGuard has patched a severe flaw in its Fireware OS, which could allow remote code execution on its appliances, while Cisco's SD-WAN Manager faces similar vulnerabilities being actively exploited.
4. Reports indicate a significant rise in vulnerability disclosures, now exceeding 10,000 monthly, driven by AI advancements that also enable more frequent exploitation of these weaknesses.
5. Attackers are increasingly leveraging AI and custom ChatGPT features to deliver malware, showcasing the evolving tactics in cybercrime.
These incidents underscore the growing sophistication of cyber threats and the urgent need for robust security measures across organizations.
|
// AI-powered summary generated at 20:00
The growing use of third parties has thrown up major data security challenges
Check Point says threat is designed to phish for log-ins and card details
Knowing only the name of a public S3 bucket, you can ascertain the account ID it resides in.
Onapsis report claims some exploited bugs date back to 2010
Researchers say Elasticsearch database may have been open for 10 days
We’re hiring for our Research + Engineering team! By Aaron Yoo, University of California, Los Angeles As an intern at Trail of Bits, I worked on Solar, a proof-of-concept static analysis framework. Solar is unique because it enables context-free interactive analysis of Solidity smart contracts. A u...
Ransomware operators demand $40m from Broward County Public Schools system
European drone group partners with YesWeHack to launch a Bug Bounty program
In the summer of 2020, we described our work fuzzing the Solidity compiler, solc. So now we’d like to revisit this project, since fuzzing campaigns tend to “saturate,” finding fewer new results over time. Did Solidity fuzzing run out of gas? Is fuzzing a high-stakes project worthwhile, especially if...
Aussies may have to prove who they are to use online dating and social media accounts
Report assesses how cyber-criminals have exploited the COVID-19 crisis
The deal will act as a platform for AddSecure to grow its business
Experts suspect branding move to kick-start affiliate program
Attackers targeting government, commercial and tech firms
Golden Chickens group goes gunning for job-seekers
Daytona Beach pastor allegedly shared child sexual abuse material in online chat rooms
Exploitation by hackers of 183 ETH from newly launched DeFi aggregator was preventable
Cyber-intelligence firm finds personal data of 533 million Facebook users posted online
Former intelligence analyst pleads guilty to disclosing classified information to journalist
Cyber-bully who asked wrestler “when will you die?” fined after victim takes her own life