> TODAY'S SUMMARY (143 articles)
Today's cybersecurity news highlights several critical threats and trends:
1. A breach of the Dutch Institute for Vulnerability Disclosure was enabled by two zero-day vulnerabilities in the Zammad ticketing system, emphasizing the risks associated with open-source software.
2. The Pentagon is under scrutiny following a data breach that exposed personal records of millions of military personnel, raising concerns over data security practices.
3. WatchGuard has patched a severe flaw in its Fireware OS, which could allow remote code execution on its appliances, while Cisco's SD-WAN Manager faces similar vulnerabilities being actively exploited.
4. Reports indicate a significant rise in vulnerability disclosures, now exceeding 10,000 monthly, driven by AI advancements that also enable more frequent exploitation of these weaknesses.
5. Attackers are increasingly leveraging AI and custom ChatGPT features to deliver malware, showcasing the evolving tactics in cybercrime.
These incidents underscore the growing sophistication of cyber threats and the urgent need for robust security measures across organizations.
|
// AI-powered summary generated at 20:00
Full event now available to watch anytime, anywhere!
IT skills shortage could also weaken Britain’s defense against attacks on critical national infrastructures
In the summer of 2020, we described our work fuzzing the Solidity compiler, solc. So now we’d like to revisit this project, since fuzzing campaigns tend to “saturate,” finding fewer new results over time. Did Solidity fuzzing run out of gas? Is fuzzing a high-stakes project worthwhile, especially if...
GRU-linked Ghostwriter group pegged for involvement
No ransom demand could indicate state involvement
You probably heard of NFTs (non-fungible tokens). They are receiving a lot of interest over the last several months. I did some digging and realized that there are some bigger issues with the standards and various interpretations and implementations of it, and how centralized many offerings are.
Wha...
SalusCare turns to the law after Amazon denies request to view storage buckets allegedly housing healthcare provider’s stolen data
Kansas, Missouri, Montana, and Washington to work with National Governors Association
Today, we are releasing an experimental coverage-guided fuzzer called Honeybee that records program control flow using Intel Processor Trace (IPT) technology. Previously, IPT has been scrutinized for severe underperformance due to issues with capture systems and inefficient trace analyses. My winter...
Feds flag danger of ransomware that weaponizes DiskCryptor
Lindy Cameron to make first speech as NCSC boss today
Many machine learning (ML) models are Python pickle files under the hood, and it makes sense. The use of pickling conserves memory, enables start-and-stop model training, and makes trained models portable (and, thereby, shareable). Pickling is easy to implement, is built into Python without requirin...
Remote workers are making mistakes and using shadow IT
Wordfence reveals new vulnerabilities in popular plugin
Le CLUSIF (CLUb de la Sécurité de l’Information Français) publie un document qui s’adresse à l’ensemble des acteurs ayant à sécuriser un système industriel existant ou à venir.
(mise à jour Septembre 2021 : le guide est à présent [...] Lire la suite
Senior Redscan execs to stay on as part of the deal
Sir Maejor Page denies posing as Black Lives Matter leader on Facebook to pocket donations
Survey of SaaS users finds 40% have lost data stored in online tools
Collaboration is designed to encourage more young people to pursue careers in cybersecurity
Insurance giant’s website reduced to attack notice following Sunday cyber-strike