> TODAY'S SUMMARY (111 articles)
Today’s cybersecurity landscape highlights several significant threats and trends:
1. A massive data breach in Arizona courts has exposed sensitive foster care records, affecting over 150,000 individuals and raising serious privacy concerns.
2. Cisco has issued urgent alerts regarding a zero-day vulnerability in its SD-WAN Manager, actively exploited by attackers to gain administrative access.
3. Google reports that AI-driven vulnerability discoveries are increasingly linked to remote code execution risks, indicating a shift in threat dynamics.
4. The Citrix NetScaler vulnerabilities are under active exploitation, with reports of sophisticated phishing campaigns targeting government and finance sectors.
5. Multiple high-severity vulnerabilities in common software, including OpenSSL and TeamViewer, necessitate immediate patching to safeguard systems.
6. Ukrainian researchers have raised alarms about mobile malware targeting iOS and Android devices, linked to ongoing state-sponsored attacks.
These developments underscore the urgency for organizations to enhance their cybersecurity measures and stay informed of emerging threats.
|
// AI-powered summary generated at 16:00
Misconfigured Elasticsearch server exposes payment and identity data
IoT giant was hit by unspecified variant on March 20
In the summer of 2020, we described our work fuzzing the Solidity compiler, solc. So now we’d like to revisit this project, since fuzzing campaigns tend to “saturate,” finding fewer new results over time. Did Solidity fuzzing run out of gas? Is fuzzing a high-stakes project worthwhile, especially if...
How does the culture of an organization impact DevSecOps?
Prison for IT pro who hacked company server and deleted over 1,200 Microsoft user accounts
You probably heard of NFTs (non-fungible tokens). They are receiving a lot of interest over the last several months. I did some digging and realized that there are some bigger issues with the standards and various interpretations and implementations of it, and how centralized many offerings are.
Wha...
Medical center and law firm facing class action after 36,000-record breach
Formula 1 appoints Herjavec Group as official cybersecurity services provider
Today, we are releasing an experimental coverage-guided fuzzer called Honeybee that records program control flow using Intel Processor Trace (IPT) technology. Previously, IPT has been scrutinized for severe underperformance due to issues with capture systems and inefficient trace analyses. My winter...
Developing AI tools that can investigate threats could prove vital
The CCAK program comes amid rising cloud adoption
Many machine learning (ML) models are Python pickle files under the hood, and it makes sense. The use of pickling conserves memory, enables start-and-stop model training, and makes trained models portable (and, thereby, shareable). Pickling is easy to implement, is built into Python without requirin...
Popular scanlation site being rebuilt following breach
Check Point sees uptick in illicit activity as demand grows
Le CLUSIF (CLUb de la Sécurité de l’Information Français) publie un document qui s’adresse à l’ensemble des acteurs ayant à sécuriser un système industriel existant ou à venir.
(mise à jour Septembre 2021 : le guide est à présent [...] Lire la suite
Javvad Malik opens the Infosecurity Magazine Online Summit
Oil giant admits personal and corporate data was stolen
How malware works on Operational Technology (OT) and how to stop it.
Investment represents largest digital identity funding round ever
34 arrested for allegedly duping Americans, Canadians, and Brits with tech support scam