> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Crime pays for infamous extortionists, researchers claim
JetBrains boss Shafirov says no evidence of compromise in TeamCity tool
An introduction to the Instance Metadata Service and how to access it.
Cyber-attackers lure victims with promise of sex video starring President Trump
United States Army promotes first Army Reserve cyber officer to brigadier general
An introduction to EC2 User Data and how to access it.
Cyber-criminals jailed for $5m skimming attack on Virginia gas pumps
Data stolen from Hackney Council is allegedly available on the dark web
Brute force the IAM permissions of a user or role to see what you have access to.
Gill succeeds Panaseer founder Nik Whitfield in the role, with the latter becoming chairman
Deepfake video and audio technologies have accelerated during the COVID-19 pandemic
🇬🇧 The following indicators of compromise are associated with the Egregor ransomware described in the CERTFR-2021-CTI-007 report. These technical elements are provided to help detecting malicious activities in logs or inside live network trafic. 🇫🇷 Les marqueurs techniques suivants sont associés...
Robots are a key component of Industry 4.0 and represent yet another endpoint in OT settings
Department first to reveal scope of the Russian campaign
On December 3rd, Aave deployed version 2 of their codebase. While we were not hired to look at the code, we briefly reviewed it the following day. We quickly discovered a vulnerability that affected versions 1 and 2 of the live contracts and reported the issue. Within an hour of sending our analysis...
Twitter soapbox may be pulled away for good after incitement to violence
Hiscox data reveals phishing accounted for majority of incidents
Defense Digital Service is working with HackerOne to launch the new program
ISQ estimates cost of poor software quality (CPSQ) in the US as $2.08tn in 2020
British Airways to start £3bn settlement discussions over data breaches affecting 500,000 customers