> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Government blames Russia for the first time
Former civil servant jailed for hacking and cyber-exploitation of hundreds of women and girls
An introduction to the Instance Metadata Service and how to access it.
Cloud security provider iboss raises millions in funding to support “rapid growth”
Swatting attacks targeting smart-home device users trigger public warning from FBI
An introduction to EC2 User Data and how to access it.
Dr Chase Cunningham is tasked with shaping Ericom’s strategic vision
Check Point claims the sector is twice as badly hit as others
Brute force the IAM permissions of a user or role to see what you have access to.
APT27 pegged for financially motivated raids
Deal will add to HelpSystems’ file transfer and process automation offerings
🇬🇧 The following indicators of compromise are associated with the Egregor ransomware described in the CERTFR-2021-CTI-007 report. These technical elements are provided to help detecting malicious activities in logs or inside live network trafic. 🇫🇷 Les marqueurs techniques suivants sont associés...
Executive order had sought to remove them on security grounds
Apex Laboratory discloses summertime cyber-attack
On December 3rd, Aave deployed version 2 of their codebase. While we were not hired to look at the code, we briefly reviewed it the following day. We quickly discovered a vulnerability that affected versions 1 and 2 of the live contracts and reported the issue. Within an hour of sending our analysis...
Cybersecurity companies merge “to address growing need for comprehensive data security”
British court rules WikiLeaks founder should not be extradited to the United States
Zero-knowledge proofs, once a theoretical curiosity, have recently seen widespread deployment in blockchain systems such as Zcash and Monero. However, most blockchain applications of ZK proofs make proof size and performance tradeoffs that are a poor fit for other use-cases. In particular, these pro...
Redmond says incident did not elevate cyber-risk
Kela researchers also discover 500,000 breached employee credentials