> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Victims could be targeted by stalkers and fraudsters
Incidents led to murder and sexual assault threats for users
An introduction to the Instance Metadata Service and how to access it.
New Yorker accused of cyber-stalking a woman and soliciting others to rape, murder, and decapitate her
APT group Lazarus attacks two targets related to COVID-19 vaccine research
An introduction to EC2 User Data and how to access it.
Europe’s human rights court hit by cyber-criminals after calling for release of Turkish political leader
Baikalov is tasked with developing the company's identity analytics and machine learning capabilities
Brute force the IAM permissions of a user or role to see what you have access to.
Orgs increasingly looking to protect themselves from the impact of cyber-attacks
Extortion and fraud risks persist for tens of thousands of patients
🇬🇧 The following indicators of compromise are associated with the Egregor ransomware described in the CERTFR-2021-CTI-007 report. These technical elements are provided to help detecting malicious activities in logs or inside live network trafic. 🇫🇷 Les marqueurs techniques suivants sont associés...
Ben-Gurion University researchers reveal new tactics for marketers and cyber-criminals
DHS advisory warns businesses of state-mandated IP theft risks
On December 3rd, Aave deployed version 2 of their codebase. While we were not hired to look at the code, we briefly reviewed it the following day. We quickly discovered a vulnerability that affected versions 1 and 2 of the live contracts and reported the issue. Within an hour of sending our analysis...
Attacker impersonates New York State to steal sensitive data from seekers of COVID-19 financial relief
Silk Road lies send computer programmer “Shabang” to prison
Zero-knowledge proofs, once a theoretical curiosity, have recently seen widespread deployment in blockchain systems such as Zcash and Monero. However, most blockchain applications of ZK proofs make proof size and performance tradeoffs that are a poor fit for other use-cases. In particular, these pro...
German police lead operation to shut down Safe-Inet service and seize its infrastructure
The breaches affected 121,355 people