> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Rights groups concerned over European Commissionâs green light
Customers have been contacted following the incident
đŹđ§ The following indicators of compromise are associated with the Egregor ransomware described in the CERTFR-2021-CTI-007 report. These technical elements are provided to help detecting malicious activities in logs or inside live network trafic. đ«đ· Les marqueurs techniques suivants sont associĂ©s...
Authentication bypass flaw found in popular Java crypto library
Tech firms, not governments, form the largest group of victims
On December 3rd, Aave deployed version 2 of their codebase. While we were not hired to look at the code, we briefly reviewed it the following day. We quickly discovered a vulnerability that affected versions 1 and 2 of the live contracts and reported the issue. Within an hour of sending our analysis...
New AI algorithm predicts which Twitter users will share unreliably sourced news
Prison for tech company employee who stole PII and used it for financial gain
Zero-knowledge proofs, once a theoretical curiosity, have recently seen widespread deployment in blockchain systems such as Zcash and Monero. However, most blockchain applications of ZK proofs make proof size and performance tradeoffs that are a poor fit for other use-cases. In particular, these pro...
Delhi police cybercrime unit arrests 54 over illegal call center targeting foreign nationals
64% of business leaders are anticipating a rise in phishing attacks in 2021
Today FireEye shared that they were victim of a cyberattack and internal red teaming tooling was accessed by adversaries. More details in this NYT article.
This reminded me that I wanted to do a post on actively protecting pen testers and pen testing assets for a while.
Against persistent adversarie...
The payment of ransoms and extortions doubled between 2019 and 2020
Messages from âfriendsâ are fake, says Identity Theft Resource Center
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in November:
Articles
Firebox Cloud supports accelerated networking in Azure
Known Issues
IKEv2 profile import fails on macOS Big Sur 11.0.1
DHCPv6 server restarts repe...
Avast urges users to uninstall now or risk phishing and data theft
Barracuda Networks reveals latest spear-phishing trends
5G security research discloses exploit opportunities
Goontact targets iOS and Android users in Asia who visit sites selling escort services
Refinitiv boosts cybercrime-fighting abilities with acquisition of Giact Systems