> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Law firm accuses taxman of incompetence over data loss incidents
Data from European outposts could be at risk
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in November:
Articles
Firebox Cloud supports accelerated networking in Azure
Known Issues
IKEv2 profile import fails on macOS Big Sur 11.0.1
DHCPv6 server restarts repe...
Feds urge job seekers to be wary of work from home scams
As Pfizer vaccine roll-out begins in UK, law enforcers urge patience
On 1 December 2020, the TDR EU AWS environment suffered from an intermittent outage which resulted in some Host Sensors being unable to contact ThreatSync. This seems to be linked to the deployment of new TDR infrastructure on the night of 30 November 2020. Despite Engineering's extensive efforts, t...
Companies partner up to launch research institute with mission to improve AI privacy
Cybersecurity company urges growing number of smart sex toy users to take precautions
[Mise à jour du 26 février 2021] 🇬🇧 The following indicators are new network indicators associated with the Ryuk ransomware described in the CERTFR-2021-CTI-006 report. These technical elements are provided to help detecting malicious activities in logs or inside live network trafic. Every...
CEO of US tech startup Trustify pleads guilty to multi-million-dollar investment scam
Ransomware will be sold as service by professional outfits collaborating to deliver better variants of attack
What a journey it has been. I wrote quite a bit about machine learning from a red teaming/security testing perspective this year. It was brought to my attention to provide a conveninent “index page” with all Husky AI and related blog posts. Here it is.
Machine Learning Basics and Building Husky AI G...
Facebook’s Nick Clegg says social media companies need to follow standards
Cyber Aware campaign urges consumers to stay safe online
In this post we will explore Generative Adversarial Networks (GANs) to create fake husky images. The goal is, of course, to have “Husky AI” misclassify them as real huskies.
If you want to learn more about Husky AI visit the Overview post.
Generative Adversarial Networks One of the attacks I wanted...
Group says agencies are trying to bypass Fourth Amendment protections
Brazilian aircraft-maker loses some unspecified data in raid
TL;DR: We’re open-sourcing a new framework, blight, for painlessly wrapping and instrumenting C and C++ build tools. We’re already using it on our research projects, and have included a set of useful actions. You can use it today for your own measurement and instrumentation needs: Why would you ever...
Shadow Academy phishing campaign has targeted 20 universities worldwide, including Oxford University
South African bank says credit analyst sold personal information of clients to third parties