> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Bill mainly aimed at China heads to Trump’s desk
Philabundance caught out by classic email supplier spoof
On 1 December 2020, the TDR EU AWS environment suffered from an intermittent outage which resulted in some Host Sensors being unable to contact ThreatSync. This seems to be linked to the deployment of new TDR infrastructure on the night of 30 November 2020. Despite Engineering's extensive efforts, t...
There is growing realization that hacking provides an important service
Sectigo looks to expand its market in Europe and Latin America
[Mise à jour du 26 février 2021] 🇬🇧 The following indicators are new network indicators associated with the Ryuk ransomware described in the CERTFR-2021-CTI-006 report. These technical elements are provided to help detecting malicious activities in logs or inside live network trafic. Every...
Tech CEO relocates $9bn cybersecurity company from California to Washington state
Trump’s former head of election cybersecurity may sue lawyer who said he should be “drawn and quartered”
What a journey it has been. I wrote quite a bit about machine learning from a red teaming/security testing perspective this year. It was brought to my attention to provide a conveninent “index page” with all Husky AI and related blog posts. Here it is.
Machine Learning Basics and Building Husky AI G...
More investment needed to secure API traffic
CISA and FBI warn that advanced persistent threat actors are targeting US think tanks
In this post we will explore Generative Adversarial Networks (GANs) to create fake husky images. The goal is, of course, to have “Husky AI” misclassify them as real huskies.
If you want to learn more about Husky AI visit the Overview post.
Generative Adversarial Networks One of the attacks I wanted...
As cloud services and SaaS were heavily adopted in 2020, how well did security keep up?
Ex-Forescout veteran will help guide continued adoption of the company’s security solutions
TL;DR: We’re open-sourcing a new framework, blight, for painlessly wrapping and instrumenting C and C++ build tools. We’re already using it on our research projects, and have included a set of useful actions. You can use it today for your own measurement and instrumentation needs: Why would you ever...
ITRC claims 2020 could see a major drop-off in breach volumes
New study of four million container images reveals major risks
There are plenty of examples of artificial intelligence and machine learning systems that made it into the news because of biased predictions and failures.
Here are a few examples on AI/ML gone wrong:
Amazon had an AI recruiting tool which favored men over women for technical jobs The Microsoft chat...
Proposed acquisition will see Slack act as the new interface for Salesforce Customer 360
Feds warn of visibility challenge for IT administrators