> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Online retail DDoS attacks increase during health crisis
Acronis will engage in the Cyber-Risk and Corporate Governance project
In this post we will explore Generative Adversarial Networks (GANs) to create fake husky images. The goal is, of course, to have “Husky AI” misclassify them as real huskies.
If you want to learn more about Husky AI visit the Overview post.
Generative Adversarial Networks One of the attacks I wanted...
Triple-digit increase in attacks since September
Suspected Chinese state actors already exploiting CVE in the wild
TL;DR: We’re open-sourcing a new framework, blight, for painlessly wrapping and instrumenting C and C++ build tools. We’re already using it on our research projects, and have included a set of useful actions. You can use it today for your own measurement and instrumentation needs: Why would you ever...
Ransomware has major financial impact on IT services giant
Phishing tops list of most frequently reported cybercrimes in US, while in the UK, it’s social media/email hacks
There are plenty of examples of artificial intelligence and machine learning systems that made it into the news because of biased predictions and failures.
Here are a few examples on AI/ML gone wrong:
Amazon had an AI recruiting tool which favored men over women for technical jobs The Microsoft chat...
Alleged members of Nigerian BEC ring arrested after being identified by cybersecurity company and INTERPOL
Canadian doctor cyber-bullied over COVID-19 approach calls for kindness
After writing Go for years, many of us have learned the error-checking pattern down to our bones: “Does this function return an error? Ope, better make sure it’s nil before moving on.” And that’s great! This should be our default behavior when writing Go. However, rote error checking can sometimes p...
There is growing responsibility on remote staff to keep orgs secure
The practical application of zero-trust varies between organizations
You might have heard about “NAT Slipstreaming” by Samy Kamkar. It’s an amazing technique that allows punching a hole in your routers firewall by just visiting a website.
The attack depends on the router having the Application Layer Gateway enabled. This gateway can be used by anyone inside your netw...
Home Depot reaches $17.5m settlement over 2014 data breach
Porter will be responsible for all aspects of risk and compliance across the enterprise
Credits Sick.Codes
Github: (https://github.com/sickcodes)
Twitter: (https://twitter.com/sickcodes)
John
Github: (https://github.com/johnjhacking) Nick Sahler
Github: (https://github.com/nicksahler)
Twitter: (https://twitter.com/tensor_bodega)
With Collaboration from:
Harold Hunt
LinkedIn: (https://w...
Events firm not clear how strong password encryption was
52% of respondents cite reputational damage as the biggest challenge regarding secure outbound communications