[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 04:00

> Video: Building and breaking a machine learning system
My GrayHat Red Team Village talk “Learning by doing: Building and breaking a machine learning system” is now live on YouTube. Check it out: https://www.youtube.com/watch?v=-SV80sIBhqY and smash the Like button! :D Question? I thought of turning the content into a hands-on workshop. Let me know if th...
> US Seizes More IRGC Domains
A further 27 domain names used by Iran’s Islamic Revolutionary Guard have been seized by the US
> KnowBe4 Launches Free Compliance Tool
US cybersecurity company debuts no-cost Compliance Audit Readiness Assessment tool
> Good idea, bad design: How the Diamond standard falls short
TL;DR: We audited an implementation of the Diamond standard proposal for contract upgradeability and can’t recommend it in its current form—but see our recommendations and upgrade strategy guidance. We recently audited an implementation of the Diamond standard code, a new upgradeability pattern. It’...
> National Guard to Help Vermont Health Network After Cyber-Attack
Vermont governor calls in National Guard to help UVM Health Network recover from cyber-attack
> NCSC Partners with Microsoft to Support Cyber Accelerator Program
NCSC and Microsoft partner to support Cyber Accelerator Program
> Machine Learning Attack Series: Image Scaling Attacks
This post is part of a series about machine learning and artificial intelligence. Click on the blog tag “huskyai” to see related posts. Overview: How Husky AI was built, threat modeled and operationalized Attacks: Some of the attacks I want to investigate, learn about, and try out A few weeks ago wh...
> Researchers Uncover New Malspam Campaign Exploiting #Election2020 Controversy
The campaign plays on claims about the integrity of the ongoing Presidential election
> Over Half of Organizations Still Operating Without a BYOD Policy
There remains a lack of urgency to adapt security in light of COVID-19
> Leveraging the Blue Team's Endpoint Agent as C2
A few years back the Blue Team of a company asked to be targeted in a Red Team Operation. That was a really fun, because Rules of Engagement commonly prevent targeting Blue Teams. Blue’s infrastructure, systems and team members are often out of scope, unfortunately. Blue team infrastructure is a gol...
> California Votes to Strengthen Privacy Laws
ACLU disagrees, but Prop 24 aimed at enhancing data protection
> Over 70,000 Personal Files Found on 100 Second-Hand USBs
Bank statements and passwords among the eBay haul
> Account Takeover on the Jack Daniel's Tennessee Squire Association Platform
Summary Many people do not know about the Jack Daniel’s Tennessee Squires. The Squire Association is an Elite Club for “friends of Jack Daniel’s”. Anyone that has ever dreamed of being a Tennessee Squire knows how difficult - if not impossible it is to obtain membership without paying thousands of d...
> Gaming Giant Capcom Suffers Security Breach
Network operations halted after unidentified attack
> Two-Thirds of Financial Services Firms Suffered Cyber-Attack in the Past Year
There has been a huge rise in cyber-attacks targeting financial services companies since COVID-19
> CVE-2020-27388: YOURLS 1.5 - 1.7.10, Multiple Stored Cross Site Scripting (XSS) Vulnerabilities in Admin Panel
Potential Abuse on a hooked Function There is a potential for abuse with any plugins that implement the hook function ‘shunt_is_valid_user’. In the code below we simply demonstrate that authentication can be completely bypassed by returning TRUE in the hooked function. This would be an ideal place f...
> $1bn in Bitcoin Moved from Silk Road Wallet
Anonymous user carries out first Silk Road wallet cryptocurrency transaction in five years
> Americans Confident in IoT Device Security
Americans believe their connected devices are secure despite overlooking basic security hygiene
> Efficient audits with machine learning and Slither-simil
Trail of Bits has manually curated a wealth of data—years of security assessment reports—and now we’re exploring how to use this data to make the smart contract auditing process more efficient with Slither-simil. Based on accumulated knowledge embedded in previous audits, we set out to detect simila...
> Kaspersky Researchers Announce AMA Session
Kaspersky’s Global Research and Analysis Team to hold Ask Me Anything session on Reddit