[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 04:00

> Prison for Russian Player in $100m Botnet Conspiracy
US imprisons Russian cyber-criminal for role in Botnet that stole and trafficked data
> IT Pro Salaries Decline in Value
Survey reveals decline in value of over 40% of salaried IT professional job titles in the last 12 months
> Good idea, bad design: How the Diamond standard falls short
TL;DR: We audited an implementation of the Diamond standard proposal for contract upgradeability and can’t recommend it in its current form—but see our recommendations and upgrade strategy guidance. We recently audited an implementation of the Diamond standard code, a new upgradeability pattern. It’...
> Florida Invests in Security Controls Ahead of #Election2020
Florida invests in cyber-controls after 2016 hacking efforts
> Remote Working Exposing Businesses to Unforeseen Threats
Corporate infrastructures are being exposed to threats that would not have been considered a year ago
> Machine Learning Attack Series: Image Scaling Attacks
This post is part of a series about machine learning and artificial intelligence. Click on the blog tag “huskyai” to see related posts. Overview: How Husky AI was built, threat modeled and operationalized Attacks: Some of the attacks I want to investigate, learn about, and try out A few weeks ago wh...
> Adobe Chooses Blizzard Entertainment’s Adams as New CSO
Incoming security chief will not have to worry about Flash
> Ransomware Alert as Emotet Detections Surge 1200%
HP Inc data warns of close link to human-operated ransomware threats
> Leveraging the Blue Team's Endpoint Agent as C2
A few years back the Blue Team of a company asked to be targeted in a Red Team Operation. That was a really fun, because Rules of Engagement commonly prevent targeting Blue Teams. Blue’s infrastructure, systems and team members are often out of scope, unfortunately. Blue team infrastructure is a gol...
> NCSC Report Highlights #COVID19 Threat Surge
More than a quarter of incidents the NCSC tackled were pandemic-related
> (CS)2AI and KPMG Release Inaugural Control Systems Cybersecurity Report
First annual control systems and operational technology cybersecurity report released by (CS)2AI and KPMG
> Account Takeover on the Jack Daniel's Tennessee Squire Association Platform
Summary Many people do not know about the Jack Daniel’s Tennessee Squires. The Squire Association is an Elite Club for “friends of Jack Daniel’s”. Anyone that has ever dreamed of being a Tennessee Squire knows how difficult - if not impossible it is to obtain membership without paying thousands of d...
> US City Fined Over Former Employee's Data Theft
$200k fine for Connecticut city that failed to terminate former employee’s access rights
> Cyber-Criminals Target Naked Zoom Users
Fresh sextortion campaign tells Zoom users they could be the next Toobin
> CVE-2020-27388: YOURLS 1.5 - 1.7.10, Multiple Stored Cross Site Scripting (XSS) Vulnerabilities in Admin Panel
Potential Abuse on a hooked Function There is a potential for abuse with any plugins that implement the hook function ‘shunt_is_valid_user’. In the code below we simply demonstrate that authentication can be completely bypassed by returning TRUE in the hooked function. This would be an ideal place f...
> Ping Identity Acquires Symphonic to Boost API and Data Security Offering
Deal will allow users to centralize administration and enforcement to critical resources and data
> Truata and Mastercard Launch Privacy-Enhanced Portal for Financial Institutions
Solution enables customer behavior to be tracked in a way that is compliant with data protection laws
> Efficient audits with machine learning and Slither-simil
Trail of Bits has manually curated a wealth of data—years of security assessment reports—and now we’re exploring how to use this data to make the smart contract auditing process more efficient with Slither-simil. Based on accumulated knowledge embedded in previous audits, we set out to detect simila...
> The BBC Experiences Over 250,000 Malicious Email Attacks Per Day
The UK's public service broadcaster has been bombarded with malicious emails this year
> Security Pros Have Role in Combatting Disinformation
Security professionals need to be tackling all aspects of disinformation