[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (7 articles)

|

// AI-powered summary generated at 04:00

> CVE-2020-27388: YOURLS 1.5 - 1.7.10, Multiple Stored Cross Site Scripting (XSS) Vulnerabilities in Admin Panel
Potential Abuse on a hooked Function There is a potential for abuse with any plugins that implement the hook function ‘shunt_is_valid_user’. In the code below we simply demonstrate that authentication can be completely bypassed by returning TRUE in the hooked function. This would be an ideal place f...
> US Army Base's Twitter Account Hacked
Army says suggestive tweets sent from Fort Bragg account were posted by a hacker
> Systems Admin Arrested for Hacking Former Employer
Systems admin allegedly hacked US department store to give former colleagues paid holidays
> Efficient audits with machine learning and Slither-simil
Trail of Bits has manually curated a wealth of data—years of security assessment reports—and now we’re exploring how to use this data to make the smart contract auditing process more efficient with Slither-simil. Based on accumulated knowledge embedded in previous audits, we set out to detect simila...
> Judge Signs Off on $7.75m Equifax Settlement
$7.75m Equifax settlement with financial institutions over 2017 data breach ratified by judge
> #SecTorCa: How One Malicious Message Could Exploit an Enterprise
Researcher reveals true depth of flaw in Microsoft Teams that was patched earlier this year
> Pourquoi le nouvel hameçonnage Emotet est-il aussi efficace ?
Le CERT-FR signale une recrudescence d’activitĂ© Emotet en France dans son bulletin d’alerte 2020-ALE-019. Il s’agit d’une nouvelle forme d’attaque : le dĂ©tournement des fils de discussion des courriels (email thread hijacking technique). Cette nouvelle forme d’attaque est particuliĂšrement [...] Li...
> #SecTorCa: Tech for Good, and Bad
All technology comes with both promises and un-intended consequences
> #SecTorCa: The Paramedic’s Guide to Surviving Cybersecurity
In both emergency services and cybersecurity, professionals deal with some of the same challenges
> Machine Learning Attack Series: Adversarial Robustness Toolbox Basics
This post is part of a series about machine learning and artificial intelligence. Click on the blog tag “huskyai” to see related posts. Overview: How Husky AI was built, threat modeled and operationalized Attacks: Some of the attacks I want to investigate, learn about, and try out I wanted to explor...
> US and UK Issue Sanctions to Iran and Russia
UK/EU issue sanctions over cyber-attack, while US points finger at Iran over fake news campaign
> Infected IoT Device Numbers Surge 100% in a Year
Nokia data reveals almost a third of devices are now compromised
> Let’s build a high-performance fuzzer with GPUs!
TL;DR: Can we use GPUs to get 10x performance/dollar when fuzzing embedded software in the cloud? Based on our preliminary work, we think the answer is yes! Fuzzing is a software testing technique that supplies programs with many randomized inputs in an attempt to cause unexpected behavior. It’s an...
> #SecTorCa: Defining the Security Metrics that Matter
Some metrics are more valuable than others in making measurable improvement in security
> Researcher Guesses Password to Access Trump Twitter Account
Two-factor authentication belatedly switched on after incident
> Hacking neural networks - so we don't get stuck in the matrix
For GrayHat 2020 I was asked to create a short intro video for my Red Team Village talk “Learning by doing: Building and breaking a machine learning system”. So I put my green screen to good use and recorded this short clip for Red Team Village. Here is the link to the clip on Twitter: Hope you like...
> #COVID19 Vaccine-Maker Shuts Global Plants After Cyber-Attack
Dr Reddy’s had just been granted permission to start trials
> #SecTorCa: A Hacker’s Perspective on Your Infrastructure
At the SecTor virtual security conference, pen tester outlines the security issues that give hackers easy access to attack users
> What does an offensive security team actually do?
There is a lot of discussion around terms such as red team, attack team, pentest, adversarial engineering or offensive security team and similar ones. I typically stay away from the (sometimes passionate) discussions that ensue whenever this topic comes up. Personally, I think a good strategy is to...
> Oregon Retailer Suffers Sustained Data Breach
Data breach at Made in Oregon goes unnoticed for six months