[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> VoIP Firm Broadvoice Leaks 350 Million Customer Records
Elasticsearch misconfiguration to blame once again
> Twitter Locks Trump Campaign Account
Twitter suspends @TeamTrump for “posting private information”
> CVE 2020-16977: VS Code Python Extension Remote Code Execution
While building “Husky AI” I started working a lot with Microsoft’s VS Code Python extension. It is a super convinient way to edit Jupyter Notebooks. I just use VS Code’s Remote SSH feature to get to my Linux host and work on modeling and testing there. When threat modeling “Husky AI” I identified ba...
> US Indicts Money Launderers to Cyber-criminal Elite
Alleged QQAAZZ members indicted for laundering millions of dollars for high-level cyber-criminals
> Cyber-Attack on Major US Bookseller
Barnes & Noble suffers cyber-attack the day after solving its Nook outage issue
> Osquery: Using D-Bus to query systemd data
During my summer internship at Trail of Bits I worked on osquery, the massively popular open-source endpoint monitoring agent used for intrusion detection, threat hunting, operational monitoring, and many other functions. Available for Windows, macOS, Linux, and FreeBSD, osquery exposes an operating...
> Government CIOs Praised for Pandemic Response, Better Collaboration Required
Better collaboration can aid state and local US government departments
> Iranian APT Group Targets Global Universities Again
Tehran wants access to cutting-edge research
> Machine Learning Attack Series: Stealing a model file
This post is part of a series about machine learning and artificial intelligence. Click on the blog tag “huskyai” to see related posts. Overview: How Husky AI was built, threat modeled and operationalized Attacks: The attacks I want to investigate, learn about, and try out We talked about creating a...
> Zoom Finally Rolls out End-to-End Encryption
Stronger security for calls from next week
> US Data Breach Volumes Plummet 30% in 2020
ITRC reveals number of victims has also fallen year-on-year
> Coming up: Grayhat Red Team Village talk about hacking a machine learning system
Excited to announce that I will be presenting at Grayhat - Red Team Village on October 31st 2020. The presentation is about my machine learning journey and how to build and break a machine learning system. If you follow my blog, you can guess that there will be lots of discussion around “Husky AI”....
> Carnival Confirms Passenger Data Compromised
Corporation reveals passenger data from three different cruise lines was accessed during cyber-attack
> Suspended Sentence for Brit Caught in FBI Creepware Sting
A British man caught using malware to secretly film people in the privacy of their homes has avoided prison
> Detecting Iterator Invalidation with CodeQL
Iterator invalidation is a common and subtle class of C++ bugs that often leads to exploitable vulnerabilities. During my Trail of Bits internship this summer, I developed Itergator, a set of CodeQL classes and queries for analyzing and discovering iterator invalidation. Results are easily interpret...
> DFS Calls for Regulation of Social Media Giants
Twitter’s inadequate cybersecurity prompts New York State to recommend regulation of social media companies
> Ransomware Victims Struggle to Recover, Hire and Spend on Threat Prevention
Ransomware victims spend less time on threat prevention and more on response
> PrivacyRaven Has Left the Nest
If you work on deep learning systems, check out our new tool, PrivacyRaven—it’s a Python library that equips engineers and researchers with a comprehensive testing suite for simulating privacy attacks on deep learning systems. Because deep learning enables software to perform tasks without explicit...
> Ivanti Appoints Melissa Puls as New SVP and CMO
Puls brings strong track record of fueling growth through a customer-centric approach to the IT management and security firm
> DVLA Submits Nearly 200 Breach Notifications to ICO
Apricorn FOI request points to data lapses