[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (135 articles)

|

// AI-powered summary generated at 20:00

> Online Piracy Ring Dismantled
Agencies in the United States and Europe unite to bring down online piracy group
> US Military Cyber Chief Defends More Aggressive Strategy
Head of US Cyber Command says America was right to become more proactive over cybersecurity
> Race conditions when applying ACLs
Today I’m gonna talk about a class of application security issues I ran across a few times over the years. In particular, let’s discuss race conditions when it comes to files with sensitive content and permissions. Race conditions can allow an adversary to gain access to sensitive information on mac...
> US Issues BeagleBoyz Warning
Americans warned about North Korean bank-robbing cyber-gang, BeagleBoyz
> Local Government Organizations Most Frequently Targeted by Ransomware
Nearly half of ransomware attacks this year have targeted municipalities
> Whoami - Get Principal Name From Keys
During an assessment you may find AWS IAM credentials. Use these tactics to identify the principal of the keys.
> Trend Micro Blocks 28 Billion Cyber-Threats in 1H 2020
Vendor spots increase in BEC and new ransomware families
> BT Security Announces Vendor Partners to Simplify and Strengthen Protection
BT Security announces vendor partners including McAfee, Fortinet, Microsoft and IBM
> Using Echidna to test a smart contract library
In this post, we’ll show you how to test your smart contracts with the Echidna fuzzer. In particular, you’ll see how to: Find a bug we discovered during the Set Protocol audit using a variation of differential fuzzing, and Specify and check useful properties for your own smart contract libraries. An...
> UltraRank Digital Skimming Group Hit Hundreds of Sites
Five-year history of Magecart-like gang uncovered by Group-IB
> Dracula Network Pushes Out Pro-China Twitter Spam
Researchers spot Beijing’s hand in botnet-for-hire campaign
> The Ultimate OSCP Preparation Guide [DEPRECATED]
The Ultimate OSCP Preparation Guide [DEPRECATED] Update Notes This guide is now deprecated due to exam revisions made by Offensive Security on January 11, 2022. I published this guide on August 17th, of 2020. Offensive Security no longer requires the buffer overflow, and to pass this exam, you’ll ha...
> Cybersecurity Community Concerned About Misinformation
Misinformation and fake domains are causing concern among American cybersecurity professionals
> Giveaway Scam Infects 65,000 Devices with Malware
Family of Android apps uses freebie lure to distribute novel ad fraud botnet
> Steal IAM Credentials and Event Data from Lambda
Leverage file read and SSRF vulnerabilities to steam IAM credentials and event data from Lambda.
> US Arrests Tourist Over Malware Conspiracy
Vacationer charged with conspiring to pay employee $1m to infect company with ransomware
> New Zealand’s Stock Exchange Hit by Cyber-Attacks Two Days in a Row
New Zealand’s stock exchange was placed on hold due to “connectivity issues” a day after a DDoS attack
> Red Teaming Telemetry Systems
These days business decisions and feature development often is influenced heavily by telemetry information. Telemetry is baked into the programs, services and applications we use. Companies are hungry for telemetry because with machine learning and Deep Neural Networks “data is the new oil”. Telemet...
> TLS and VPN Flaws Offer Most Pen Tester Access
Vulnerabilities in TLS and a 10-year-old botnet are the most common findings from penetration tests
> Security Flaws in Two Popular TV Set-Top Boxes Expose Customers to Attack
The tv set up boxes are vulnerable to remote takeover, enabling cyber-criminals to launch attacks