[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (135 articles)

|

// AI-powered summary generated at 20:00

> The Ultimate OSCP Preparation Guide [DEPRECATED]
The Ultimate OSCP Preparation Guide [DEPRECATED] Update Notes This guide is now deprecated due to exam revisions made by Offensive Security on January 11, 2022. I published this guide on August 17th, of 2020. Offensive Security no longer requires the buffer overflow, and to pass this exam, you’ll ha...
> Looting Causes Data Breach at Walgreens
Pharmacy warns PHI of 72,000 Americans compromised by prescription-stealing looters
> US Disrupts Three Cyber-Enabled Terror Campaigns
US announces largest ever cryptocurrency seizure as three terror campaigns disrupted
> Steal IAM Credentials and Event Data from Lambda
Leverage file read and SSRF vulnerabilities to steam IAM credentials and event data from Lambda.
> Phishing Scam Targets Asda Shoppers
Scammers lure supermarket shoppers by dangling a £1000 gift card via social media
> RedCurl Emerges as a Corporate Espionage APT
Group-IB report details prolific group’s activities for the first time
> Red Teaming Telemetry Systems
These days business decisions and feature development often is influenced heavily by telemetry information. Telemetry is baked into the programs, services and applications we use. Companies are hungry for telemetry because with machine learning and Deep Neural Networks “data is the new oil”. Telemet...
> Over 43,000 Phishing Emails Slip Through NHS Security Filters
Health service at risk as staff battle COVID-19
> GCHQ: Don’t Fall For ‘Celebrity-Backed’ Investment Scams
NCSC has already taken down 300,000 URLs connected to such scams
> Sinter: New user-mode security enforcement for macOS
TL;DR: Sinter is the first available open-source endpoint protection agent written entirely in Swift, with support for Apple’s new EndpointSecurity API from first principles. Sinter demonstrates how to build a successful event-authorization security agent, and incorporates solutions to many of the c...
> "Hacker Princess" Wins (ISC)² Diversity Award
Kristin Paget scoops gong for driving a more diverse cybersecurity workforce
> US Court Orders Defendant to Unlock Phones
New Jersey’s highest court rules defendant must share his phones’ passcodes with law enforcement
> CEH Master, An Honest Review
Certified Ethical Hacker | Master The CEH Master offered by EC-Council, claims to be a real-world, hands-on approach to everyday life as an ethical hacker: In the above photo, what stood out the most to me was, “We test your abilities with real-world challenges in a real-world environment, and a tim...
> CactusPete Targets Eastern European Military
APT group spies on financial and military organizations in Eastern Europe
> Phishing Tactic Targets Verizon Users' Credentials
Phishing attack targets and collects Verizon user credentials
> Linux Privilege Escalation: Quick and Dirty
Linux Privilege Escalation: Quick and Dirty Automated Tooling Usually, my approach is to use an automated tool in conjunction with some manual enumeration. However, you can completely accomplish the Privilege Escalation process from an automated tool paired with the right exploitation methodology. 1...
> IT Pros Name Misconfiguration #1 Cloud Security Threat
Check Point report reveals skills shortage is biggest barrier to adoption
> CASB Complexity Means Many Products Are Under-Utilized
Cloud Security Alliance claims in-house skills are also lacking
> Unauthenticated Enumeration of IAM Users and Roles
Discover how to exploit cross-account behaviors to enumerate IAM users and roles in another AWS account without authentication.
> Open Source Supply Chain Attacks Surge 430%
Sonatype warns of OSS dependencies and vulnerable components