[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (135 articles)

|

// AI-powered summary generated at 20:00

> #BHUSA: Researchers Reveal Attacks Against Email Sender Authentication
There are various different standards intended to help secure email sender authentication, but they don’t quite work as promised
> #BHUSA: Lack of Electronic Medical Record Security Amplified Opioid Crisis
Trust in Electronic Medical Record system is essential, but security needs to be improved
> Unauthenticated Enumeration of IAM Users and Roles
Discover how to exploit cross-account behaviors to enumerate IAM users and roles in another AWS account without authentication.
> Capital One Fined $80m for 2019 Breach
The Office of the Comptroller of the Currency fines Capital One over its 2019 breach
> #BHUSA: How Nation States Hack Public Opinion
Keynote speaker explains how nation state threat actors manipulate social media to extend disinformation, division and propaganda
> Accidentally stepping on a DeFi lego
The initial release of yVault contained logic for computing the price of yUSDC that could be manipulated by an attacker to drain most (if not all) of the pool’s assets. Fortunately, Andre, the developer, reacted incredibly quickly and disabled the faulty code, securing the approximately 400,000 USD...
> Substantial Rise in Attacks on Orgs’ Web Apps Last Year
55% of cyber-attacks targeted organizations' applications in 2019
> Louisiana Judicial Candidate Charged with Hacking
Louisiana judicial candidate allegedly hacked state computers and shared confidential documents with a friend
> Steal EC2 Metadata Credentials via SSRF
Old faithful; How to steal IAM Role credentials from the EC2 Metadata service via SSRF.
> Online Exam Tool Suffers Data Breach
Data breach hits online examination software used by universities
> US Cybersecurity Firms Partner to Protect Healthcare
CynergisTek teams up with Awake Security to spot threats in healthcare networks
> Illusion of Control: Capability Maturity Models and Red Teaming
Throughout my career I have been fascinated with quality assurance and testing, especially security testing and red teaming. One discussion that comes up frequently is how to measure the maturity of such programs and processes. My answer is straight forward as there are already existing frameworks t...
> Half of Orgs Regularly Push Vulnerable Code in App Security Programs
43% of organizations see DevOps integration as the most important aspect of improving app security programs
> #BHUSA: How Public Standards Help to Enable Financial Fraud
Financial malware used by North Korea has to rely on the same transaction standards that banks do
> Connection Tracking
Abuse security group connection tracking to maintain persistence even when security group rules are changed.
> #BHUSA: Android Phones at Risk of BlueRepli Bluetooth Attack
Researchers disclose Bluetooth attack that can potentially enable an attacker to steal information from almost any Android device
> INTERPOL: Cybercrime Growing at an “Alarming Pace” Due to #COVID19
Cyber-criminals are taking advantage of the increasing reliance on digital technology
> IAM unique identifiers
Chart of the IAM unique ID prefixes.
> Redcar and Cleveland Attack Recovery Cost Over ÂŁ10m
February's cyber-attack on Redcar and Cleveland council cost ÂŁ10m in recovery costs
> #BHUSA: Can the US Election be Held During the Pandemic?
Keynote speaker Matt Blaze outlines the challenges of election security and what needs to happen to enable a safe and secure US election in November