[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (135 articles)

|

// AI-powered summary generated at 20:00

> Tanium Partners with Google Cloud to Better Battle APTs
Tanium integrates technology with Google Cloud, BeyondCorp and Chronicle
> Copper Technologies Appoints New Chief Information Security Officer
Jake Rogers takes up the role, joining from Amnesty International
> Accidentally stepping on a DeFi lego
The initial release of yVault contained logic for computing the price of yUSDC that could be manipulated by an attacker to drain most (if not all) of the pool’s assets. Fortunately, Andre, the developer, reacted incredibly quickly and disabled the faulty code, securing the approximately 400,000 USD...
> Cloud Breaches Set to Grow in “Velocity and Scale”
93% of cloud deployments contain misconfigured services
> Punishing Cybersecurity Errors Found to be Counterproductive
Punishing employees for cyber-mistakes can reduce their long-term cyber-resilience
> Steal EC2 Metadata Credentials via SSRF
Old faithful; How to steal IAM Role credentials from the EC2 Metadata service via SSRF.
> Michigan's Largest Healthcare Provider Phished Again
Beaumont Health notifies 6,000 patients of a second phishing-related data breach
> FBI Issues Online Shopping Scam Alert
Feds report a rise in the number of Americans not receiving items purchased online
> Illusion of Control: Capability Maturity Models and Red Teaming
Throughout my career I have been fascinated with quality assurance and testing, especially security testing and red teaming. One discussion that comes up frequently is how to measure the maturity of such programs and processes. My answer is straight forward as there are already existing frameworks t...
> Facebook Seen as Riskiest Online Platform
Internet users believe their personal data is most at risk on Facebook
> WastedLocker Ransomware “Most Sophisticated Attack” Outside Nation State Use
Ransomware requires multiple levels of detection for prevention
> Connection Tracking
Abuse security group connection tracking to maintain persistence even when security group rules are changed.
> Google Bans Ads Linking to Hacked Political Content
Tech giant in bid to prevent Presidential election interference
> New AppMaker Tool Promises Censorship-Free Content
NGOs operating inside the Great Firewall urged to take advantage
> IAM unique identifiers
Chart of the IAM unique ID prefixes.
> NetWalker RaaS Makes $25m in Five Months
McAfee report reveals a fast-emerging player on the ransomware scene
> Malware Author Admits Role in $568m Cyber-Fraud
Malware creator pleads guilty to role in transnational cybercrime organization that stole $568m
> Motivated Intruder - Red Teaming for Privacy!
In this post I will discuss some testing techniques for internal red teams to identify privacy issues in services and infrastructure, most importantly a simple three step approach that might uncover interesting results. Background story First, let me share a story from the past. When I did my master...
> Second Data Breach at Kentucky Unemployment System
Claimant reports second data breach in four months at Kentucky's Office of Unemployment Insurance
> Cyber-Criminals Ease Off Travel Industry
Cyber-attackers are eschewing the travel and hospitality sector to target IT companies