[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (135 articles)

|

// AI-powered summary generated at 20:00

> Illusion of Control: Capability Maturity Models and Red Teaming
Throughout my career I have been fascinated with quality assurance and testing, especially security testing and red teaming. One discussion that comes up frequently is how to measure the maturity of such programs and processes. My answer is straight forward as there are already existing frameworks t...
> Ohio Researcher Admits Selling Secrets to China
Children’s hospital researcher made over $1m selling US scientific research to China
> Volunteer Program Aims to Secure US Election
New initiative matches US election officials with volunteer cybersecurity professionals
> Connection Tracking
Abuse security group connection tracking to maintain persistence even when security group rules are changed.
> Digital Propaganda Campaign Discredits US
Ghostwriter campaign spreads misinformation and stirs up hatred of US and NATO
> Many Second Hand Phones Are Sold with Security Vulnerabilities
Which? finds 31% of used phones sold by one retailer are not supported by security updates
> IAM unique identifiers
Chart of the IAM unique ID prefixes.
> Future Bright for CISOs Despite Budget and Transformation Challenges, Say Security Leaders
The best CISOs are in a place where they are business leaders
> Drizly Breach Hits 2.5 Million Customer Accounts
Personal information stolen in cyber-raid
> Motivated Intruder - Red Teaming for Privacy!
In this post I will discuss some testing techniques for internal red teams to identify privacy issues in services and infrastructure, most importantly a simple three step approach that might uncover interesting results. Background story First, let me share a story from the past. When I did my master...
> Crypto Firm Ledger’s Breach Hits One Million Customers
Marketing database exposed in June attack
> Twitter Confirms Spear-Phishing Attack Caused Account Takeover
Twitter confirms a spear-phishing attack caused the recent account takeover
> Bypass GuardDuty Pentest Findings for the AWS CLI
Prevent Kali Linux, ParrotOS, and Pentoo Linux from throwing GuardDuty alerts by modifying the User Agent string when using the AWS CLI.
> EU Applies First Ever Sanctions in Response to Cyber-Attacks
WannaCry, NotPetya and Cloud Hopper attackers are punished
> UK Gov-Funded Projects Aim to Put Britain at Forefront of 5G Tech
Remote music festival among multiple 5G R&D projects to receive UK government funding
> Bypass Credential Exfiltration Detection
When stealing IAM credentials from an EC2 instance you can avoid a GuardDuty detection by using VPC Endpoints.
> Mississippi Radio Host Charged with Cyber-Stalking
WPBQ Radio host The Cipher Voice arrested on cyber-stalking charges
> Mimecast Acquires MessageControl
Mimecast acquires Chicago email and messaging security company MessageControl
> Firefox - Debugger Client for Cookie Access
Finally I got to writing some basic tooling for invoking the Firefox debugging API to send commands to the browser and read the responses. This can be useful for grabbing cookies in the post-exploitation phase. It works for Windows and macOS, should also work on Linux. This technique is probably mos...
> ESET Releases Advice on Protecting Against Thunderspy
Thunderbolt-based attacks are generally limited to high profile targets