[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (135 articles)

|

// AI-powered summary generated at 20:00

> Accountability Concerns Main Reason Security Pros Want to Quit
Survey finds lack of executive accountability is main reason security pros want to quit
> No More Ransom Initiative Reflects on Achievements on Fourth Anniversary
No More Ransom has prevented an estimated $632m reaching criminals
> IAM unique identifiers
Chart of the IAM unique ID prefixes.
> Garmin Confirms Cyber-Attack as Ransomware Recovery Rumored
Garmin admits it suffered encrypting cyber-attack last week
> Identity Governance Business Critical as Orgs Return to Work, Say IT Experts
86% of IT experts believe monitoring for cybersecurity threats will become more challenging due to increase in SaaS apps
> Motivated Intruder - Red Teaming for Privacy!
In this post I will discuss some testing techniques for internal red teams to identify privacy issues in services and infrastructure, most importantly a simple three step approach that might uncover interesting results. Background story First, let me share a story from the past. When I did my master...
> Cosmetics Giant Avon Leaks 19 Million Records
Unsecured cloud server discovered by researchers
> UK/US Governments Warn of QNAP NAS Malware
QSnatch has infected over 60,000 devices globally
> Bypass GuardDuty Pentest Findings for the AWS CLI
Prevent Kali Linux, ParrotOS, and Pentoo Linux from throwing GuardDuty alerts by modifying the User Agent string when using the AWS CLI.
> Over Half of Universities Suffered Data Breach in Past Year
Redscan data finds many are failing on security training and testing
> Virginia Startup CEO Charged with Investment Fraud
The CEO of a bankrupt Crystal City tech firm has been charged with investment fraud
> Bypass Credential Exfiltration Detection
When stealing IAM credentials from an EC2 instance you can avoid a GuardDuty detection by using VPC Endpoints.
> American Insurer Charged Over Sustained Data Breach
New York regulator charges First American Financial unit over years-long data breach
> Google Accused of Privacy Breaches by Australian Watchdog
Australia’s consumer watchdog is taking Google to court over personal data use
> Firefox - Debugger Client for Cookie Access
Finally I got to writing some basic tooling for invoking the Firefox debugging API to send commands to the browser and read the responses. This can be useful for grabbing cookies in the post-exploitation phase. It works for Windows and macOS, should also work on Linux. This technique is probably mos...
> Sheffield Hallam University Confirms Blackbaud-Linked Data Breach
Blackbaud hack hits Sheffield Hallam University
> Panaseer Establishes Advisory Board to Help Expand Cybersecurity Vision
Panaseer establishes advisory board made up of prominent figures in the infosecurity sector
> Remotely debugging Firefox instances
Previously I talked about remotely debugging Chrome, and we also covered the latest Microsoft Edge browser along the way. These features allow an adversary to gain access to authentication tokens and cookies. See MITRE ATT&CK Technique T1539: Steal Web Session Cookie as well for this. What about...
> Six Former NFL Players Charged with $4m Fraud Scheme
Superseding indictment alleges they made false claims for medical equipment
> Phishing Scam Promises ÂŁ400 Council Tax Cut
Another attempt to capitalize on COVID-19 news