[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (57 articles)

|

// AI-powered summary generated at 12:00

> Steal IAM Credentials and Event Data from Lambda
Leverage file read and SSRF vulnerabilities to steam IAM credentials and event data from Lambda.
> Red Teaming Telemetry Systems
These days business decisions and feature development often is influenced heavily by telemetry information. Telemetry is baked into the programs, services and applications we use. Companies are hungry for telemetry because with machine learning and Deep Neural Networks “data is the new oil”. Telemet...
> Human Error Threatens Cloud Security
Majority of security professionals believe human error could expose cloud data
> FireEye Announces Bug Bounty Program
California cybersecurity company launches public bug bounty program
> Sinter: New user-mode security enforcement for macOS
TL;DR: Sinter is the first available open-source endpoint protection agent written entirely in Swift, with support for Apple’s new EndpointSecurity API from first principles. Sinter demonstrates how to build a successful event-authorization security agent, and incorporates solutions to many of the c...
> Pace Center for Girls' Donor Data Breached
Blackbaud security breach affects donor data of Florida non-profit social services agency
> Incident Response Exercises Not Taken Seriously by Business Leaders
Business efforts on incident response exercises do not show suitable preparedness
> CEH Master, An Honest Review
Certified Ethical Hacker | Master The CEH Master offered by EC-Council, claims to be a real-world, hands-on approach to everyday life as an ethical hacker: In the above photo, what stood out the most to me was, “We test your abilities with real-world challenges in a real-world environment, and a tim...
> Microsoft Patches 120 CVEs Including Two Zero Days
Yet another 100+ patch-load for sysadmins this year
> Police Use of Facial Recognition Ruled Unlawful in World-First Case
Liberty celebrates verdict but South Wales Police may continue trials
> Linux Privilege Escalation: Quick and Dirty
Linux Privilege Escalation: Quick and Dirty Automated Tooling Usually, my approach is to use an automated tool in conjunction with some manual enumeration. However, you can completely accomplish the Privilege Escalation process from an automated tool paired with the right exploitation methodology. 1...
> A Third of UK Unis Hit By Ransomware in Last 10 Years
Universities may be seen as especially vulnerable to ransomware attack
> SANS Institute Phishing Attack Leads to Theft of 28,000 Records
Security training firm says PII forwarded to external address
> Unauthenticated Enumeration of IAM Users and Roles
Discover how to exploit cross-account behaviors to enumerate IAM users and roles in another AWS account without authentication.
> Australian Jailed for Stealing XRP Crypto
Australia jails one of the first people in the country to be charged with stealing cryptocurrency
> Cyber-Harassment Charges Dropped Against Nutley Cop Photo Tweeters
Case dismissed against Twitter users who sought to publicly identify New Jersey cop
> Accidentally stepping on a DeFi lego
The initial release of yVault contained logic for computing the price of yUSDC that could be manipulated by an attacker to drain most (if not all) of the pool’s assets. Fortunately, Andre, the developer, reacted incredibly quickly and disabled the faulty code, securing the approximately 400,000 USD...
> Public Sector Outperforming Private in Data Management Although Challenges Remain
The percentage of data stored by the public sector has a known value compared with other industries
> Data Breach at Illinois Healthcare System
Illinois healthcare system FHN warns patients their data was exposed in February
> Steal EC2 Metadata Credentials via SSRF
Old faithful; How to steal IAM Role credentials from the EC2 Metadata service via SSRF.