[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (135 articles)

|

// AI-powered summary generated at 20:00

> Beijing-Backed Hackers Indicted for #COVID19 Vaccine Attacks
Duo stole IP over 10-year period for China, alleges DoJ
> Women in Cybersecurity Paid 21% Less Than Men
Although female workforce is growing, inequities remain
> Bypass GuardDuty Pentest Findings for the AWS CLI
Prevent Kali Linux, ParrotOS, and Pentoo Linux from throwing GuardDuty alerts by modifying the User Agent string when using the AWS CLI.
> MATA Malware Framework Latest Move for North Korean Hackers
Kaspersky uncovers multi-platform toolset used in data theft and ransomware
> Bypass Credential Exfiltration Detection
When stealing IAM credentials from an EC2 instance you can avoid a GuardDuty detection by using VPC Endpoints.
> Vodafone Partners with Accenture to Offer Cybersecurity Services
Accenture and Vodafone Business team up to bring cybersecurity services to Europe
> Fortinet Acquires OPAQ Networks
Fortinet acquires Secure Access Service Edge (SASE) cloud provider OPAQ Networks
> Firefox - Debugger Client for Cookie Access
Finally I got to writing some basic tooling for invoking the Firefox debugging API to send commands to the browser and read the responses. This can be useful for grabbing cookies in the post-exploitation phase. It works for Windows and macOS, should also work on Linux. This technique is probably mos...
> Texas College to Improve Cybersecurity of Smart Buildings
Texas college launches project to beef up the cybersecurity of smart buildings
> #COVID19 Provides Unique Opportunities for Fraudsters
Increased reliance on digital services has led to a huge rise in online fraud
> Remotely debugging Firefox instances
Previously I talked about remotely debugging Chrome, and we also covered the latest Microsoft Edge browser along the way. These features allow an adversary to gain access to authentication tokens and cookies. See MITRE ATT&CK Technique T1539: Steal Web Session Cookie as well for this. What about...
> Trusted Connectivity Alliance Announces New Chair and Expanded Board
TCA is a global, non-profit association that works to enable a secure, connected future
> ISC Attributes Cyber-Attacks and Election Interference to Russia
ISC says Russia poses all-encompassing security threat, calls for collaborative intelligence and consensus against aggressive action
> Performing port-proxying and port-forwarding on Windows
A technique on Windows that is less known is how to do basic port-proxying. Proxying ports is useful when a process binds on one (maybe only the local) interface and you want to expose that endpoint on another network interface. Let’s say you have an existing process that listens only on the loopbac...
> Experts Predict Record 20,000 CVEs for 2020
Skybox Security claims mobile OS bugs have surged 50%
> Telecom Argentina Has Tuesday Deadline to Pay $7.5m Ransom
ISP appears to have been targeted by REvil group
> Contract verification made easier
Smart contract authors can now express security properties in the same language they use to write their code (Solidity) and our new tool, manticore-verifier, will automatically verify those invariants. Even better, Echidna and Manticore share the same format for specifying property tests. In other w...
> Genealogy Software Maker Exposes Data on 60,000 Users
Family tree developer misconfigures Elasticsearch server
> Cyprus Extradites Alleged Cyber-Criminal to the US
Alleged cyber-criminal becomes first Cypriot national to be extradited from Cyprus to the US
> Analysts Detect New Banking Malware
Researchers discover new malware based on Xerxes banking Trojan