[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (108 articles)

|

// AI-powered summary generated at 16:00

> Account-Snooping Yahoo Engineer Escapes Jail Time
Man escapes jail time after using his position to snoop on thousands of accounts
> Mobile Users Increasingly Targeted by Undeletable Malicious Files
Adware is often being pre-installed on mobile devices
> Blast from the past: Cross Site Scripting on the AWS Console
Amazon Bug Bounty! Great news: Amazon is now offering bounties via a security vulnerabiltiy research program Bad news: AWS is out of scope! When I read this I remembered that a few years ago I found persistent Cross-Site-Scripting on the AWS Console. This post is a write up on how I found the XSS ba...
> Volume and Size of Fines for Data Breaches Expected to Rise
37% of workers expect the number and size of fines for their employers to increase
> Flaw Fixed in Hotels.com Generator as Tesco Clubcard Users Impacted
Weakness exploited in way Hotels.com generates vouchers
> Feedspot ranked 'Embrace the Red' one of the top 15 pentest blogs
I’m excited that Feedspot ranked this blog (Embrace the Red) the number #10 pentest blog out there. Subscribe and check-in regularly for new content related to offensive security engineering, penetration testing and red teaming. You can also follow me on Twitter @wunderwuzzi23. Cheers.
> Corporate Cybercrime Victims Double in Five Years
ISP estimates cost to UK economy of ÂŁ87bn
> North Korean Hackers Behind Magecart Attacks
Sansec claims Pyongyang-sponsored attackers struck Claire’s
> Using built-in OS indexing features for credential hunting
A few months ago we discussed the importance of performing active credential hunting for your organization. This is to ensure clear text credentials in widely accessible locations and source code are identified before an adversary gets a hold of them. In this post we will explore using built-in oper...
> Google VP Withdraws from Black Hat 2020 Over its Name
Heated debate in infosec community after calls for change in terminology
> NSA Issues VPN Security Guidance
Be careful which pre-configured policies you leave on your IPsec VPN, warns the US government
> Le groupe cybercriminel TA505 (22 juin 2020)
Les marqueurs techniques suivants sont associés au groupe cybercriminel TA505 (voir la publication CERTFR-2020-CTI-006). Ils peuvent être utilisés à des fins de recherche de compromission dans des journaux historiques ou de détection. Mise à jour du 10 février 2021 : un nouveau rapport détaillant...
> Moose Remain Unaware of Lottery Privacy Breach
The Nova Scotia moose hunting lottery didn’t go entirely to plan this year
> Avaddon Ransomware Still Using Excel 4.0 Macros
The Avaddon ransomware is using Excel 4.0 macros as an infection vector
> Record Number Enrol in Online NCSC CyberFirst Courses
The NCSC plans to provide a mix of classroom and virtual classes going forward
> V Shred Exposes Pics and PII on 100,000 Customers
Researchers at vpnMentor claim fitness firm misconfigured S3 bucket
> GoldenSpy Uninstaller Appears Out of Nowhere
Backdoor removal asks more questions than it answers
> Global Dating App Users Exposed in Multiple Security Snafus
WizCase researchers find unsecured online databases in US and Asia
> Researchers Find Vulnerabilities in Apache Remote Desktop Software
Apache Guacamole is an open source remote access gateway
> US Schools and Colleges Have Leaked 24.5 Million Records Since 2005
Educational establishments across the US have leaked millions of records since 2005, according to an analysis of public data