[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (108 articles)

|

// AI-powered summary generated at 16:00

> Online Learning Platform Exposes Data on One Million Students
OneClass claimed leak was of test data, but researchers disagree
> US Bill Proposes Ban on Feds' Using Facial Recognition Technology
US senators introduce bill to stop federal law enforcement from using facial recognition technology
> Using built-in OS indexing features for credential hunting
A few months ago we discussed the importance of performing active credential hunting for your organization. This is to ensure clear text credentials in widely accessible locations and source code are identified before an adversary gets a hold of them. In this post we will explore using built-in oper...
> Fraudster Jailed for Stealing Millions from US Seniors
Criminal Brit funds millionaire lifestyle by stealing savings of elderly Americans
> $200m Spear Phished from Cryptocurrency Exchanges
New threat group CryptoCore steals $200m in 2 years from cryptocurrency exchanges
> Le groupe cybercriminel TA505 (22 juin 2020)
Les marqueurs techniques suivants sont associés au groupe cybercriminel TA505 (voir la publication CERTFR-2020-CTI-006). Ils peuvent être utilisés à des fins de recherche de compromission dans des journaux historiques ou de détection. Mise à jour du 10 février 2021 : un nouveau rapport détaillant...
> Microsoft: Patch IIS Bug Now to Protect Exchange Servers
Redmond warns of sophisticated multi-stage attacks
> European Commission: Still Work to Do on GDPR
Report reveals problems with regulator resourcing and harmonization
> Shadowbunny article published in the PenTest Magazine
The Shadowbunny TTP in the PenTest Magazine The latest edition of the PenTest Magazine features an article of mine about using virtual machines (VMs) during lateral movement to establish persistence and evade detections. A few years back when I came up with the idea of using VMs for lateral movement...
> Domestic Abuse Victims Exposed in Cloud Misconfiguration
Reporting app leaves voice recordings publicly accessible
> Police Seize Alleged Bitcoin Raider's $90m in Assets
Man wanted for cybercrimes in the US has $90m worth of assets seized by New Zealand cops
> Advocating for change
As a company, we believe Black lives matter. In the face of continued police brutality, racial disparities in law enforcement, and limited accountability, we demand an end to systemic racism, endorse restrictions on police use of force, and seek greater accountability for police actions. We believe...
> HelpSystems Acquires Two Security Software Companies
Titus and Boldon James acquired by HelpSystems
> 350,000 Social Media Influencers and Users at Risk Following Data Breach
Personal information of social media users and influencers exposed on dark web
> Putting system owners in Security Bug Jail
Some organization have this interesting concept of a bug jail to prevent new feature development when there are too many existing flaws in the system. For instance, if an engineer has 5 or more bugs assigned they aren’t allowed to work on anything else but fixing their bugs. What is the Security Bug...
> PlayStation Announces Bug Bounty Program
Critical vulnerabilities worth at least $50,000 in new PlayStation bug bounty program
> NCSC: One Million Phishing Messages Reported in Two Months
One million phishing emails flagged to NCSC, with cryptocurrency the most common lure
> Upgradeable contracts made safer with Crytic
Upgradeable contracts are not as safe as you think. Architectures for upgradeability can be flawed, locking contracts, losing data, or sabotaging your ability to recover from an incident. Every contract upgrade must be carefully reviewed to avoid catastrophic mistakes. The most common delegatecall p...
> IRMS Appoints New Chair with Diversity, Inclusion and Education at Top of Agenda
Reynold Leming announced as new chair of the Information and Records Management Society
> 33% Surge in Financial Fraud Attempts During #COVID19 Lockdown
Financial providers foil criminals seeking to take advantage of pandemic disruption