> TODAY'S SUMMARY (108 articles)
Today's cybersecurity landscape highlights several significant threats and trends. AI models continue to leak sensitive corporate data, with over 13,000 exposed images identified by Glow Security. A major breakthrough in law enforcement occurred with the arrest of a ShinyHunters leader in the Netherlands, coinciding with recent high-profile hacks, including an attack on the FBI. Russian threat actor Star Blizzard has refined phishing techniques, while Citrix NetScaler is facing mass exploitation of a zero-day vulnerability (CVE-2026-88771). Apple has patched a critical zero-day flaw (CVE-2026-86950) linked to sophisticated attacks, underscoring ongoing vulnerabilities in popular software. Additionally, the Pentagon personnel agency breach affecting 3 million individuals emphasizes the persistent risk to sensitive government data.
|
// AI-powered summary generated at 16:00
OneClass claimed leak was of test data, but researchers disagree
US senators introduce bill to stop federal law enforcement from using facial recognition technology
A few months ago we discussed the importance of performing active credential hunting for your organization.
This is to ensure clear text credentials in widely accessible locations and source code are identified before an adversary gets a hold of them.
In this post we will explore using built-in oper...
Criminal Brit funds millionaire lifestyle by stealing savings of elderly Americans
New threat group CryptoCore steals $200m in 2 years from cryptocurrency exchanges
Les marqueurs techniques suivants sont associés au groupe cybercriminel TA505 (voir la publication CERTFR-2020-CTI-006). Ils peuvent être utilisés à des fins de recherche de compromission dans des journaux historiques ou de détection. Mise à jour du 10 février 2021 : un nouveau rapport détaillant...
Redmond warns of sophisticated multi-stage attacks
Report reveals problems with regulator resourcing and harmonization
The Shadowbunny TTP in the PenTest Magazine The latest edition of the PenTest Magazine features an article of mine about using virtual machines (VMs) during lateral movement to establish persistence and evade detections.
A few years back when I came up with the idea of using VMs for lateral movement...
Reporting app leaves voice recordings publicly accessible
Man wanted for cybercrimes in the US has $90m worth of assets seized by New Zealand cops
As a company, we believe Black lives matter. In the face of continued police brutality, racial disparities in law enforcement, and limited accountability, we demand an end to systemic racism, endorse restrictions on police use of force, and seek greater accountability for police actions. We believe...
Titus and Boldon James acquired by HelpSystems
Personal information of social media users and influencers exposed on dark web
Some organization have this interesting concept of a bug jail to prevent new feature development when there are too many existing flaws in the system.
For instance, if an engineer has 5 or more bugs assigned they aren’t allowed to work on anything else but fixing their bugs.
What is the Security Bug...
Critical vulnerabilities worth at least $50,000 in new PlayStation bug bounty program
One million phishing emails flagged to NCSC, with cryptocurrency the most common lure
Upgradeable contracts are not as safe as you think. Architectures for upgradeability can be flawed, locking contracts, losing data, or sabotaging your ability to recover from an incident. Every contract upgrade must be carefully reviewed to avoid catastrophic mistakes. The most common delegatecall p...
Reynold Leming announced as new chair of the Information and Records Management Society
Financial providers foil criminals seeking to take advantage of pandemic disruption