[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (108 articles)

|

// AI-powered summary generated at 16:00

> Ripple20 Vulnerabilities Affect Hundreds of Millions of IoT Devices
Zero-day vulnerabilities found in Treck software library pose threat for millions of IoT devices
> Wiggle Investigates Cyber-Attack
Customer complaints trigger investigation into alleged cyber-attack at Wiggle
> Putting system owners in Security Bug Jail
Some organization have this interesting concept of a bug jail to prevent new feature development when there are too many existing flaws in the system. For instance, if an engineer has 5 or more bugs assigned they aren’t allowed to work on anything else but fixing their bugs. What is the Security Bug...
> eBay Executives Charged With Cyber-Stalking Critics
eBay executives accused of cyber-stalking staff at an online newsletter and mailing them live cockroaches
> ESET CTO: AI Can Work With Correct Human Intervention
With correct human intervention and data validation, automation can work for businesses
> Upgradeable contracts made safer with Crytic
Upgradeable contracts are not as safe as you think. Architectures for upgradeability can be flawed, locking contracts, losing data, or sabotaging your ability to recover from an incident. Every contract upgrade must be carefully reviewed to avoid catastrophic mistakes. The most common delegatecall p...
> 46% of SMEs Sharing Confidential Files by Email During Lockdown
Financial and employee data regularly being shared between colleagues via email
> New Fake Ad Alert System Launched to Fight Online Scams
ASA and IAB set up new UK Scam Ad Alert tool
> ECDSA: Handle with Care
The elliptic curve digital signature algorithm (ECDSA) is a common digital signature scheme that we see in many of our code reviews. It has some desirable properties, but can also be very fragile. For example, LadderLeak was published just a couple of weeks ago, which demonstrated the feasibility of...
> Global DDoS Attack Dismissed as T-Mobile Misconfiguration
An apparent major DDoS attack was caused by a T-Mobile widespread routing issue
> IT Pros Feel #COVID19 Pressure as 66% Cite Increased Security Risks
Ivanti study reveals major spike in workload for tech teams
> Red Teaming and Monte Carlo Simulations
Monte Carlo simulations can be a useful tool to uplevel your red teaming skills and provide a different and fresh perspective for highlighting, discussing and presenting findings. Red teaming is about challenging an organization. This includes analyzing business processes and methodologies, includin...
> Magecart Attackers Target Retail Brands Under Lockdown
As stores go online only, data thieves line up
> NHS: 100+ Email Accounts Hijacked in Phishing Campaign
NCSC says credential harvesting operation has been ongoing since 2018
> How to check if a mutex is locked in Go
TL;DR: Can we check if a mutex is locked in Go? Yes, but not with a mutex API. Here’s a solution for use in debug builds. Although you can Lock() or Unlock() a mutex, you can’t check whether it’s locked. While it is a reasonable omission (e.g., due to possible race conditions; see also Why […]
> Philippines Convicts Rappler Founder of Cyber-Libel
Rappler founder and executive director to appeal conviction for cyber-libel in a Philippines court
> Mobile Threats Delivered by Adult Content Double
Mobile threats distributed via adult content doubled in 2019
> Breaking the Solidity Compiler with a Fuzzer
Over the last few months, we’ve been fuzzing solc, the standard Solidity smart contract compiler, and we’ve racked up almost 20 (now mostly fixed) new bugs. A few of these are duplicates of existing bugs with slightly different symptoms or triggers, but the vast majority are previously unreported bu...
> Foodora Data Breach Impacts Customers in 14 Countries
Delivery Hero confirms Foodora data breach affecting three quarters of a million customers
> Poor Password Practices and Growing Acceptance of Biometrics in Financial Accounts
People regularly use the same passwords across online financial accounts