> TODAY'S SUMMARY (108 articles)
Today's cybersecurity landscape highlights several significant threats and trends. AI models continue to leak sensitive corporate data, with over 13,000 exposed images identified by Glow Security. A major breakthrough in law enforcement occurred with the arrest of a ShinyHunters leader in the Netherlands, coinciding with recent high-profile hacks, including an attack on the FBI. Russian threat actor Star Blizzard has refined phishing techniques, while Citrix NetScaler is facing mass exploitation of a zero-day vulnerability (CVE-2026-88771). Apple has patched a critical zero-day flaw (CVE-2026-86950) linked to sophisticated attacks, underscoring ongoing vulnerabilities in popular software. Additionally, the Pentagon personnel agency breach affecting 3 million individuals emphasizes the persistent risk to sensitive government data.
|
// AI-powered summary generated at 16:00
Ransomware attack knocks out Knoxville’s computer network
3.5 million security cameras around the world potentially have a critical security flaw
Upgradeable contracts are not as safe as you think. Architectures for upgradeability can be flawed, locking contracts, losing data, or sabotaging your ability to recover from an incident. Every contract upgrade must be carefully reviewed to avoid catastrophic mistakes. The most common delegatecall p...
Lion loses its roar Down Under
Technology's use by police under fire after US protests
The elliptic curve digital signature algorithm (ECDSA) is a common digital signature scheme that we see in many of our code reviews. It has some desirable properties, but can also be very fragile. For example, LadderLeak was published just a couple of weeks ago, which demonstrated the feasibility of...
Microsoft spots unusual threat vector as machine learning toolkit is targeted
Personal data of police officers in the United States is being leaked online
Monte Carlo simulations can be a useful tool to uplevel your red teaming skills and provide a different and fresh perspective for highlighting, discussing and presenting findings.
Red teaming is about challenging an organization. This includes analyzing business processes and methodologies, includin...
A survey looks at the deployment of SD-WAN on the public cloud
Macy’s settles a class-action lawsuit over a 2018 data breach with a payment of $192,000
TL;DR: Can we check if a mutex is locked in Go? Yes, but not with a mutex API. Here’s a solution for use in debug builds. Although you can Lock() or Unlock() a mutex, you can’t check whether it’s locked. While it is a reasonable omission (e.g., due to possible race conditions; see also Why […]
Fund will enable recipients to build on their innovative solutions
Threat group claims to have exfiltrated data from M&A firm used by Victoria Beckham
Over the last few months, we’ve been fuzzing solc, the standard Solidity smart contract compiler, and we’ve racked up almost 20 (now mostly fixed) new bugs. A few of these are duplicates of existing bugs with slightly different symptoms or triggers, but the vast majority are previously unreported bu...
Malicious apps pose as contact tracing functions to infiltrate users of Android devices
OPORA will use funding for product development, sales and marketing efforts
L'annuaire Active Directory, centre névralgique de la sécurité des systèmes d'information Microsoft, est un élément critique permettant la gestion centralisée de comptes, de ressources et de permissions. L'obtention de privilèges élevés sur cet annuaire entraîne une prise de contrôle instantanée...
COVID19 lockdown has driven increase in use of banking apps
Mimecast’s annual study finds most firms expect email attacks