[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (54 articles)

|

// AI-powered summary generated at 12:00

> Bug Hunting with Crytic
Crytic, our Github app for discovering smart contract flaws, is kind of a big deal: It detects security issues without human intervention, providing continuous assurance while you work and securing your codebase before deployment. Crytic finds many bugs no other tools can detect, including some that...
> Attacks on Banks Spike 238% During #COVID19 Crisis
VMware Carbon Black says attacks coincide with major news events
> ICO’s BA and Marriott Fines Likely to Be Pushed Back Again
Cordery Compliance claims final sum may be much reduced
> $3000 Bug Bounty Award from Mozilla for a successful targeted Credential Hunt
Last month I did some research on Firefox, specifically I was learning more about it’s remote debugging features. As part of that I was reading Bugzilla bug information and learned more about Mozilla’s infrastructure. One thing I noticed reading up on details was that Mozilla uses Phabricator. What...
> UK Power Grid Biz Suffers Outage After Cyber-Attack
Elexon’s internal systems hit but electricity supply unaffected
> Ohio Votes to Outlaw Attempted Hacks
Ohio passes bill to criminalize all malicious hacking attempts, even if they fail
> Le groupe cybercriminel SILENCE (07 mai 2020)
Les marqueurs techniques suivants sont associés en source ouverte au groupe cybercriminel SILENCE (voir la publication CERTFR-2020-CTI-004). Ils peuvent être utilisés à des fins de recherche de compromission dans des journaux historiques. Toute communication depuis ou vers cette infrastructure ne...
> Critical Flaws Found in Cyberoam Security Devices
Vulnerabilities detected in Cyberoam’s firewall and VPN technology
> Identity Breaches at 79% of Organizations
IDSA finds 79% of organizations suffered an identity-related security breach in the last 2 years
> Cookie Crimes and the new Microsoft Edge Browser
Revisiting Cookie Crimes In 2018 @mangopdf described “Cookie Crimes”, which is great research around Chrome’s remote debugging feature that allows adversaries and malware to gain access to cookies quite convienently during post-exploitation. The original research is published here, and it still work...
> DWF Appoints Mark Hendry as Director of Data Protection and Cybersecurity
DWF appoints a new director of data protection and cybersecurity
> Kaspersky Report Shows Need for Improved Password Storage
A Kaspersky study shows the majority of people are unaware of how to check if their credentials have been leaked
> Post-Exploitation: Abusing Chrome's debugging feature to observe and control browsing sessions remotely
Chrome’s remote debugging feature enables malware post-exploitation to gain access to cookies. Root privileges are not required. This is a pretty well-known and commonly used adversarial technique - at least since 2018 when Cookie Crimes was released. However, remote debugging also allows observing...
> Remote Workers Often Not Provided Secure Tools
Remote workers are often not provided secure tools to access networks and authenticate themselves
> Microsoft OLE Bugs Most Frequently Exploited Since 2016
US government reveals top 10 most targeted CVEs
> US: Chinese Hackers Are Targeting #COVID19 Vaccine Researchers
FBI and CISA warn domestic organizations to double down on security
> #COVID19 Hospital Construction Firms Hit by Cyber-Attacks
Data theft and ransomware likely end goals
> City Index Reports Intrusion and Potential Data Breach
Financial trading service provider reports network intrusion to users
> Ramsay Cyber-Espionage Framework Rumbled by Researchers
Researchers discover new cyber-espionage framework dubbed "Ramsay" in development
> CyberArk Acquires Idaptive
Identity-as-a-Service company Idaptive has been acquired by CyberArk