[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (54 articles)

|

// AI-powered summary generated at 12:00

> Banks’ DMARC Fail Puts #COVID19 Business Loans at Risk of Phishing
Proofpoint claims just 20% have DMARC set to strongest policy
> Law Firm to the Stars Confirms Ransomware Attack
Grubman Shire Meiselas & Sacks notifies celebrity clients of ransomware attack
> Le groupe cybercriminel SILENCE (07 mai 2020)
Les marqueurs techniques suivants sont associĂ©s en source ouverte au groupe cybercriminel SILENCE (voir la publication CERTFR-2020-CTI-004). Ils peuvent ĂȘtre utilisĂ©s Ă  des fins de recherche de compromission dans des journaux historiques. Toute communication depuis ou vers cette infrastructure ne...
> Investigation into “Significant Privacy Breach” at Ontario Care Home
An Ontario care home where 66 have died from COVID-19 is being investigated over potential privacy breach
> INTERPOL Declares “Anti-Ransomware Day”
INTERPOL and Kaspersky dub WannaCry’s third anniversary “Anti-Ransomware Day”
> Cookie Crimes and the new Microsoft Edge Browser
Revisiting Cookie Crimes In 2018 @mangopdf described “Cookie Crimes”, which is great research around Chrome’s remote debugging feature that allows adversaries and malware to gain access to cookies quite convienently during post-exploitation. The original research is published here, and it still work...
> CISSP Qualification Given Cert Status Equivalent to Master’s Degree Level
CISSP designated as comparable to RQF Level 7
> Colin Murphy Appointed KnowBe4’s New Chief Information Officer
Experienced IT pro joins C-suite of international cybersecurity awareness training provider
> Post-Exploitation: Abusing Chrome's debugging feature to observe and control browsing sessions remotely
Chrome’s remote debugging feature enables malware post-exploitation to gain access to cookies. Root privileges are not required. This is a pretty well-known and commonly used adversarial technique - at least since 2018 when Cookie Crimes was released. However, remote debugging also allows observing...
> Check Point Detects 30% Increase in #COVID19 Attacks
Cyber-criminals continue to register new domains or phishing campaigns
> Pitney Bowes Hit by Ransomware for Second Time
Mailing tech firm targeted by Maze group
> Hunting for credentials and building a credential type reference catalog
Adversaries are leveraging widely exposed clear text credentials to gain access to sensitive information. At times the term “harvesting credentials” is used when red teamers emulate these attacks - which is something that appears to be more opportunistic and I would propose that security teams start...
> Two WordPress Plugin Bugs Expose Over One Million Sites
Wordfence warns of cross-site request forgery vulnerabilities
> US to Issue Warning over Attempted Theft of Coronavirus Research
FBI and DHS to warn that state-backed threat actors are trying to swipe COVID-19 vaccine data
> Attackers Pose as Zoom to Steal Microsoft Credentials
Fake Zoom notification email contains malicious link to Microsoft login
> Only 19% of Lockdown ‘Work from Homers’ Update Anti-Virus Solution
New research highlights poor work-from-home security practices
> Cyber-Attacks on UK Orgs Up 30% in Q1 2020
Beaming research finds UK companies suffered more than one attack per minute
> Black Hat USA and DEF CON Cancelled Due to #COVID19
Popular cybersecurity conferences will go virtual this year
> Cognizant: Ransomware Costs Could Reach $70m
IT giant admits major financial hit from Maze raid
> Data Breach Exposes Four Million Dating App Users
MobiFriends was apparently breached back in January 2019