[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (54 articles)

|

// AI-powered summary generated at 12:00

> WordPress Hacker Attacks One Million Sites in a Month
Cross-site scripting bugs in plug-ins targeted in new campaign
> Global Firms Cut IT Security Budgets Due to #COVID19
Move could further expose remote working security gaps during pandemic
> Cookie Crimes and the new Microsoft Edge Browser
Revisiting Cookie Crimes In 2018 @mangopdf described “Cookie Crimes”, which is great research around Chrome’s remote debugging feature that allows adversaries and malware to gain access to cookies quite convienently during post-exploitation. The original research is published here, and it still work...
> Europol Dismantles Combo Sellers InfinityBlack
Cybercrime group touted stolen user log-ins to other gangs
> US Platform Enhances Remote Learning Cybersecurity
US platform aims to help K–12 students safely learn remotely during lockdown
> Post-Exploitation: Abusing Chrome's debugging feature to observe and control browsing sessions remotely
Chrome’s remote debugging feature enables malware post-exploitation to gain access to cookies. Root privileges are not required. This is a pretty well-known and commonly used adversarial technique - at least since 2018 when Cookie Crimes was released. However, remote debugging also allows observing...
> Virtual Graduation Ceremony Delayed by Cyber-attack
Cyber-attack derails American university students’ virtual commencement ceremony
> Dominic Raab Condemns #COVID19 Cyber-Attacks as NCSC and CISA Release APT Advisory
UK Foreign Secretary says he has evidence APT groups are exploiting COVID-19
> Hunting for credentials and building a credential type reference catalog
Adversaries are leveraging widely exposed clear text credentials to gain access to sensitive information. At times the term “harvesting credentials” is used when red teamers emulate these attacks - which is something that appears to be more opportunistic and I would propose that security teams start...
> GoDaddy Suffers Data Breach
Web-hosting account credentials impacted by data breach at world’s largest domain registrar
> Report Reveals Fears Over Threats Posed by Wireless Devices
Over two-thirds of cybersecurity pros have no confidence they could prevent a wireless attack
> Announcing the 1st International Workshop on Smart Contract Analysis
At Trail of Bits we do more than just security audits: We also push the boundaries of research in vulnerability detection tools, regularly present our work in academic conferences, and review interesting papers from other researchers (see our recent Real World Crypto and Financial Crypto recaps). In...
> Brexit-Related Firm Wins Government Contracts Related to AI and Data Mining
AI firm wins multiple government contracts
> Tesla Car Parts Found on eBay Containing User Data
Report suggests carmaker doesn’t have privacy-first disposal process
> Adult Streaming Site Leaks Data on Millions of Members
An unsecured database is again to blame in CAM4 privacy snafu
> State Hackers Target UK Unis for #COVID19 Vaccine Research
Oxford University has started human clinical trials
> Nearly Half of IT Pros Spend Weeks or More Renegotiating Vendor Contracts
Survey reveals need for more unified IT processes in organizations
> 'Vaccines' Containing Blood of Recovered #COVID19 Patients for Sale on Dark Web
Dark web dealers are selling fake vaccines allegedly made with blood from recovered #COVID19 patients
> Belfast Police Warn of Cybercrime Surge
Northern Irish police warn businesses of a spike in cybercrime during the COVID-19 health crisis
> Breach Exposes Data of 774,000 Australian Migrants
A breach of Australia’s SkillsSelect platform has exposed the data of 774,000 migrants