[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Nikkei Hit in $29m BEC Scam
Media giant and US city latest victims of email fraud
> Global Registrar Web.com Suffers Major Breach
Customers’ personal info may have been compromised
> Two New Tools that Tame the Treachery of Files
Parsing is hard, even when a file format is well specified. But when the specification is ambiguous, it leads to unintended and strange parser and interpreter behaviors that make file formats susceptible to security vulnerabilities. What if we could automatically generate a “safe” subset of any file...
> #ISC2Congress: The Truth Behind the Lack of Women in Cybersecurity
Low confidence and a toxic workplace culture put women off cybersecurity jobs
> #ISC2Congress: Cybersecurity Education Requires a Transdisciplinary Approach
Cybersecurity should be taught in the same way as reading and writing
> Destroying x86_64 instruction decoders with differential fuzzing
TL;DR: x86_64 decoding is hard, and the number and variety of implementations available for it makes it uniquely suited to differential fuzzing. We’re open sourcing mishegos, a differential fuzzer for instruction decoders. You can use it to discover discrepancies in your own decoders and analysis to...
> #ISC2Congress: Cybersecurity Recruitment Is in a Dangerous Crisis
Inadequate recruitment practices in cybersecurity are a threat to national security
> Two Plead Guilty to Uber and Lynda.com Hacks
Duo’s extortion attempts worked only with ride-hailing giant
> How safe browsing fails to protect user privacy
Recently, security researchers discovered that Apple was sending safe browsing data to Tencent for all Chinese users. This revelation has brought the underlying security and privacy guarantees of the safe browsing protocol under increased scrutiny. In particular, safe browsing claims to protect user...
> Twitter Bans Political Ads Ahead of Key UK Election
Social media platform aims to clean up its act
> #BSidesBelfast: We Need Security Capabilities For Our Whole Lifetime
The next generation need to create "digital identity" security capabilities
> Grace Hopper Celebration (GHC) 2019 Recap
A few weeks ago I had the inspiring experience of attending the annual Grace Hopper Celebration (GHC), the world’s largest gathering of women in technology. Over four days in Orlando, Florida, GHC hosted a slew of workshops and presentations, plus a massive career fair with over […]
> ICO to Police: Go Slow on Facial Recognition
UK watchdog set to work on statutory code of practice
> #BSidesBelfast: Supply Chain Attacks Will Hit Code Repositories Next
Supply chain attacks continue to be a reality for businesses
> MITRE ATT&CK Update for Cloud and cookies!
MITRE just updated the ATT&CK Framework to include Cloud TTPs. The update includes techniques for stealing cookies from machines and using them for lateral movement. These are the two techniques I helped contribute to the matrix: Credential Access - Steal Web Session Cookie Lateral Movement - We...
> #ISC2Congress: Military Hero Shares Tips for a Successful Life
William McRaven tells cybersecurity professionals to take risks and expect failures
> #ISC2Congress: Stars of Cybersecurity Honored in Florida
2019 ISLA Americas winners collect gongs at conference
> Formal Analysis of the CBC Casper Consensus Algorithm with TLA+
As a summer intern at Trail of Bits, I used the PlusCal and TLA+ formal specification languages to explore Ethereum’s CBC Casper consensus protocol and its Byzantine fault tolerance. This work was motivated by the Medium.com article Peer Review: CBC Casper by Muneeb Ali, Jude […]
> #ISC2Congress: CTI Is Woefully Underused
Lack of understanding leaves phenomenal security resource untapped
> #BSidesBelfast: Threat Hunting Requires Curiosity and Culture
What to look for when building a threat hunting team