[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (146 articles)

|

// AI-powered summary generated at 20:00

> MITRE ATT&CK Update for Cloud and cookies!
MITRE just updated the ATT&CK Framework to include Cloud TTPs. The update includes techniques for stealing cookies from machines and using them for lateral movement. These are the two techniques I helped contribute to the matrix: Credential Access - Steal Web Session Cookie Lateral Movement - We...
> Johannesburg Held to Ransom
Cyber-extortionists are threatening to expose the city's data online
> Drivers' Data Exposed in 7-Eleven Fuel App Breach
App user shown personal data of other customers in 7-Eleven breach
> Formal Analysis of the CBC Casper Consensus Algorithm with TLA+
As a summer intern at Trail of Bits, I used the PlusCal and TLA+ formal specification languages to explore Ethereum’s CBC Casper consensus protocol and its Byzantine fault tolerance. This work was motivated by the Medium.com article Peer Review: CBC Casper by Muneeb Ali, Jude […]
> US Proposes Legalizing Cybersecurity Tech Donations to Doctors
Physicians may be allowed to accept cybersecurity donations that could prevent cyber-attacks
> Senators Urge AWS Investigation After Capital One Breach
Warren and Wyden claim cloud giant should have SSRF mitigations
> Watch Your Language: Our First Vyper Audit
A lot of companies are working on Ethereum smart contracts, yet writing secure contracts remains a difficult task. You still have to avoid common pitfalls, compiler issues, and constantly check your code for recently discovered risks. A recurrent source of vulnerabilities comes from the early state...
> Ongoing Phishing Campaign is Targeting UN and NGOs
Phishers are after Microsoft and Okta credentials
> Man Pleads Guilty After Physically Deploying Keyloggers
New Jersey man was after sensitive IP on emerging technology
> Phishing Scam Nets Montana Healthcare Service
Summer data breach exposed personal information of 129,000 patients
> Study Reveals the Worst State for Online Privacy
Your boss can legally demand your social media passwords in the Equality State
> Lack of Diversity Persists in Cybersecurity
Survey reveals cybersecurity workforce is still dominated by white men
> Chartered Institute: IT Security Industry is Stagnating
Industry body urges firms to relax hiring policies to encourage diversity
> Action Fraud Snafu Leaves 9000 Cases Quarantined
Know Fraud system mistakenly identifies reports as containing malware
> £265m Data Breach Costs Could Have Been Avoided with £9600 Worth of Bug Bounties
HackerOne research highlights the effectiveness of bug bounty programs
> AWS Left Reeling After Eight-Hour DDoS
US East Coast region particularly badly affected
> Bedside Robots May Have Been Used to Spy on Hotel Guests in Japan
Hotel owners apologize for ignoring bedside robot spying vulnerability
> Cash-back Websites Expose 2 TB of Sensitive Information
Bank details of over 3.5 million users laid bare in double data breach
> US Government Agencies Outline Security Strategy for 2020 Election
Agencies share collaborative plans to tackle interference in presidential election
> NCSC Blocked 658 Incidents Including Nation State Attacks
NCSC dealt with 658 incidents in third year of operation