> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
MITRE just updated the ATT&CK Framework to include Cloud TTPs.
The update includes techniques for stealing cookies from machines and using them for lateral movement. These are the two techniques I helped contribute to the matrix:
Credential Access - Steal Web Session Cookie Lateral Movement - We...
Cyber-extortionists are threatening to expose the city's data online
App user shown personal data of other customers in 7-Eleven breach
As a summer intern at Trail of Bits, I used the PlusCal and TLA+ formal specification languages to explore Ethereum’s CBC Casper consensus protocol and its Byzantine fault tolerance. This work was motivated by the Medium.com article Peer Review: CBC Casper by Muneeb Ali, Jude […]
Physicians may be allowed to accept cybersecurity donations that could prevent cyber-attacks
Warren and Wyden claim cloud giant should have SSRF mitigations
A lot of companies are working on Ethereum smart contracts, yet writing secure contracts remains a difficult task. You still have to avoid common pitfalls, compiler issues, and constantly check your code for recently discovered risks. A recurrent source of vulnerabilities comes from the early state...
Phishers are after Microsoft and Okta credentials
New Jersey man was after sensitive IP on emerging technology
Summer data breach exposed personal information of 129,000 patients
Your boss can legally demand your social media passwords in the Equality State
Survey reveals cybersecurity workforce is still dominated by white men
Industry body urges firms to relax hiring policies to encourage diversity
Know Fraud system mistakenly identifies reports as containing malware
HackerOne research highlights the effectiveness of bug bounty programs
US East Coast region particularly badly affected
Hotel owners apologize for ignoring bedside robot spying vulnerability
Bank details of over 3.5 million users laid bare in double data breach
Agencies share collaborative plans to tackle interference in presidential election
NCSC dealt with 658 incidents in third year of operation