> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
‘Samy’ MySpace worm creator discusses the difficulties of defending against attacks
4% of IT stakeholders have never heard of a 22-year-old cyber-threat that directly impacts 95% of businesses
During my internship this summer, I built a multi-party computation (MPC) tool that implements a 3-party computation protocol for perceptron and support vector machine (SVM) algorithms. MPC enables multiple parties to perform analyses on private datasets without sharing them with each other. I defve...
New Leadership in Healthcare Privacy and Security Risk Management course is launched
Almost 50% more young women are applying to study cybersecurity via the NCSC
Have you ever tried using LLVM’s X-Ray profiling tools to make some flame graphs, but gotten obscure errors like: ==65892==Unable to determine CPU frequency for TSC accounting. ==65892==Unable to determine CPU frequency. Or worse, have you profiled every function in an application, only to find the...
Researcher explores why hacking exploits are not always malicious but rather inspired by inquisitively
Personal contact information of Twitter users may have “inadvertently been used for advertising purposes”
Earlier today, a new iPhone Boot ROM exploit, checkm8 (or Apollo or Moonshine), was published on GitHub by axi0mX, affecting the iPhone 4S through the iPhone X. The vulnerability was patched in devices with A12 and A13 CPUs. As of this writing, the iPhone XS, XS Max, XR, 11, 11 Pro and 11 Pro Max […...
Offensive cyber-capabilities are getting stronger and more readily available
Former chief of MI6 says there are challenges to overcome in the telecommunications sector
Has it really been 3 months since Trail of Bits hosted QueryCon? We’ve had such a busy and productive summer that we nearly forgot to go back and reflect on the success of this event! On June 20-21, Trail of Bits partnered with Kolide and Carbon Back to host the 2nd annual QueryCon, at the […]
Microsoft patched 59 vulnerabilities yesterday, nine classified as “critical”
How breach response is about readiness
Business Email Compromise attacks more than doubled in Q3, 2019.
New Open Cybersecurity Alliance wins backing of 18 vendors
A cyber-safety method modeled on the human nervous system is being developed in Arizona
Making cyber a business risk can aid with board engagement
More sophisticated attackers and targeted attacks are a concern for UK police
Just 32% of orgs think securing data in the cloud is their own responsibility