> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
69% of UK workers do not have confidence in their ability to keep data secure
The Emerald Isle’s cybersecurity sector continues to grow
During my internship this summer, I built a multi-party computation (MPC) tool that implements a 3-party computation protocol for perceptron and support vector machine (SVM) algorithms. MPC enables multiple parties to perform analyses on private datasets without sharing them with each other. I defve...
Amex warns customers to be vigilant for fraudulent activity on their accounts after data breach
Gamers were shown personal information of other contenders when registering to compete
Have you ever tried using LLVM’s X-Ray profiling tools to make some flame graphs, but gotten obscure errors like: ==65892==Unable to determine CPU frequency for TSC accounting. ==65892==Unable to determine CPU frequency. Or worse, have you profiled every function in an application, only to find the...
Too many decisions in cybersecurity require more of a discussion on morals and ethics
Vendor collaboration enables better threat intelligence
Earlier today, a new iPhone Boot ROM exploit, checkm8 (or Apollo or Moonshine), was published on GitHub by axi0mX, affecting the iPhone 4S through the iPhone X. The vulnerability was patched in devices with A12 and A13 CPUs. As of this writing, the iPhone XS, XS Max, XR, 11, 11 Pro and 11 Pro Max […...
Two and a half years on from WannaCry, endpoints remain unpatched and vulnerable
ISP data reveals IoT and file sharing are top targets
Has it really been 3 months since Trail of Bits hosted QueryCon? We’ve had such a busy and productive summer that we nearly forgot to go back and reflect on the success of this event! On June 20-21, Trail of Bits partnered with Kolide and Carbon Back to host the 2nd annual QueryCon, at the […]
Only 13% have cyber insurance, according to FOI request
Governments repeat “impossible” backdoor access request
URGENT/11 vulnerabilities discovered in widely used third-party software
Government entities, schools, and healthcare providers are the main focus of this year’s US ransomware attacks
Matjaž Škorjanc has reportedly been arrested by German federal police on US charges
The winners of the annual Security Serious "Unsung Heroes" awards were announced at an event in London
Context researchers reveal sophisticated nation state group Avivore
Personal info and passwords were accessed in 2016 incident