> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
New report reveals threat actors don cyber-disguises to mask their true intentions
Services at hospitals in the US and Australia have been disrupted by ransomware attacks
Earlier today, a new iPhone Boot ROM exploit, checkm8 (or Apollo or Moonshine), was published on GitHub by axi0mX, affecting the iPhone 4S through the iPhone X. The vulnerability was patched in devices with A12 and A13 CPUs. As of this writing, the iPhone XS, XS Max, XR, 11, 11 Pro and 11 Pro Max […...
Major new organization unifies National Security Agency’s cyber defense strategy
How Magecart attack groups have succeeded, and are moving forwards in attack tactics
Has it really been 3 months since Trail of Bits hosted QueryCon? We’ve had such a busy and productive summer that we nearly forgot to go back and reflect on the success of this event! On June 20-21, Trail of Bits partnered with Kolide and Carbon Back to host the 2nd annual QueryCon, at the […]
NCSC marks three years since its opening with a reflection on achievements
Onapsis study warns of failing security audits
Report highlights growing unease among CEOs
Individual compromised thousands of users in search of adult material
Password-free use of video-conferencing platforms opens door to eavesdroppers
Publishers’ ad blockers are no match for new "meowlware"
Study finds it’s cheap and easy to get fake news stories published in reputable media outlets
Increased attack sophistication means defenders are continually getting stronger
Danish firm Demant comes clean over September attack
Bitdefender study reveals resource constraints are holding them back
Eight employees are fired over two years, according to FOI findings
Bulletproof servers hosting illegal pornography websites seized in bunker raid
New research shows cyber-audits can make and break deals
State representative seeks support for legislation outlawing the uninvited sending of sexually explicit digital images