> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
China suspected of stealing aviation secrets
Organization aims to help victims, improve accountability and develop behavioral norms
Earlier today, a new iPhone Boot ROM exploit, checkm8 (or Apollo or Moonshine), was published on GitHub by axi0mX, affecting the iPhone 4S through the iPhone X. The vulnerability was patched in devices with A12 and A13 CPUs. As of this writing, the iPhone XS, XS Max, XR, 11, 11 Pro and 11 Pro Max […...
Professor of law awarded $625,000 to propose cyber-harassment reforms
Trojan-delivered spyware uses messaging app to exfiltrate stolen information
Has it really been 3 months since Trail of Bits hosted QueryCon? We’ve had such a busy and productive summer that we nearly forgot to go back and reflect on the success of this event! On June 20-21, Trail of Bits partnered with Kolide and Carbon Back to host the 2nd annual QueryCon, at the […]
State of New York accuses donut chain of failing to protect customers
Venafi reveals low levels of trust in governments’ data protection promises
This year’s IACR Crypto conference was an excellent blend of far-out theory and down-to-earth pragmatism. A major theme throughout the conference was the huge importance of getting basic cryptographic primitives right. Systems ranging from TLS servers and bitcoin wallets to state-of-the-art secure m...
Unsolicited texts from legitimate lenders look like scams
Delivery service only discovered May incident earlier this month
A fight to control the digital infrastructure of a miniature city will take place at HITB + Cyber Week
A cybersecurity information-sharing resource has been launched to help healthcare organizations in the US
The Lone Star State calls for applications to certify cybersecurity training
Cloud native apps rarely secured using DevOps strategies
Digital skimming takes a new turn in the quest for more victims
Another Elasticsearch database found unprotected online
Elliott Gunton wanted for attack on cryptocurrency exchange
Job-seeking veterans targeted by threat group Tortoiseshell
Staff switching jobs within a company are retaining unnecessary access rights