> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
GCHQ body issues new report for higher education sector
Exposed S3 bucket led to large-scale data theft
This year’s IACR Crypto conference was an excellent blend of far-out theory and down-to-earth pragmatism. A major theme throughout the conference was the huge importance of getting basic cryptographic primitives right. Systems ranging from TLS servers and bitcoin wallets to state-of-the-art secure m...
Barclaycard reports SCA has had no negative impact on transactions
Tortoiseshell bombards Saudi IT firms with a mix of malware
De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.
Security Risk Advisors opens European HQ in Kilkenny
Forces also need a clear Code of Practice, says think tank
We are proud to announce the integration of ensemble fuzzing into DeepState, our unit-testing framework powered by fuzzing and symbolic execution. Ensemble fuzzing allows testers to execute multiple fuzzers with varying heuristics in a single campaign, while maintaining an architecture for synchroni...
SANS study reveals worries over cyber-skills shortages
Whistleblower failed to abide by NDA, says DoJ
As a summer intern at Trail of Bits, I’ve been working on building Fennec, a tool to automatically replace function calls in compiled binaries that’s built on top of McSema, a binary lifter developed by Trail of Bits. The Problem Let’s say you have a compiled binary, but you […]
New Open Banking regulations make financial services organizations more vulnerable to cybercrime
Follow-up study reveals security of IoT devices is still SOHOpeless
Recently Coinbase published a well written blog post on how they were under attack. The adversaries exploite Firefox 0-days. Details can be found here. One intersting aspect is the following:
“We have also observed the attackers specifically target cloud services, e.g. gmail and others, via browser...
University of Nevada tops the leaderboard in the first official college rankings published by the NCL
TechRank aims to help candidates and companies with job search and hiring processes
Poorly configured systems create major security and privacy risk
New phishing campaign spotted in various languages
Alert Logic report has some quick win advice for SMBs