> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
DEFRA and Environment Agency respond to FOI requests
Symantec lays off hundreds of employees amid buyout rumors
This year’s IACR Crypto conference was an excellent blend of far-out theory and down-to-earth pragmatism. A major theme throughout the conference was the huge importance of getting basic cryptographic primitives right. Systems ranging from TLS servers and bitcoin wallets to state-of-the-art secure m...
Coalfire employees charged with burglary of courthouse that had hired firm to carry out security checks
Milwaukee School of Engineering opens new cybersecurity facility funded by $34m donation from former student
De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.
How consistent API flaws allowed IoT devices to be hacked
The steps to take to ensure your mental health stability
We are proud to announce the integration of ensemble fuzzing into DeepState, our unit-testing framework powered by fuzzing and symbolic execution. Ensemble fuzzing allows testers to execute multiple fuzzers with varying heuristics in a single campaign, while maintaining an architecture for synchroni...
Dealer Leads leaves 413GB of data publicly accessible
Cobalt Dickens continues its long-running quest for data
As a summer intern at Trail of Bits, I’ve been working on building Fennec, a tool to automatically replace function calls in compiled binaries that’s built on top of McSema, a binary lifter developed by Trail of Bits. The Problem Let’s say you have a compiled binary, but you […]
F-Secure warns that users still aren’t patching or choosing strong passwords
Aggressive sextortion emails are being sent to Irish inboxes, threatening to expose people as pedophiles
Recently Coinbase published a well written blog post on how they were under attack. The adversaries exploite Firefox 0-days. Details can be found here. One intersting aspect is the following:
“We have also observed the attackers specifically target cloud services, e.g. gmail and others, via browser...
Study finds 34% of security pros bypass security to get products to market quicker
UNICEF apologizes after leaking personal info of 8000 online learners
KLEE-Native, a fork of KLEE that operates on binary program snapshots by lifting machine code to LLVM bitcode.
Redscan data shows rising interest in SIEM, threat hunting, zero trust and more
Regulation slips worryingly down priority list for many firms