> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
Capita study finds only half of firms even allow BYOD
This year’s IACR Crypto conference was an excellent blend of far-out theory and down-to-earth pragmatism. A major theme throughout the conference was the huge importance of getting basic cryptographic primitives right. Systems ranging from TLS servers and bitcoin wallets to state-of-the-art secure m...
Relatively light load still includes some critical bugs
The fightback begins as Operation reWired is revealed
De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.
McDonald's buys Apprente as part of plan to use AI voice assistants in drive-thrus
Trend Micro has detected a sharp increase in the monetization of hacked IoT devices
We are proud to announce the integration of ensemble fuzzing into DeepState, our unit-testing framework powered by fuzzing and symbolic execution. Ensemble fuzzing allows testers to execute multiple fuzzers with varying heuristics in a single campaign, while maintaining an architecture for synchroni...
Baton Rouge is getting a new $1.5 million cybersecurity training and operations center
What paths can leaders take to successfully manage challenging conversations?
As a summer intern at Trail of Bits, I’ve been working on building Fennec, a tool to automatically replace function calls in compiled binaries that’s built on top of McSema, a binary lifter developed by Trail of Bits. The Problem Let’s say you have a compiled binary, but you […]
What companies need to learn about a malware attack such as NotPetya
How the shipping giant reacted to the devastating NotPetya malware attack
Recently Coinbase published a well written blog post on how they were under attack. The adversaries exploite Firefox 0-days. Details can be found here. One intersting aspect is the following:
“We have also observed the attackers specifically target cloud services, e.g. gmail and others, via browser...
Proofpoint urges organizations to improve human-centric security
The top ten security projects for 2019 now include container security and BEC
KLEE-Native, a fork of KLEE that operates on binary program snapshots by lifting machine code to LLVM bitcode.
Default setting could improve privacy and security protections
Car parts maker was tricked into wiring four billion yen
We open-sourced a set of static analysis tools, KRFAnalysis, that analyze and triage output from our system call (syscall) fault injection tool KRF. Now you can easily figure out where and why, KRF crashes your programs. During my summer internship at Trail of Bits, I worked on KRF, […]