[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (107 articles)

|

// AI-powered summary generated at 16:00

> DeepState Now Supports Ensemble Fuzzing
We are proud to announce the integration of ensemble fuzzing into DeepState, our unit-testing framework powered by fuzzing and symbolic execution. Ensemble fuzzing allows testers to execute multiple fuzzers with varying heuristics in a single campaign, while maintaining an architecture for synchroni...
> Teen Cybersecurity Training Program Returns For Third Year
Government-backed Cyber Discovery program has launched across the UK
> Data Leak Hits 2.5 Million Customers of Cosmetics Giant Yves Rocher
French consulting firm Aliznet left Elasticsearch database unsecured
> Rewriting Functions in Compiled Binaries
As a summer intern at Trail of Bits, I’ve been working on building Fennec, a tool to automatically replace function calls in compiled binaries that’s built on top of McSema, a binary lifter developed by Trail of Bits. The Problem Let’s say you have a compiled binary, but you […]
> Privacy Snafu Exposes UK Holidaymakers’ Data for Three Years
Teletext Holidays gaffe compromised over 200,000 audio files
> China’s Social Credit System Raises Data Security Fears
Concerns that Beijing could abuse access to corporate data feeds
> Coinbase under attack and cookie theft
Recently Coinbase published a well written blog post on how they were under attack. The adversaries exploite Firefox 0-days. Details can be found here. One intersting aspect is the following: “We have also observed the attackers specifically target cloud services, e.g. gmail and others, via browser...
> PDF Reader Biz Breached: Foxit Forces Password Reset
Unknown number of customers had personal data compromised
> MPs Bombarded by Spam as Brexit No Deal Nears
FOI request reveals email security challenges
> Binary symbolic execution with KLEE-Native
KLEE-Native, a fork of KLEE that operates on binary program snapshots by lifting machine code to LLVM bitcode.
> Municipal Government Calls For Facial Recognition Ban
Another U.S. municipality wants to ban facial recognition technology
> Hack Exploited Apple Users for Two Years
Google researchers have detected a sustained zero-day attack on Apple iOs devices.
> Reverse Taint Analysis Using Binary Ninja
We open-sourced a set of static analysis tools, KRFAnalysis, that analyze and triage output from our system call (syscall) fault injection tool KRF. Now you can easily figure out where and why, KRF crashes your programs. During my summer internship at Trail of Bits, I worked on KRF, […]
> Biometric ID Cards Ahoy!
India announces plan to issue its seafarers with biometric identity cards.
> Fileless Malware Detections Soar 265% in 2019
Trend Micro mid-year report warns of growing efforts to keep attacks hidden
> Wrapper’s Delight
During my summer at Trail of Bits, I took full advantage of the latest C++ language features to build a new SQLite wrapper from scratch that is easy to use, lightweight, high performant, and concurrency friendly—all in under 750 lines of code.
> HackerOne Announces Five New $1m White Hats
Talented researchers benefit from bug bounty pay-outs
> Huawei Faces Android Blackout on 5G Smartphone
Google says it will not be able to supply flagship Mate 30
> Cybersecurity - Homefield Advantage
No one should beat your security team on the homefield! For several years I have been using the term Homefield Advantage in the context of running a security program, especially in regards to certain aspects of red teaming. Homefield Advantage describes well what a mature security program has to rea...
> Phishing Campaign Hides Malware in Resumes
Cyber-criminals pose as job seekers to deliver Quasar RAT.