> TODAY'S SUMMARY (107 articles)
Today's cybersecurity landscape highlights several significant threats and trends. The FBI is dealing with a potential data breach affecting agents' personal information, while the ShinyHunters group has intensified its activities, targeting vulnerabilities in Oracle PeopleSoft and creating risks for the FBI. Meanwhile, Citrix NetScaler is facing critical zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772), which are actively exploited, prompting urgent patching recommendations from CISA. In cloud security, the JadePuffer ransomware operator is utilizing AI-driven attacks to compromise Azure environments, leading to the destruction of cloud resources. Additionally, a recent report indicates that over 80,000 organizations have suffered stolen AI logins, raising concerns about the operationalization of AI in cybercrime. Lastly, a $387.5 million breach at Bitget has highlighted ongoing vulnerabilities in cryptocurrency exchanges.
|
// AI-powered summary generated at 16:00
We are proud to announce the integration of ensemble fuzzing into DeepState, our unit-testing framework powered by fuzzing and symbolic execution. Ensemble fuzzing allows testers to execute multiple fuzzers with varying heuristics in a single campaign, while maintaining an architecture for synchroni...
Government-backed Cyber Discovery program has launched across the UK
French consulting firm Aliznet left Elasticsearch database unsecured
As a summer intern at Trail of Bits, I’ve been working on building Fennec, a tool to automatically replace function calls in compiled binaries that’s built on top of McSema, a binary lifter developed by Trail of Bits. The Problem Let’s say you have a compiled binary, but you […]
Teletext Holidays gaffe compromised over 200,000 audio files
Concerns that Beijing could abuse access to corporate data feeds
Recently Coinbase published a well written blog post on how they were under attack. The adversaries exploite Firefox 0-days. Details can be found here. One intersting aspect is the following:
“We have also observed the attackers specifically target cloud services, e.g. gmail and others, via browser...
Unknown number of customers had personal data compromised
FOI request reveals email security challenges
KLEE-Native, a fork of KLEE that operates on binary program snapshots by lifting machine code to LLVM bitcode.
Another U.S. municipality wants to ban facial recognition technology
Google researchers have detected a sustained zero-day attack on Apple iOs devices.
We open-sourced a set of static analysis tools, KRFAnalysis, that analyze and triage output from our system call (syscall) fault injection tool KRF. Now you can easily figure out where and why, KRF crashes your programs. During my summer internship at Trail of Bits, I worked on KRF, […]
India announces plan to issue its seafarers with biometric identity cards.
Trend Micro mid-year report warns of growing efforts to keep attacks hidden
During my summer at Trail of Bits, I took full advantage of the latest C++ language features to build a new SQLite wrapper from scratch that is easy to use, lightweight, high performant, and concurrency friendly—all in under 750 lines of code.
Talented researchers benefit from bug bounty pay-outs
Google says it will not be able to supply flagship Mate 30
No one should beat your security team on the homefield! For several years I have been using the term Homefield Advantage in the context of running a security program, especially in regards to certain aspects of red teaming. Homefield Advantage describes well what a mature security program has to rea...
Cyber-criminals pose as job seekers to deliver Quasar RAT.