> TODAY'S SUMMARY (107 articles)
Today's cybersecurity landscape highlights several significant threats and trends. The FBI is dealing with a potential data breach affecting agents' personal information, while the ShinyHunters group has intensified its activities, targeting vulnerabilities in Oracle PeopleSoft and creating risks for the FBI. Meanwhile, Citrix NetScaler is facing critical zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772), which are actively exploited, prompting urgent patching recommendations from CISA. In cloud security, the JadePuffer ransomware operator is utilizing AI-driven attacks to compromise Azure environments, leading to the destruction of cloud resources. Additionally, a recent report indicates that over 80,000 organizations have suffered stolen AI logins, raising concerns about the operationalization of AI in cybercrime. Lastly, a $387.5 million breach at Bitget has highlighted ongoing vulnerabilities in cryptocurrency exchanges.
|
// AI-powered summary generated at 16:00
A financially motivated threat group continues to adapt its tools.
Lancaster University confirms it was hit by sophisticated and malicious phishing attack
Cela devient de fait le rendez-vous français de la rentrée sur le sujet de la cybersécurité industrielle, avec une participation croissante chaque année.
Les inscriptions sont ouvertes pour cette journée qui se déroulera le 26 septembre [...] Lire la suite
Iranian-linked APT34 is reportedly behind a malicious phishing campaign on LinkedIn.
Orgs failing on privileged access security strategies
Trail of Bits recently completed a security assessment of Kubernetes, including its interaction with Docker. Felix Wilhelm’s recent tweet of a Proof of Concept (PoC) “container escape” sparked our interest, since we performed similar research and were curious how this PoC could impact Kubernetes. Qu...
A Rapid7 report reveals the most common external and internal weaknesses present in companies.
Under-fire Chinese tech giant could be in more hot water
Trail of Bits was among the select companies that Forrester invited to participate in its recent report, The Forrester Wave™: Midsize Cybersecurity Consulting Services, Q2 2019. In this evaluation, Trail of Bits was cited as a Leader. We received the highest score among all participants in the curre...
Latest study finds global average for losses creeps up to $3.92m
Hackers posted a series of bizarre messages
LibraBFT is the Byzantine Fault Tolerant (BFT) consensus algorithm used by the recently released Libra cryptocurrency. LibraBFT is based on another BFT consensus algorithm called HotStuff. While some have noted the similarities between the two algorithms, they differ in some crucial respects. In thi...
Asia Pacific and Japanese governments are enabling law enforcement to monitor citizen behavior, says Charity Wright.
The information-stealing TrickBot Trojan is disguised as Chrome and Firefox browser updates.
Here at Trail of Bits we review a lot of code. From major open source projects to exciting new proprietary software, we’ve seen it all. But one common denominator in all of these systems is that for some inexplicable reason people still seem to think RSA is a good cryptosystem to use. Let me save […...
The total settlement payout could be as much as $700 million.
Harald Martin III said to have wilfully retained defense information
One thing every red team should attempt early on and regularly is to perform some password spray testing across their organization to identify and help remediate usage of weak passwords.
In the past I have done this on Windows a lot, but now I built a simple version for it for Bash to run it also fr...
Hackers scanned for vulnerable organizations
Major compromise lifts lid on secretive Kremlin projects