[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (107 articles)

|

// AI-powered summary generated at 16:00

> Monroe College Campuses Downed by Ransomware
The attacker has reportedly demanded $2 million to decrypt the files.
> Nearly 20% of Organizations Still Run Windows 7
Only six months remain until the end of Windows 7 support.
> On LibraBFT’s use of broadcasts
LibraBFT is the Byzantine Fault Tolerant (BFT) consensus algorithm used by the recently released Libra cryptocurrency. LibraBFT is based on another BFT consensus algorithm called HotStuff. While some have noted the similarities between the two algorithms, they differ in some crucial respects. In thi...
> Chinese Software Engineer Accused of US IP Theft
Man stole source code before moving back to China, indictment alleges
> Japanese Exchange Bitpoint Hit By $32m Cyber-Attack
Firm suspends services after notifying authorities
> Seriously, stop using RSA
Here at Trail of Bits we review a lot of code. From major open source projects to exciting new proprietary software, we’ve seen it all. But one common denominator in all of these systems is that for some inexplicable reason people still seem to think RSA is a good cryptosystem to use. Let me save […...
> Facebook Set For Record $5bn FTC Fine
Social network penalized after Cambridge Analytica scandal
> Attacks in Turkey Used Excel Formula Injection
Malicious spam attacks on Turkish organizations flew under the radar.
> BashSpray - Simple Password Spray Bash Script
One thing every red team should attempt early on and regularly is to perform some password spray testing across their organization to identify and help remediate usage of weak passwords. In the past I have done this on Windows a lot, but now I built a simple version for it for Bash to run it also fr...
> Hacked Hair Straightener Could Set a Fire
Researchers hack a Bluetooth Glamoriser hair straightener.
> Healthcare Organizations Too Confident in Cybersecurity
Healthcare organizations rely on basic authentication methods, report finds.
> Avoiding Smart Contract “Gridlock” with Slither
A denial-of-service (DoS) vulnerability, dubbed ‘Gridlock,’ was publicly reported on July 1st in one of Edgeware’s smart contracts deployed on Ethereum. As much as $900 million worth of Ether may have been processed by this contract. Edgeware has since acknowledged and fixed the “fatal bug.” When we...
> ZTE Aims to Win Over EU Lawmakers With New Lab
Facility will enable regulators to conduct testing and reviews
> Sea Turtle DNS Hijackers Go After More Victims
Cisco Talos reveals new targets and techniques in ongoing campaign
> State of the Art Proof-of-Work: RandomX
RandomX is a new ASIC and GPU-resistant proof-of-work (PoW) algorithm originally developed for Monero, but potentially useful in any blockchain using PoW that wants to bias towards general purpose CPUs. Trail of Bits was contracted by Arweave to review this novel algorithm in a two person-week engag...
> Apple Disables Walkie-Talkie App Over Privacy Concerns
Users of watchOS function could potentially eavesdrop on others
> Kiosk Vulnerability Puts Customer Data at Risk
Vulnerability in widely used kiosk software could give attacker access to cloud database.
> Siderophile: Expose your Crate’s Unsafety
Today we released a tool, siderophile, that helps Rust developers find fuzzing targets in their codebases. Siderophile trawls your crate’s dependencies and attempts to finds every unsafe function, expression, trait method, etc. It then traces these up the callgraph until it finds the function in you...
> Buhtrap Group Using Zero-Day Attack in Windows
Researchers discover zero-day used in targeted attacks in Eastern Europe.
> Flaw in GE Anesthesia and Respiratory Devices
Vulnerability could allow an attacker to send remote commands.