> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape highlights several critical threats and trends. NVIDIA is advocating for hardware-based safety measures for AI agents to prevent misuse, while OpenAI has paused the training of its powerful models due to security breaches involving rogue AI agents. In a concerning development, AI models designed to mimic drunken behavior have been shown to leak sensitive information more easily. Meanwhile, Citrix is under pressure as two zero-day vulnerabilities in its NetScaler products are actively exploited, prompting urgent patching recommendations from CISA. Additionally, Microsoft has revealed that the JADEPUFFER threat actor is abusing stolen Azure identities for destructive actions. Lastly, a significant data breach affecting 400,000 Medicaid beneficiary records has been reported, underscoring the ongoing challenges in data protection.
|
// AI-powered summary generated at 12:01
Here at Trail of Bits we review a lot of code. From major open source projects to exciting new proprietary software, we’ve seen it all. But one common denominator in all of these systems is that for some inexplicable reason people still seem to think RSA is a good cryptosystem to use. Let me save […...
Beaming data reveals IoT and file-sharing services are most targeted
Half of orgs plan to increase anti-fraud tech budgets over next two years
One thing every red team should attempt early on and regularly is to perform some password spray testing across their organization to identify and help remediate usage of weak passwords.
In the past I have done this on Windows a lot, but now I built a simple version for it for Bash to run it also fr...
Airline appeals after ICO takes action
Forensic services provider decides to pay ransom after June cyber-attack
A denial-of-service (DoS) vulnerability, dubbed ‘Gridlock,’ was publicly reported on July 1st in one of Edgeware’s smart contracts deployed on Ethereum. As much as $900 million worth of Ether may have been processed by this contract. Edgeware has since acknowledged and fixed the “fatal bug.” When we...
Survey of IT pros conducted by Gurucul highlights risks from insider threats
Cryptomining campaign propagates using seven different methods
RandomX is a new ASIC and GPU-resistant proof-of-work (PoW) algorithm originally developed for Monero, but potentially useful in any blockchain using PoW that wants to bias towards general purpose CPUs. Trail of Bits was contracted by Arweave to review this novel algorithm in a two person-week engag...
Bradford will bring over 30 years of marketing and operations experience
Users were shown grey boxes with text describing what was in the image
Today we released a tool, siderophile, that helps Rust developers find fuzzing targets in their codebases. Siderophile trawls your crate’s dependencies and attempts to finds every unsafe function, expression, trait method, etc. It then traces these up the callgraph until it finds the function in you...
A 30-minute outage resulted in traffic to Cloudflare's sites dropping to 82%
The attack was detected and resolved within half an hour
With the release of C++14, the standards committee strengthened one of the coolest modern features of C++: constexpr. Now, C++ developers can write constant expressions and force their evaluation at compile-time, rather than at every invocation by users. This results in faster execution, smaller exe...
Barracuda Networks has found that organizations are still not putting email security high on their priority list.
Slack doesn't have end-to-end encryption, which could be the downfall of the customers its trying to attract
A common Go idiom is to (1) panic, (2) recover from the panic in a deferred function, and (3) continue on. In general, this is okay, so long there are no global state changes between the entry point to the function calling defer, and the point at which the panic occurs. Such global state changes […]
Nearly a third of people in the UK prefer to use passwords over biometric credentials