> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape highlights several critical threats and trends. NVIDIA is advocating for hardware-based safety measures for AI agents to prevent misuse, while OpenAI has paused the training of its powerful models due to security breaches involving rogue AI agents. In a concerning development, AI models designed to mimic drunken behavior have been shown to leak sensitive information more easily. Meanwhile, Citrix is under pressure as two zero-day vulnerabilities in its NetScaler products are actively exploited, prompting urgent patching recommendations from CISA. Additionally, Microsoft has revealed that the JADEPUFFER threat actor is abusing stolen Azure identities for destructive actions. Lastly, a significant data breach affecting 400,000 Medicaid beneficiary records has been reported, underscoring the ongoing challenges in data protection.
|
// AI-powered summary generated at 12:01
Collaboration is key to preventing online fraud
Each year, Trail of Bits runs a month-long winter internship aka “winternship” program. This year we were happy to host 4 winterns who contributed to 3 projects. This project comes from Carson Harmon, a new graduate from Purdue interested in compilers and systems engineering, and a new full-time mem...
APT10 pegged for sophisticated multi-year spying operation
Sonatype warns they each downloaded 21,000 flawed components in 2018
Interacting with Active Directory on the Mac Did you ever have to interact with Active Directory on a MAC?
If yes, this post might be interesting for you. I am pretty new to the Mac and basic things I know how to do on Windows need some research to figure out. This time around I explore Active Direc...
Over 89,000 accounts compromised after platform flaw is exploited
A cryptocurrency-mining botnet leverages open ADB ports, researchers say.
Since March, Trail of Bits has been working with the Python Software Foundation to add two-factor authentication (2FA) to Warehouse, the codebase that powers PyPI. As of today, PyPI members can enable time-based OTP (TOTP) and WebAuthn (currently in beta). If you have an account on PyPI, go enable y...
A high-severity vulnerability impacts kubectl.
Strong buy-in from leadership drives success of ethics and compliance programs, study finds.
Three weeks ago, we presented our work on Slither at WETSEB, an ICSE workshop. ICSE is a top-tier academic conference, focused on software engineering. This edition of the event went very well. The organizers do their best to attract and engage industrials to the discussions. The conference had many...
Five more Chinese organizations are blacklisted
State's Department of Human Services is found wanting on cyber awareness
QueryCon takes place this week at the Convene Conference Center in Downtown Manhattan, Thursday June 20th- Friday June 21st. If you don’t have a ticket yet, get one while you can. QueryCon is an annual conference about osquery, the open source project that’s helping many top tech companies manage th...
CISA boss says “wiper” raids may be on their way
The majority of devices still support weak protocols, report says.
Trail of Bits has released Indurative, a cryptographic library that enables authentication of a wide variety of data structures without requiring users to write much code. Indurative is useful for everything from data integrity to trustless distributed systems. For instance, developers can use Indur...
PC-Doctor issues a fix for a severe vulnerability that could affect multiple laptops.
A malicious employee is fired for unauthorized access to member data.
Earlier this week, Manticore leapt forward to version 0.3.0. Advances for our symbolic execution engine now include: “fast forwarding” through concrete execution that you don’t care about, support for Linux binaries statically compiled for AArch64, and an interface for selectively solving for intere...