[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (51 articles)

|

// AI-powered summary generated at 12:01

> UK Orgs Lose 2 & 1/2 Months a Year on Poor Password Management
Companies are failing to effectively manage password security
> “Major Flaw” Discovered in Evernote’s Chrome Extension
Code flaw could have allowed threat actors to extract personal information from the browser environment
> Announcing Manticore 0.3.0
Earlier this week, Manticore leapt forward to version 0.3.0. Advances for our symbolic execution engine now include: “fast forwarding” through concrete execution that you don’t care about, support for Linux binaries statically compiled for AArch64, and an interface for selectively solving for intere...
> KnowBe4 Gets Whopping $300m in Funding
Dubbed a cybersecurity unicorn, KnowBe4's valuation soars to $1bn.
> Philly Courts Still Down After Cyber-Attack
Some Philadelphia Court systems are still down three weeks post-attack
> Google Leaks Your Alternate Email Addresses to Unauthenticated Users
The Google Login Flow leaks additional email account information to unauthenticated users. I discovered this in the Google Account Login flow while building KoiPhish. Responsible Disclosure I reported this issue to Google and they looked into it and after a about 5 weeks of back and forth they decid...
> Flaw in SymCrypt Can Trigger DDoS
A Google researcher reported a Windows vulnerability as part of Project Zero.
> XSS is Most Rewarding Bug Bounty as CSRF is Revived
XSS is the most rewarding security vulnerability, according to data on the number of bug bounties paid
> Using osquery for remote forensics
System administrators use osquery for endpoint telemetry and daily monitoring. Security threat hunters use it to find indicators of compromise on their systems. Now another audience is discovering osquery: forensic analysts. While osquery core is great for querying various system-level data remotely...
> Microsoft Fixes Four SandboxEscaper Zero-Days
Patch Tuesday sees updates for 88 flaws
> FBI: Don’t Trust HTTPS or Padlock on Websites
Feds warn that hackers are increasingly using certs to ‘secure’ their phishing sites
> Fuzzing Unit Tests with DeepState and Eclipser
If unit tests are important to you, there’s now another reason to use DeepState, our Google-Test-like property-based testing tool for C and C++. It’s called Eclipser, a powerful new fuzzer very recently presented in an ICSE 2019 paper. We are proud to announce that Eclipser is now fully integrated i...
> Code Signing Shortcomings Leave Gaps for Hackers
Venafi research finds just 14% of European firms have security in place
> Radiohead Officially Releases Music Stolen in Hack
Rather than pay the $150K ransom, Radiohead has made the stolen tracks available to fans.
> Announcing Automated Reverse Engineering Trainings
Consider our modular trainings. They can be organized to suit your company’s needs. You choose the number of skills and days to spend honing them.
> SOCs Struggle with Staffing, Reporting and Visibility
Alert overload and false positives remain a problem in the SOC.
> HaveIBeenPwned.com Open to Acquisition
Maintaining the site at its level of growth has become overwhelming for Troy Hunt.
> Slither: The Leading Static Analyzer for Smart Contracts
We have published an academic paper on Slither, our static analysis framework for smart contracts, in the International Workshop on Emerging Trends in Software Engineering for Blockchain (WETSEB), colocated with ICSE. Our paper shows that Slither’s bug detection outperforms other static analysis too...
> FTSE 250+ Demonstrate Weak Security, But Low SMB Exposure
FTSE 250+ organizations leave an average of 35 servers and devices exposed
> Welsh Man Gets Four Years for TalkTalk Attack
Asperger’s syndrome sufferer sentenced to young offender institute