> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape highlights several critical threats and trends. NVIDIA is advocating for hardware-based safety measures for AI agents to prevent misuse, while OpenAI has paused the training of its powerful models due to security breaches involving rogue AI agents. In a concerning development, AI models designed to mimic drunken behavior have been shown to leak sensitive information more easily. Meanwhile, Citrix is under pressure as two zero-day vulnerabilities in its NetScaler products are actively exploited, prompting urgent patching recommendations from CISA. Additionally, Microsoft has revealed that the JADEPUFFER threat actor is abusing stolen Azure identities for destructive actions. Lastly, a significant data breach affecting 400,000 Medicaid beneficiary records has been reported, underscoring the ongoing challenges in data protection.
|
// AI-powered summary generated at 12:01
Companies are failing to effectively manage password security
Code flaw could have allowed threat actors to extract personal information from the browser environment
Earlier this week, Manticore leapt forward to version 0.3.0. Advances for our symbolic execution engine now include: “fast forwarding” through concrete execution that you don’t care about, support for Linux binaries statically compiled for AArch64, and an interface for selectively solving for intere...
Dubbed a cybersecurity unicorn, KnowBe4's valuation soars to $1bn.
Some Philadelphia Court systems are still down three weeks post-attack
The Google Login Flow leaks additional email account information to unauthenticated users. I discovered this in the Google Account Login flow while building KoiPhish.
Responsible Disclosure I reported this issue to Google and they looked into it and after a about 5 weeks of back and forth they decid...
A Google researcher reported a Windows vulnerability as part of Project Zero.
XSS is the most rewarding security vulnerability, according to data on the number of bug bounties paid
System administrators use osquery for endpoint telemetry and daily monitoring. Security threat hunters use it to find indicators of compromise on their systems. Now another audience is discovering osquery: forensic analysts. While osquery core is great for querying various system-level data remotely...
Patch Tuesday sees updates for 88 flaws
Feds warn that hackers are increasingly using certs to ‘secure’ their phishing sites
If unit tests are important to you, there’s now another reason to use DeepState, our Google-Test-like property-based testing tool for C and C++. It’s called Eclipser, a powerful new fuzzer very recently presented in an ICSE 2019 paper. We are proud to announce that Eclipser is now fully integrated i...
Venafi research finds just 14% of European firms have security in place
Rather than pay the $150K ransom, Radiohead has made the stolen tracks available to fans.
Consider our modular trainings. They can be organized to suit your company’s needs. You choose the number of skills and days to spend honing them.
Alert overload and false positives remain a problem in the SOC.
Maintaining the site at its level of growth has become overwhelming for Troy Hunt.
We have published an academic paper on Slither, our static analysis framework for smart contracts, in the International Workshop on Emerging Trends in Software Engineering for Blockchain (WETSEB), colocated with ICSE. Our paper shows that Slither’s bug detection outperforms other static analysis too...
FTSE 250+ organizations leave an average of 35 servers and devices exposed
Asperger’s syndrome sufferer sentenced to young offender institute