[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> Google Survey Finds Two in Three Users Reuse Passwords
More than half of users think their accounts are safer than the average users.
> UK Launches £6m IoT Security Competition
Government is looking for innovative ideas from British firms
> Symbolic Path Merging in Manticore
Each year, Trail of Bits runs a month-long winter internship “winternship” program. This year we were happy to host 4 winterns who contributed to 3 projects. This is the first in a series of blog posts covering the 2019 Wintern class. Our first report is from Vaibhav Sharma (@vbsharma), a PhD studen...
> Huddle House Suffers POS Malware Breach
Customers may have been exposed for over 17 months
> Kids' Smart Watch Recalled Over Security Concerns
European Commission issues RAPEX alert
> Fuzzing an API with DeepState (Part 2)
Alex Groce, Associate Professor, School of Informatics, Computing and Cyber Systems, Northern Arizona University Mutation Testing Introducing one bug by hand (as we did in Part 1) is fine, and we could try it again, but “the plural of anecdote is not data.” However, this is not strictly true. If we...
> Flaw in SS7 Lets Attackers Empty Bank Accounts
UK's Metro Bank falls victim to SS7 attack.
> Speak Up Malware Targets Linux, Mac in New Campaign
New malware injects backdoor Trojan by exploiting known vulnerabilities.
> Fuzzing an API with DeepState (Part 1)
Alex Groce, Associate Professor, School of Informatics, Computing and Cyber Systems, Northern Arizona University Using DeepState, we took a handwritten red-black tree fuzzer and, with minimal effort, turned it into a much more fully featured test generator. The DeepState fuzzer, despite requiring no...
> Alexa 500 Sites Targeted with Adaptive Malware
Hackers attempt to hit major retailers in a malvertising campaign.
> Student Loans Company Hit by One Million Cyber-Attacks
Government body repelled all but one in 2017/18
> How McSema Handles C++ Exceptions
C++ programs using exceptions are problematic for binary lifters. The non-local control-flow “throw” and “catch” operations that appear in C++ source code do not map neatly to straightforward binary representations. One could allege that the compiler, runtime, and stack unwinding library collude to...
> Home Improvement Site Houzz Suffers Data Breach
Customers urged to reset passwords
> ICO Fines Brexit Campaign and Key Backer £120K
Leave.EU and Eldon Insurance broke data protection laws
> Empire Hacking: Ethereum Edition 2
On December 12, over 150 attendees joined a special, half-day Empire Hacking to learn about pitfalls in smart contract security and how to avoid them. Thank you to everyone who came, to our superb speakers, and to BuzzFeed for hosting this meetup at their office. Watch the presentations again It’s h...
> Execs Remain Weak Link in Cybersecurity Chain
Top executives believe security policies and cyber-threats don't apply to them.
> FDD Finds Trump's Cyber Policies Are Sensible
A midterm assessment of Trump's cyber policies finds administration is making effective changes.
> How to write a rootkit without really trying
We open-sourced a fault injection tool, KRF, that uses kernel-space syscall interception. You can use it today to find faulty assumptions (and resultant bugs) in your programs. Check it out! This post covers intercepting system calls from within the Linux kernel, via a plain old kernel module. We’ll...
> Why All Users Should Change Passwords Today
Change Your Password Day is a good time to switch to a password manager.
> Iran APT Group Targets Foreign Embassies
Kaspersky Lab claims group looks more like sysadmins than expert hackers