[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> US Launches Major Effort to Disrupt North Korean Botnet
FBI notifies victims of Joanap malware
> Airbus Staff Caught in Data Breach
Unauthorized access incident affected commercial aircraft business
> Symbolic Path Merging in Manticore
Each year, Trail of Bits runs a month-long winter internship “winternship” program. This year we were happy to host 4 winterns who contributed to 3 projects. This is the first in a series of blog posts covering the 2019 Wintern class. Our first report is from Vaibhav Sharma (@vbsharma), a PhD studen...
> New UK Fraud Rules Set to Empower Victims
Consumers can now complain to the fraudster's bank
> Third-Party Breaches Plague Multiple Industries
Discover, Allen Chern and Verity Medical Foundation report unauthorized third-party access to customer data.
> Fuzzing an API with DeepState (Part 2)
Alex Groce, Associate Professor, School of Informatics, Computing and Cyber Systems, Northern Arizona University Mutation Testing Introducing one bug by hand (as we did in Part 1) is fine, and we could try it again, but “the plural of anecdote is not data.” However, this is not strictly true. If we...
> 65 Fortune 100s Downloaded Flawed Apache Struts
The vulnerability exploited in Equifax breach is still being used nearly two years later.
> Digital Growth Exposes Firms to Complexity and Threats
Almost all IT executives feel vulnerable to attack, according to Thales
> Fuzzing an API with DeepState (Part 1)
Alex Groce, Associate Professor, School of Informatics, Computing and Cyber Systems, Northern Arizona University Using DeepState, we took a handwritten red-black tree fuzzer and, with minimal effort, turned it into a much more fully featured test generator. The DeepState fuzzer, despite requiring no...
> Global Ransomware Attack Could Cost $193 Billion
New cyber risk report paints doomsday scenario
> Global Police Close Notorious Online Marketplace
The xDedic site enabled an illegal trade in server credentials
> How McSema Handles C++ Exceptions
C++ programs using exceptions are problematic for binary lifters. The non-local control-flow “throw” and “catch” operations that appear in C++ source code do not map neatly to straightforward binary representations. One could allege that the compiler, runtime, and stack unwinding library collude to...
> Largest DDoS Attack Sent Over 500 Million Packets per Second
Last year's DDoS attack at GitHub, surpasses all previous attacks, says Imperva.
> Info-Stealing FormBook Returns in New Campaign
Underground hacking forums recommend a new version of FormBook for hosting and serving malware.
> Empire Hacking: Ethereum Edition 2
On December 12, over 150 attendees joined a special, half-day Empire Hacking to learn about pitfalls in smart contract security and how to avoid them. Thank you to everyone who came, to our superb speakers, and to BuzzFeed for hosting this meetup at their office. Watch the presentations again It’s h...
> Attackers Exploit Zero-Day in WordPress Plugin
Total Donations was abandoned by its developers, leaving little hope for a fix.
> Group FaceTime Disabled While Apple Works on Fix
Using FaceTime today won't keep eavesdroppers away.
> How to write a rootkit without really trying
We open-sourced a fault injection tool, KRF, that uses kernel-space syscall interception. You can use it today to find faulty assumptions (and resultant bugs) in your programs. Check it out! This post covers intercepting system calls from within the Linux kernel, via a plain old kernel module. We’ll...
> UK Government Pledges Security Skills and R&D Funding
Wants nation to be a leader in hardware security
> US Turns Up Heat on Huawei with 23-Count Indictments
DoJ alleges Chinese firm stole trade secrets and tricked banks into breaking sanctions