[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> How to write a rootkit without really trying
We open-sourced a fault injection tool, KRF, that uses kernel-space syscall interception. You can use it today to find faulty assumptions (and resultant bugs) in your programs. Check it out! This post covers intercepting system calls from within the Linux kernel, via a plain old kernel module. We’ll...
> WEF: Cyber-Attacks a Major Global Risk for Next Decade
Annual report reveals continued concerns over online theft and disruption
> Oklahoma Government Leaks 3TB of Sensitive Data
Publicly accessible data included info on FBI investigations
> On Bounties and Boffins
Trying to make a living as a programmer participating in bug bounties is the same as convincing yourself that you’re good enough at Texas Hold ‘Em to quit your job. There’s data to back this up in Fixing a Hole: The Labor Market for Bugs, a chapter in New Solutions for Cybersecurity, by Ryan Ellis,...
> Researchers Find 87GB Trove of Breached Log-Ins
“Collection #1” dump features over 21m dehashed passwords
> MS Word Documents Spreading .Net RAT Malware
Auto-execution VBA code is able to perform several malicious actions, says FortGuard Labs.
> KoiPhish - The Beautiful Phishing Proxy
KoiPhish is a simple yet beautiful relay proxy idea. The idea for this little project goes back many years. Since I started learning Golang I figured it would be good exercise to finally go ahead an implement it. So, last December during the 35C3 (which is always inspiring congress) I wrote it up. I...
> Fortnite Vulnerable to Account Take-Over Attack
Vulnerabilities could allow hackers full access to user accounts and in-game currency.
> Bugs Rack Web Host Sites and Flight-Booking System
Two independent security researchers disclose vulnerabilities in web hosting platforms and an airline reservation system.
> McPivot and useful LLDB commands
Just a list of useful notes when dealing with Macs. I’m pretty new to Macs and there might be other, better solutions to the challenges I had to sovle but these worked for me and I’m learning. :) Pivoting between accounts and keychain issues After pivoting on a target host and elevating to root it s...
> New Magecart Group Hits Hundreds of Sites Via Supply Chain
Attack targets French ad agency
> Alleged SEC Hackers Charged in Insider Trading Conspiracy
Ukrainian men said to have stolen non-public documents
> What do La Croix, octonions, and Second Life have in common?
This year for CSAW CTF, Trail of Bits contributed two cryptography problems. In the first problem, you could combine two bugs to break DSA much like the Playstation 3 firmware hackers. The other challenge–-weirder and mathier–-was split into two parts: one for the qualifiers, one in finals. This cha...
> IT Teams Have One Year to Move Off Windows 7
UK security experts urge organizations to plan upgrade
> Orgs Slow to Advance IoT Security
IoT security showed incremental improvement in 2018, says Gemalto.
> Fuzzing Like It’s 1989
With 2019 a day away, let’s reflect on the past to see how we can improve. Yes, let’s take a long look back 30 years and reflect on the original fuzzing paper, An Empirical Study of the Reliability of UNIX Utilities, and its 1995 follow-up, Fuzz Revisited, by Barton P. Miller. In this blog post, […]
> City of Del Rio Hit by Ransomware Attack
Del Rio, Texas, is working with the Feds after the city suffered a ransomware attack.
> Shutdown a Threat to IT Security Recruitment
Recruitment of top talent is potentially compromised as government enters into its 25th day of a shutdown.
> $10,000 research fellowships for underrepresented talent
The Trail of Bits SummerCon Fellowship program is now accepting applications from emerging security researchers with excellent project ideas. Fellows will explore their research topics with our guidance and then present their findings at SummerCon 2019. We will be reserving at least 50% of our fundi...
> UK Banks Finally Issue New Cards After Ticketmaster Breach
Suspicious activity was first reported to ticketing firm in April