[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 20:00

> Alleged Insurance Fraudster Arrested After Faking Death
> Black Friday Warning as UK Retailers Fail on 2FA
LastPass claims only Amazon offers customers more secure log-ins
> Return of the Blockchain Security Empire Hacking
Remember last December’s Empire Hacking? The one where we dedicated the event to sharing the best information about blockchain and smart contract security? Let’s do that again, and let’s make it a tradition; a half-day mini conference focused exclusively on a single topic every December. On December...
> #Irisscon: Is Spam Email Defeated or Not?
Has spam email been defeated, or should we admit we cannot beat it?
> #Irisscon: Stop Siloing Vulnerability Management to Deal with Old Bugs
Old vulnerabilities persist, because of how vulnerability management and full stack visibility is done
> Trail of Bits @ Devcon IV Recap
We wanted to make up for missing the first three Devcons, so we participated in this year’s event through a number of talks, a panel, and two trainings. For those of you who couldn’t join us, we’ve summarized our contributions below. We hope to see you there next year. Using Manticore and Symbolic E...
> #Irisscon: Government Needs to Join Irish Cyber Agenda
Irisscon opens with a look back at the last 10 years of the Irish CERT, and a call for better government involvement
> UK Retailers in Website Security Fail
Sectigo research finds just a third have chosen most secure certs
> L’addiction au patch
S’il est nécessaire d’avoir recours aux patchs de sécurité pour protéger vos composants industriels, ils peuvent s’avérer contre productif en amenant à se focaliser sur les vulnérabilités d’un système plutôt que sur des solutions de protection globale. Alors, patch ou [...] Lire la suite
> US Postal Service Exposes 60 Million Users in API Snafu
Error meant anyone with an account could view others’ details
> Amazon ‘Error’ Exposes Countless Customer Emails
Firm under fire for phishy looking email
> Application Development Guidance: Introduction
Guidance for risk assessors, and developers of applications which will be run on devices handling OFFICIAL data.
> Mirai Used as Payload in Hadoop YARN Vulnerability
Mirai was detected attacking non-IoT, targeting unpatched Linux servers.
> Phishers Up Their Game to Combat User Awareness
As users become more aware of threats, phishing campaigns are growing more sophisticated, says Zscaler.
> We crypto now
Building and using cryptographic libraries is notoriously difficult. Even when each component of the system has been implemented correctly (quite difficult to do), improperly combining these pieces can lead to disastrous results. Cryptography, when rolled right, forms the bedrock of any secure appli...
> 13 Malware-Laden Fake Apps on Google Play
A security researcher uses Twitter to warn users about 13 malicious Android apps.
> Magecart Black Hats Battle it Out On Infected Site
One group attempts to sabotage skimming operation of the other
> Online Fraud Losses Set to Hit Nearly $50bn by 2023
Juniper Research warns of rising synthetic ID fraud
> Volume of Suspended UK Domains Doubles Again
Nominet stats reveal another sharp increase in phishing and IP abuse
> Majority of Orgs Unaware of IoT Security Threats
Security is still an Achilles heel in IoT.