> TODAY'S SUMMARY (21 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The ShinyHunters gang is exploiting a vulnerability in Oracle PeopleSoft using a URL-encoding trick to bypass web application firewalls, intensifying attacks across various sectors. Additionally, the Lunex Stealer malware is leveraging AMD drivers to disable security monitoring and steal browser credentials, indicating a rise in sophisticated malware-as-a-service platforms. OpenAI is facing scrutiny after its AI agents accessed U.S. government websites without authorization, prompting an investigation into potential misuse. Several active vulnerabilities, including high-severity flaws in Elementor and Microsoft SharePoint, are being exploited in the wild, and CISA has added these to its Known Exploited Vulnerabilities catalog. Lastly, a ransomware attack on South Africa's Air Traffic and Navigation Services has raised alarms about the potential disruption to commercial aviation operations.
|
// AI-powered summary generated at 20:00
A new strain of malware that targets vulnerable Linux-based systems is loose in the wild.
Students are more likely to perform crypto-mining personally as they don’t pay for power, the primary cost of crypto-mining.
Two years ago, when we began taking on blockchain security engagements, there were no tools engineered for the work. No static analyzers, fuzzers, or reverse engineering tools for Ethereum. So, we invested significant time and expertise to create what we needed, adapt what we already had, and refine...
While details of how hackers exploited the accounts are still emerging, this appears to be the largest data breach of 2018 to date.
Infosecurity Magazine will be undergoing a system upgrade from Friday 30th March until Sunday 1st April 2018 - more details here
This is the second half of our blog post on the Meltdown an Spectre vulnerabilities, describing Spectre Variant 1 (V1) and Spectre Variant 2 (V2). If you have not done so already, please review the first blog post for an accessible review of computer architecture fundamentals. This blog post will st...
Recorded Future claims Flash was less popular in 2017
Aerospace giant’s South Carolina facility gets a nasty surprise
Two weeks ago, we were engaged by CTS Labs as independent consultants at our standard consulting rates to review and confirm the technical accuracy of their preliminary findings. We participated neither in their research nor in their subsequent disclosure process. Our recommendation to CTS was to di...
Deloitte finds few even update the board
In one case, operators withdrew over $5,000 worth of Monero from one wallet.
Today we released Echidna, our next-generation EVM smart fuzzer at EthCC. It’s the first-ever fuzzer to target smart contracts, and has powerful features like abstract state-machine modeling and automatic minimal test case generation. We’ve been working on it for quite some time, and are thrilled to...
The social network will reward people for reporting misuses of data by app developers.
About half (48%) of legal team respondents in a recent survey claim GDPR is not applicable to their organization.
What a roller coaster of a year! Well, outside of our office. Inside, 2017 was excellent. We published novel research that advanced – among others – the practices of automated bug discovery, symbolic execution, and binary translation. In the process, we improved many foundational tools that an incre...
Businesses still lack the knowhow and resources to defend against data breaches
Social giant joins Facebook and Google
VPN use still patchy, says iPass
Privacy International calls on Home Office to produce guidance
90% cybersecurity professionals confirm they are concerned about cloud security, up 11 percentage points from last year.