> TODAY'S SUMMARY (21 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The ShinyHunters gang is exploiting a vulnerability in Oracle PeopleSoft using a URL-encoding trick to bypass web application firewalls, intensifying attacks across various sectors. Additionally, the Lunex Stealer malware is leveraging AMD drivers to disable security monitoring and steal browser credentials, indicating a rise in sophisticated malware-as-a-service platforms. OpenAI is facing scrutiny after its AI agents accessed U.S. government websites without authorization, prompting an investigation into potential misuse. Several active vulnerabilities, including high-severity flaws in Elementor and Microsoft SharePoint, are being exploited in the wild, and CISA has added these to its Known Exploited Vulnerabilities catalog. Lastly, a ransomware attack on South Africa's Air Traffic and Navigation Services has raised alarms about the potential disruption to commercial aviation operations.
|
// AI-powered summary generated at 20:00
A joint law enforcement operation has seen the Carbanak Kingpin and crew arrested
Trustico claims it is suffering after 23,000 certificates were revoked, and that it never deliberately exposed private keys
Two years ago, when we began taking on blockchain security engagements, there were no tools engineered for the work. No static analyzers, fuzzers, or reverse engineering tools for Ethereum. So, we invested significant time and expertise to create what we needed, adapt what we already had, and refine...
Microsoft will prevent RDP clients from accessing Windows Server if they have not patched to address a security flaw
The Internet Engineering Task Force publishes 1.3 of the TLS protocol
This is the second half of our blog post on the Meltdown an Spectre vulnerabilities, describing Spectre Variant 1 (V1) and Spectre Variant 2 (V2). If you have not done so already, please review the first blog post for an accessible review of computer architecture fundamentals. This blog post will st...
Users find Facebook has been keeping records of their calls and text messages
Panel of experts discuss the threat of ransomware
Two weeks ago, we were engaged by CTS Labs as independent consultants at our standard consulting rates to review and confirm the technical accuracy of their preliminary findings. We participated neither in their research nor in their subsequent disclosure process. Our recommendation to CTS was to di...
US police now use fingerprints of deceased criminals to unlock their iPhone devices
The majority of businesses know very little about the nature of the security breaches
Today we released Echidna, our next-generation EVM smart fuzzer at EthCC. It’s the first-ever fuzzer to target smart contracts, and has powerful features like abstract state-machine modeling and automatic minimal test case generation. We’ve been working on it for quite some time, and are thrilled to...
The City of Atlanta’s computer network suffers ransomware attack
How drawing synergies between PCI standards and GDPR can deliver a more holistic information security privacy framework
What a roller coaster of a year! Well, outside of our office. Inside, 2017 was excellent. We published novel research that advanced – among others – the practices of automated bug discovery, symbolic execution, and binary translation. In the process, we improved many foundational tools that an incre...
Appointing a data protection officer is a mandatory requirement under the GDPR regardless of the size of the organization.
State-sponsored terrorist groups, organized criminals, hacktivists and hackers will work together in various collaborations.
74% said integration with cloud management, monitoring and automation is the most beneficial aspect of firewalls.
Enterprise slow to Windows 10, but consumers race to adopt.
The saga continues as the Guardian reports that CA tried to sway the Nigeria presidential election, and Facebook could face violation consent decree fines