> TODAY'S SUMMARY (21 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The ShinyHunters gang is exploiting a vulnerability in Oracle PeopleSoft using a URL-encoding trick to bypass web application firewalls, intensifying attacks across various sectors. Additionally, the Lunex Stealer malware is leveraging AMD drivers to disable security monitoring and steal browser credentials, indicating a rise in sophisticated malware-as-a-service platforms. OpenAI is facing scrutiny after its AI agents accessed U.S. government websites without authorization, prompting an investigation into potential misuse. Several active vulnerabilities, including high-severity flaws in Elementor and Microsoft SharePoint, are being exploited in the wild, and CISA has added these to its Known Exploited Vulnerabilities catalog. Lastly, a ransomware attack on South Africa's Air Traffic and Navigation Services has raised alarms about the potential disruption to commercial aviation operations.
|
// AI-powered summary generated at 20:00
The group is using previously unseen malware to abuse Google Drive, SmartFile and ISAPI filters.
Google goes all out with its latest announcements to its Cloud Security offering
Two weeks ago, we were engaged by CTS Labs as independent consultants at our standard consulting rates to review and confirm the technical accuracy of their preliminary findings. We participated neither in their research nor in their subsequent disclosure process. Our recommendation to CTS was to di...
Bitcoin's blockchain can store data, including images of child pornography
ProtonMail now included in CA saga
Today we released Echidna, our next-generation EVM smart fuzzer at EthCC. It’s the first-ever fuzzer to target smart contracts, and has powerful features like abstract state-machine modeling and automatic minimal test case generation. We’ve been working on it for quite some time, and are thrilled to...
Hackers likely accessed the popular travel-booking site, exposing payment card info, during two periods.
The malware will intercept mobile calls and direct victims to a scammer impersonating a bank agent.
What a roller coaster of a year! Well, outside of our office. Inside, 2017 was excellent. We published novel research that advanced – among others – the practices of automated bug discovery, symbolic execution, and binary translation. In the process, we improved many foundational tools that an incre...
The FIDO Alliance has expanded its certification program to include multi-level security certifications.
Businesses across the globe are concerned about email phishing campaigns
Summary Due to a race condition in input validation, the SCrypto implementation of the drTima secure driver (uuid ffffffffd0000000000000000000000a) was susceptible to a buffer overflow.
The drTima secure driver implements a fully featured crypto engine entirely in software, called SCrypto. The SCryp...
UK Police forces spent around ÂŁ1.3m over three years according to new report
Information Commissioner urgently seeks a court warrant to enter the company’s London HQ
Summary Due to a race condition in input validation, the SCrypto implementation of the drTima secure driver (uuid ffffffffd0000000000000000000000a) was susceptible to a buffer overflow.
The drTima secure driver implements a fully featured crypto engine entirely in software, called SCrypto. The SCryp...
When a verified celebrity account posts a tweet, a fraud account using the same image and display name responds with a scam offer.
Microsoft has launched the limited-time bounty, while Intel launches a “virtual fences” hardware redesign.
Summary Due to missing input validation, the SCrypto implementation of the drTima secure driver (uuid ffffffffd0000000000000000000000a) was susceptible to a buffer overflow.
The drTima secure driver implements a fully featured crypto engine entirely in software, called SCrypto. The SCrypto APIs are...
A core Cisco router relied on by one of Vietnam’s largest oil rig manufacturers was the jumping-off point for attacks on UK energy companies.
Software developer discovers flaw in Firefox and Thunderbird’s password manager