> TODAY'S SUMMARY (21 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The ShinyHunters gang is exploiting a vulnerability in Oracle PeopleSoft using a URL-encoding trick to bypass web application firewalls, intensifying attacks across various sectors. Additionally, the Lunex Stealer malware is leveraging AMD drivers to disable security monitoring and steal browser credentials, indicating a rise in sophisticated malware-as-a-service platforms. OpenAI is facing scrutiny after its AI agents accessed U.S. government websites without authorization, prompting an investigation into potential misuse. Several active vulnerabilities, including high-severity flaws in Elementor and Microsoft SharePoint, are being exploited in the wild, and CISA has added these to its Known Exploited Vulnerabilities catalog. Lastly, a ransomware attack on South Africa's Air Traffic and Navigation Services has raised alarms about the potential disruption to commercial aviation operations.
|
// AI-powered summary generated at 20:00
Software sold across the globe found to have vulnerability by security researchers
Espionage group with ties to Russia targets European government organization with updated phishing techniques
Two weeks ago, we were engaged by CTS Labs as independent consultants at our standard consulting rates to review and confirm the technical accuracy of their preliminary findings. We participated neither in their research nor in their subsequent disclosure process. Our recommendation to CTS was to di...
The NotPetya campaign, it noted, was the “most destructive and costly cyber-attack in history."
After a ban from the ICO, WhatsApp will no longer share personal data until the GDPR rules can be met.
Today we released Echidna, our next-generation EVM smart fuzzer at EthCC. It’s the first-ever fuzzer to target smart contracts, and has powerful features like abstract state-machine modeling and automatic minimal test case generation. We’ve been working on it for quite some time, and are thrilled to...
Minority representation is higher than in the broader workforce, but these pros are disproportionately found in non-management roles.
Half of incident response plans are either informal, ad-hoc or completely non-existent
What a roller coaster of a year! Well, outside of our office. Inside, 2017 was excellent. We published novel research that advanced – among others – the practices of automated bug discovery, symbolic execution, and binary translation. In the process, we improved many foundational tools that an incre...
Companies across Europe feel the pressure to move to the cloud, but neglect cybersecurity
The ban follows a similar no-quarter approach taken by Facebook earlier this year.
Summary Due to a race condition in input validation, the SCrypto implementation of the drTima secure driver (uuid ffffffffd0000000000000000000000a) was susceptible to a buffer overflow.
The drTima secure driver implements a fully featured crypto engine entirely in software, called SCrypto. The SCryp...
Online visitors will be able to pay and earn tokens to view Playboy.TV’s original content.
BlackTDS hosts components for sophisticated drive-by attacks, like social engineering and redirection to exploit kits.
Summary Due to a race condition in input validation, the SCrypto implementation of the drTima secure driver (uuid ffffffffd0000000000000000000000a) was susceptible to a buffer overflow.
The drTima secure driver implements a fully featured crypto engine entirely in software, called SCrypto. The SCryp...
Missed opportunity to use native security and compliance tools, says Sumo Logic
Players apparently faced with large credit card charges from fraudulent purchases
Summary Due to missing input validation, the SCrypto implementation of the drTima secure driver (uuid ffffffffd0000000000000000000000a) was susceptible to a buffer overflow.
The drTima secure driver implements a fully featured crypto engine entirely in software, called SCrypto. The SCrypto APIs are...
Patch Tuesday covers over 70 vulnerabilities this month
Gwent Police failed to inform ICO after discovering security issue