[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (112 articles)

|

// AI-powered summary generated at 20:00

> Air Gaps, Faraday Cages Can't Deter Hackers After All
One method exploits the magnetic field generated by a computer's CPU.
> Litecoin Emerges as Most Popular Dark Web Currency, After Bitcoin
Surprisingly, it's not Dash.
> An accessible overview of Meltdown and Spectre, Part 1
In the past few weeks the details of two critical design flaws in modern processors were finally revealed to the public. Much has been written about the impact of Meltdown and Spectre, but there is scant detail about what these attacks are and how they work. We are going to try our best to fix […]
> 81% of Cybersecurity Pros See Value in Threat Intelligence
68% of organizations are currently creating or consuming threat data.
> Fraud Attempts Soar 113% in Q4
Bots and breached credentials continue to fuel insatiable rise
> Unbox Your Phone - Part III.
Summary This is the third part of a blog series covering my security research into Samsung’s TrustZone. This post covers the following vulnerabilities that I have found: SVE-2017–8888: Authentication Bypass + Buffer overflow in tlc_server SVE-2017–8889: Stack buffer overflow in ESECOMM Trustlet SVE-...
> Global Arrests as $530m Carding Forum Folds
Infraud Organization inflicted $2.2bn in intended losses
> Swisscom Breach Hits 10% of Swiss Population
Telecoms firm says intruders got in via sales partner's access rights
> Unbox Your Phone - Part II.
Summary This is the second part of a blog series covering my security research into Samsung’s TrustZone. This post is a companion to my talk from Ekoparty 2017, namely the reverse engineering process of T-base. The slides and video of the talk are both available online. In fact, since both of those...
> Uber CISO: "No Justification" for Failure to Disclose Massive Breach
“It was wrong not to disclose the breach earlier,” said John Flynn, speaking at a hearing on Capitol Hill.
> 42% of the Web's Top Sites Are Compromised
Sites are running vulnerable software, have been breached or have been used to distribute malware.
> Unbox Your Phone - Part I.
Summary This is the first part of a blog series about reverse engineering and exploiting Samsung’s TrustZone. Following parts in the series so far: 2, 3. This first post covers the basics of the architecture. All of this is public info, nothing new, all of it has been covered in bits and pieces in v...
> ShurL0ckr Ransomware Evades Malware Detection in Google Drive, O365
Further analysis showed that a full 44% of scanned organizations had some form of malware in at least one of their cloud applications.
> Suspected ATM Jackpotting Fraudsters Arrested
Two men arrested outside cash-point dispensing $20 notes
> Heavy lifting with McSema 2.0
Four years ago, we released McSema, our x86 to LLVM bitcode binary translator. Since then, it has stretched and flexed; we added x86-64 support, put it on a performance-focused diet, and improved its usability and documentation. McSema wasn’t the only thing improving these past years, though. At the...
> Business Wire Suffers Week-Long DDoS Attack
Press release site under sustained pressure
> Adobe Issues Emergency Fix to Foil North Korean Hackers
Priority 1 bulletin fixes zero-day flaw
> 2017: Worst Year Ever for Data Loss and Breaches
The number of records compromised also surpassed all other years, with over 7.8 billion records exposed, a 24.2% increase over 2016’s previous high of 6.3 billion.
> Organizations Spend a Whopping $16M per Year on Detection Tools
Upfront costs are dwarfed by the human costs of managing and assessing the millions of alerts and false-positives these tools generate.
> Flaw in TLS/SSL Certificates Allows Covert Data Transfer
A proof of concept simulates a threat actor transferring the Mimikatz malware over TLS negotiation traffic.