[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (112 articles)

|

// AI-powered summary generated at 20:00

> Winter Olympics Attack Expands with Top-Tier Spyware
Additional implants are being used as a second-stage payload to gain persistence for continued data exfiltration and for targeted access.
> 12,000 Social Media Stars Exposed in Latest Cloud Misconfig
A marketing agency made public a raft of information about influential "creators" – mostly Instagram, Twitter and YouTube personalities.
> An accessible overview of Meltdown and Spectre, Part 1
In the past few weeks the details of two critical design flaws in modern processors were finally revealed to the public. Much has been written about the impact of Meltdown and Spectre, but there is scant detail about what these attacks are and how they work. We are going to try our best to fix […]
> NCSC’s ‘Active Cyber Defence’ Initiative Boasts Impressive First-Year Results
More than one million security scans and seven million security tests carried out on public sector websites
> API Security Concerns Are on the Rise
More than two-thirds (69%) of organizations are exposing APIs to the public and their partners.
> Unbox Your Phone - Part III.
Summary This is the third part of a blog series covering my security research into Samsung’s TrustZone. This post covers the following vulnerabilities that I have found: SVE-2017–8888: Authentication Bypass + Buffer overflow in tlc_server SVE-2017–8889: Stack buffer overflow in ESECOMM Trustlet SVE-...
> Fraudulent Money Transfers Cost Orgs $352K on Average
Incidents quadrupled in 2017, with losses ranging from a few thousand dollars up to $3 million.
> Just 20% of Orgs Have Breach Notification Plans
The majority (73%) said they were “somewhat prepared” and would have to figure things out “on the fly.”
> Unbox Your Phone - Part II.
Summary This is the second part of a blog series covering my security research into Samsung’s TrustZone. This post is a companion to my talk from Ekoparty 2017, namely the reverse engineering process of T-base. The slides and video of the talk are both available online. In fact, since both of those...
> Over 500,000 Windows Machines Infected with Monero Mining Software
Crypto-mining malware spreading via EternalBlue exploit
> Bomgar Acquires Lieberman Software Adding Privilege to Access
Bomgar has acquired Lieberman Software to enhance its portfolio of secure access software
> Unbox Your Phone - Part I.
Summary This is the first part of a blog series about reverse engineering and exploiting Samsung’s TrustZone. Following parts in the series so far: 2, 3. This first post covers the basics of the architecture. All of this is public info, nothing new, all of it has been covered in bits and pieces in v...
> JenX Botnet Emerges to Target IoT Devices and Grand Theft Auto
The botnet is for rent. Its service description reads: “God’s wrath will be employed against the IP that you provide us.”
> Critical Infrastructure More Vulnerable Than Ever Before
The number of internet-accessible industrial control systems (ICS) is increasing every year, as are vulnerabilities.
> Heavy lifting with McSema 2.0
Four years ago, we released McSema, our x86 to LLVM bitcode binary translator. Since then, it has stretched and flexed; we added x86-64 support, put it on a performance-focused diet, and improved its usability and documentation. McSema wasn’t the only thing improving these past years, though. At the...
> Criminals Move to Cash in on Cryptocurrency Gold Rush
Cybercriminals have developed several schemes to defraud those looking to profit from the growth in cryptocurrencies.
> Cisco: Crypto-Mining Botnets Could Make $100m Annually
Black hats are eschewing ransomware in favor of easier ways to make cash
> US Government in Whois GDPR Warning
NTIA wants info to remain freely accessible despite new European privacy laws
> Fortune 500 Staff Spill 2.7 Million Log-Ins to Dark Web
Leaked usernames and passwords for online accounts represent a growing security risk
> Security Not Keeping Up with Cloud-First Business Strategies
40% of respondents in a new survey felt that their security solutions aren’t as flexible as the rest of their cloud initiatives.