> TODAY'S SUMMARY (112 articles)
Today's cybersecurity news highlights several significant threats and trends:
1. Labcorp faces a $2.3 million fine due to cybersecurity failings and is implementing enhanced data security measures, including a new incident response plan.
2. Cryptocurrency exchange Bitget reports a staggering $351.6 million theft by suspected North Korean hackers, prompting investigations and withdrawal suspensions.
3. A critical vulnerability in the Elementor WordPress plugin allows unauthenticated attackers to create admin accounts, emphasizing the ongoing risk of exploited software flaws.
4. Fake desktop applications targeting payroll services have emerged, tricking HR staff into granting remote access to attackers.
5. CISA warns of exploited flaws in Adobe and WSO2 products, adding them to its Known Exploited Vulnerabilities catalog, highlighting the urgency for organizations to patch these vulnerabilities.
|
// AI-powered summary generated at 20:00
Ballroom dancer, singer and television presenter Anton du Beke hosted the 13th White Hat Ball at London’s Lancaster Gate hotel
The NATO Cooperative Cyber Defence Centre of Excellence will coordinate education and training across the Alliance.
In the past few weeks the details of two critical design flaws in modern processors were finally revealed to the public. Much has been written about the impact of Meltdown and Spectre, but there is scant detail about what these attacks are and how they work. We are going to try our best to fix […]
Only 11.3% of top US retailer and 12.2% of top EU retailer domains have fully implemented DMARC and SPF.
The median total cost of a ransomware attack was $133,000 last year, and most companies were hit twice.
Summary This is the third part of a blog series covering my security research into Samsung’s TrustZone.
This post covers the following vulnerabilities that I have found:
SVE-2017–8888: Authentication Bypass + Buffer overflow in tlc_server SVE-2017–8889: Stack buffer overflow in ESECOMM Trustlet SVE-...
Developers and infrastructure specialists will also benefit from a 3% pay raise
Attackers may tweak ransomware and target supply chain
Summary This is the second part of a blog series covering my security research into Samsung’s TrustZone.
This post is a companion to my talk from Ekoparty 2017, namely the reverse engineering process of T-base. The slides and video of the talk are both available online.
In fact, since both of those...
Scam netted criminals $150K ahead of start-up’s ICO
Trump security team wanted to reduce supply chain risks
Summary This is the first part of a blog series about reverse engineering and exploiting Samsung’s TrustZone. Following parts in the series so far: 2, 3.
This first post covers the basics of the architecture. All of this is public info, nothing new, all of it has been covered in bits and pieces in v...
The Strava app could show the location of soldiers stationed at sensitive locations, such as military bases.
IBM Security has found that people now prioritize security over convenience when logging into applications and devices.
Four years ago, we released McSema, our x86 to LLVM bitcode binary translator. Since then, it has stretched and flexed; we added x86-64 support, put it on a performance-focused diet, and improved its usability and documentation. McSema wasn’t the only thing improving these past years, though. At the...
An Allot report found that CSPs can realize a twofold to threefold increase in customer satisfaction.
NIS Directive will land on May 10
Hacked exchange will need to fork out over $400m
Second unscheduled update of the month for Redmond
Discussions are already underway with over 50 clubs, including Premier League Clubs in the UK and prominent teams in Europe, the US and Australia.