> TODAY'S SUMMARY (70 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Notably, North Korean hackers are suspected of stealing $351 million from the Bitget cryptocurrency exchange, underscoring the ongoing risk to the crypto sector. The Dyfed-Powys Police in Wales experienced a cyberattack that potentially compromised staff data, while a new campaign named ClickFix exploits trusted websites to deploy the Psychedelic Stealer, targeting browser and crypto credentials. Vulnerabilities in Salesforce's Agentforce have been identified, allowing zero-click data exfiltration, further emphasizing the need for robust security measures. LinkedIn is enhancing checks against fake profiles as AI-generated content becomes more prevalent, indicating a rising trend in AI-related security threats. Additionally, multiple vulnerabilities in Linux kernels across various distributions have been reported, necessitating immediate attention from organizations using these systems.
|
// AI-powered summary generated at 16:00
Democrat senators Warren and Warner introduce new legislation
There was a 37% increase in botnet command-and-control (C&C) listings in 2017, with the majority (68%) of them being hosted on servers run by threat actors.
On December 12, over 150 attendees learned how to write and hack secure smart contracts at the final Empire Hacking meetup of 2017. Thank you to everyone who came, to our superb speakers, and to Datadog for hosting this meetup at their office. Watch the presentations again We believe strongly that t...
Bad guys can access all of the compute power connected to a particular public Wi-Fi network, all at once, to mine for cryptocurrency.
The majority of IT professionals are investing in virus protection (71%), malware protection (67%), patch management (53%), and IDP (52%).
You’re reading the second post in our four-part series about osquery. Read post number one for a snapshot of the tool’s current use, the reasons for its growing popularity among enterprise security teams, and how it stacks up against commercial alternatives. osquery shows considerable potential to r...
ICO forces retailer to pay up, but larger fines await with GDPR
Scheduled updates follow last week’s out-of-band patches
Today, we are releasing access to our maintained repository of osquery extensions. Our first extension takes advantage of the Duo Labs EFIgy API to determine if the EFI firmware on your Mac fleet is up to date. There are very few examples of publicly released osquery extensions. Very little document...
Wray claims Feds have nearly 7800 devices they can’t access
Reddit has confirmed that one of its email providers, Mailgun, has been breached.
Bruce Beam will lead all aspects of (ISC)²’s global IT/ICT and cybersecurity operations.
The Tribune of India was able to access the entirety of the state identification database for just $8.
Security top concern on future cloud adoption for IT decision makers
UK Conservative Party lets secure cert expire
Digital toymaker was also accused by FTC of failing to properly secure children’s data
New protocol will land later this year
Threat actors could gain control over the device, exfiltrate information and spread malware.
Proofpoint uncovered the vulnerability and created a proof of concept exploit for the issue, which exists in the Google Apps Script.
Coinhive weighed in on the Reddit thread saying that the site appears to have been surreptitiously infected.