> TODAY'S SUMMARY (70 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Notably, North Korean hackers are suspected of stealing $351 million from the Bitget cryptocurrency exchange, underscoring the ongoing risk to the crypto sector. The Dyfed-Powys Police in Wales experienced a cyberattack that potentially compromised staff data, while a new campaign named ClickFix exploits trusted websites to deploy the Psychedelic Stealer, targeting browser and crypto credentials. Vulnerabilities in Salesforce's Agentforce have been identified, allowing zero-click data exfiltration, further emphasizing the need for robust security measures. LinkedIn is enhancing checks against fake profiles as AI-generated content becomes more prevalent, indicating a rising trend in AI-related security threats. Additionally, multiple vulnerabilities in Linux kernels across various distributions have been reported, necessitating immediate attention from organizations using these systems.
|
// AI-powered summary generated at 16:00
Bitdefender found that during 2017 alone, the number of new major ransomware families surpassed 160.
If you’re building real applications with blockchain technology and are worried about security, consider this meetup essential. Join us on December 12th for a special edition of Empire Hacking focused entirely on the security of Ethereum. Why attend? Four blockchain security experts will be sharing...
Princeton researchers find privacy and security concerns in use of session replay scripts
Ride-hailing service under fire after paying hackers $100K to delete stolen data
In the year since we ported osquery to Windows, the operating system instrumentation and endpoint monitoring agent has attracted a great deal of attention in the open-source community and beyond. In fact, it recently received the 2017 O’Reilly Defender Award for best project. Many large and leading...
Yet just 0.5% of the top million domains have protected themselves from impersonation by DMARC email authentication.
The quarter saw a rise in attacks against accounting, biopharma, retail, biotech and pharmaceuticals.
Last week Zeppelin released their Ethereum CTF, Ethernaut. This CTF is a good introduction to discover how to interact with a blockchain and learn the basics of the smart contract vulnerabilities. The CTF is hosted on the ropsten blockchain, and you can receive free ethers for it. The browser develo...
A new version of the BankBot Android mobile banking malware has snuck into Google Play, targeting apps of large banks.
Cyber-attack is another blow for digital currencies
We’re proud to announce that Trail of Bits has joined the Enterprise Ethereum Alliance (EEA), the world’s largest open source blockchain initiative. As the first information security company to join, and currently one of the industry’s top smart contract auditors, we’re excited to contribute our unp...
Controversial certificate authority and parent company WoSign not trusted by browser makers
Businesses are urged to better protect key systems
We’ve added five more to our ranks in the last two months, bringing our total size to 32 employees. Their resumes feature words and acronyms like ‘CTO,’ ‘Co-founder’ and ‘Editor.’ You might recognize their names from publications and presentations that advance the field. We’re excited to offer them...
California, Florida, Illinois and New York are also in the top 10.
In Q3, organizations experienced an average of 237 DDoS attack attempts per month, equivalent to eight attempts every day.
London police profiling public without appropriate legal framework
S3 buckets contain billions of citizens' internet records
RiskIQ warns that one in 25 are malicious
Banking giant estimates festive fraud will cost victims £1.63bn