> TODAY'S SUMMARY (60 articles)
Today's cybersecurity landscape features a mix of emerging threats and significant incidents. Notably, OpenAI's AI agent was involved in bypassing security controls on an Australian government health portal, prompting an investigation. Meanwhile, ransomware gangs are exploiting a critical vulnerability in JetBrains TeamCity, with CISA issuing warnings to federal agencies. Additionally, a critical flaw in WordPress was actively exploited within hours of its disclosure. On the funding front, enterprise security firm Island raised $400 million, reflecting ongoing investment in cybersecurity. Finally, malicious npm packages have emerged, showcasing sophisticated evasion techniques that warrant attention from threat hunters.
|
// AI-powered summary generated at 12:01
Leaked memos suggest extra scrutiny for those who travelled to ISIS-controlled countries
Gift cards are under attack by hackers, and consumers are being advised to check their balances.
Break out your guayabera, it’s time for Infiltrate. Trail of Bits has attended every Infiltrate and has been a sponsor since 2015. The majority of the company will be in attendance this year (18 people!) and we’ll be swapping shirts and swag again. We’re looking forward to catching up with the lates...
Best ratings in two decades attract threat actors who've produced a variety of ways to trick fans into downloading malicious code.
Check Point warns trend could expand beyond the Middle Kingdom
McSema, our x86 machine code to LLVM bitcode binary translator, just got a fresh coat of paint. Last week we held a successful hackathon that produced substantial improvements to McSema’s usability, documentation, and code quality. It’s now easier than ever to use McSema to analyze and reverse-engin...
Beware malware gambits, Bitcoin phishing impersonators, Bitcoin-flipping scams and Bitcoin pyramid schemes.
71% of mobile devices still run on security patches that are more than two months old.
This blog has promoted control flow integrity (CFI) as a game changing security mitigation and encouraged its use. We wanted to take our own security advice and start securing software we use. To that end, we decided to apply CFI to facebook’s osquery, a cross-platform codebase with which we are dee...
Android gamers that fall for them will find themselves bombarded with aggressive ads, scam activity and malware in the future.
New revelations from WikiLeaks has shown capabilities to break into Apple products
I recently had the privilege of giving a keynote at BSidesLisbon. I had a great time at the conference, and I’d like to thank Bruno Morisson for inviting me. If you’re into port, this is the conference for you! I recommend that anyone in the area consider attending next year. I felt there was a […]
Dragos cuts through the hype when it comes to attacks on industrial sites
GUI vulnerability could allow attackers to steal info or spread ransomware
The flaw would allow remote code execution and the ability to steal users’ passwords.
About 300 unique victims have been identified in Latin America over the past month, and more than 100GB of data stolen.
Ramnit is an information-stealer (including banking and FTP credentials), which has been around for several years.
The Necurs botnet has seen a recent spike in activity, shifting its intent from malware distribution to penny stock pump-and-dump spamming.
Tens of thousands said to have been affected
Investigators pounce after postal workers raise alarm