> TODAY'S SUMMARY (101 articles)
Today's cybersecurity news highlights several significant threats and trends. OpenAI has partnered with Ukraine to enhance the cybersecurity of critical infrastructure amid ongoing conflict with Russia. A member of the Ryuk ransomware gang received a two-year prison sentence for extorting over $1.2 million. The ShinyHunters group claims to have breached the FBI, demanding the retraction of a report criticizing their methods. Vulnerabilities in multiple platforms, including GitHub and WordPress, continue to pose risks, with leaked GitHub App keys still being exploited. Additionally, a new Windows malware, CLOSEDQUORUM, utilizes AI models to determine its actions, showcasing the evolving landscape of AI in cyberattacks.
|
// AI-powered summary generated at 16:00
Part of the plan is a much-needed software patching and updating audit, and more training and recruiting for cybersecurity specialists.
The Poseidon Group is a previously undiscovered but long-standing team that's been stealing information for at least 10 years.
For most mobile app developers, password management has as much appeal as a visit to the dentist. You do it because you have to, but it is annoying and easy to screw up, even when using standard libraries or protocols like OAUTH. Your users feel the same way. Even if they know to use strong […]
With a Skycure integration, Microsoft Exchange is building in protection for the sensitive information stored in email.
Kingston Digital has acquired the USB technology and assets of IronKey from Imation, and Imation has also sold the IronKey Enterprise Management Services (EMS) platform, to DataLocker.
We’re excited to announce that Sophia D’Antoine will be the next featured speaker at Etsy’s Code as Craft series on Wednesday, February 10th from 6:30-8pm in NYC. What is Code as Craft? Etsy Code as Craft events are a semi-monthly series of guest speakers who explore a technical topic or computing t...
Safer Internet Day aims to promote a more inclusive net
The Adwind RAT is a cross-platform, multifunctional malware available via a single malware-as-a-service platform.
Every good security researcher has a well-curated list of blogs they subscribe to. At Trail of Bits, given our interest in software security and its intersections with programming languages, one of our favorites is The Programming Language Enthusiast by Michael Hicks. Our primary activity is to desc...
TaoBao, a commerce site that could be considered the eBay of China, was the subject of an ongoing offensive from mid-October to November.
Gossip site the latest to be struck in ongoing campaign
At the end of last year, we had some free time to explore new and interesting uses of the automated bug-finding technology we developed for the DARPA Cyber Grand Challenge. While the rest of the competitors are quietly preparing for the CGC Final Event, we can entertain you with tales of running our...
Latest AV vendor to get the Project Zero treatment
The perpetrators gained unauthorized access to Social Security numbers for thousands of current and former UCF students and staff.
Now that the new year is upon us, we can look back and take assessment of 2015. The past year saw Trail of Bits continuing our prior work, such as automated vulnerability discovery and remediation, and branching out into new areas, like secure self-hosted video chat. We also increased our community...
58 unique researchers submitted more than 7,000 reports.
Discovery could boost contactless card security
We’re excited to announce our financial support for Let’s Encrypt, the open, automated and free SSL Certificate Authority (CA) that went into public beta on December 3. With so much room for improvement in the CA space, Let’s Encrypt offers a refreshing, promising vision of encrypting the web. Expen...
Claims negative and inaccurate reporting has damaged the company
Hundreds of servers have already been compromised.