> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape reveals a record surge in ransomware attacks, with 1,073 firms targeted globally in August, primarily in the industrial sector. Microsoft has disrupted the AI-powered phishing service, EvilTokens, which compromised over 12,000 inboxes across various organizations. Meanwhile, critical vulnerabilities have been reported in several platforms, including Adobe, WordPress, and F5's BIG-IP, necessitating immediate patches to prevent potential exploitation. Additionally, the ShinyHunters group claims to have breached FBI systems via a zero-day vulnerability in Oracle PeopleSoft, threatening to leak sensitive data. In malware developments, Chinese hackers are leveraging a Chrome-Windows zero-day to deploy CLEANGULP malware, highlighting the ongoing threat posed by exploit chains.
|
// AI-powered summary generated at 12:01
Signs of greater co-operation between superpowers
Rival companies in legal tussle
This summer I’ve had the incredible opportunity to work with Trail of Bits as a high school intern. In return, I am obligated to write a blog post about this internship. So without further ado, here it is. Starting with Fuzzing The summer kicked off with fuzzing, a technique I had heard of but had [...
Hackers manipulated a subscription system to steal personal contact information from August 2012 until at least July 2015.
Exercise highlights importance of training and awareness programs
This summer FireEye’s FLARE team hosted its second annual Flare-On Challenge targeting reverse engineers, malware analysts, and security professionals. In total, there were eleven challenges, each using different anti-reversing techniques and each in different formats. For example, challenges ranged...
Leeds man gets 20-week suspended sentence
Privacy fears after BMJ survey reveals dangers of BYOD
It can operate as a local access trojan, without a command & control server, receiving its commands locally, through a hidden control panel.
China suspected of grabbing IP from LoopPay
FireEye warns users not to click on suspicious links
A network of fake LinkedIn profiles has been created to help the threat actors target potential victims through social engineering.
Talos group disrupts proxy network making a fortune from ransomware
Silanis provides electronic signature (e-signature) and digital transaction solutions used to sign, send and manage documents.
Over a long-term period compromised identities are seen moving industries, likely in an attempt to defeat traditional fraud detection tools.
Attackers could record authentication credentials and be provided with complete backdoor capabilities.
It’s the first malware seen in the wild that abuses private APIs in the iOS system to implement malicious functionalities.
Chatham House warns ‘air gapping’ is a myth
18-34 year-olds put themselves at a higher risk than most by doing things like checking financial accounts on public Wi-Fi and not using a password on their phones.
Also, most cards will still only require the presenter to provide a signature to complete the transaction.