> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape reveals a record surge in ransomware attacks, with 1,073 firms targeted globally in August, primarily in the industrial sector. Microsoft has disrupted the AI-powered phishing service, EvilTokens, which compromised over 12,000 inboxes across various organizations. Meanwhile, critical vulnerabilities have been reported in several platforms, including Adobe, WordPress, and F5's BIG-IP, necessitating immediate patches to prevent potential exploitation. Additionally, the ShinyHunters group claims to have breached FBI systems via a zero-day vulnerability in Oracle PeopleSoft, threatening to leak sensitive data. In malware developments, Chinese hackers are leveraging a Chrome-Windows zero-day to deploy CLEANGULP malware, highlighting the ongoing threat posed by exploit chains.
|
// AI-powered summary generated at 12:01
Half of respondents claim their firm is underinvesting in cybersecurity
But Gartner predicts slowdown in Europe next quarter due to strong dollar
This summer I’ve had the incredible opportunity to work with Trail of Bits as a high school intern. In return, I am obligated to write a blog post about this internship. So without further ado, here it is. Starting with Fuzzing The summer kicked off with fuzzing, a technique I had heard of but had [...
The group is making its mission to vet internet-connected devices for vulnerabilities and flaws.
XcodeGhost far more widespread than at first thought
This summer FireEye’s FLARE team hosted its second annual Flare-On Challenge targeting reverse engineers, malware analysts, and security professionals. In total, there were eleven challenges, each using different anti-reversing techniques and each in different formats. For example, challenges ranged...
The guide is meant to help security researchers who find vulnerabilities to report a security issue to a company, and without being threatened with legal action.
Skills shortages still a major problem
Claims firm Systema Software fingered for breach of 1.5m details
Routers in over 30 countries now found to be affected
It has an arsenal of privilege escalation exploits, which is used to install a rootkit on the device so it can persist even after the user uninstalls it.
The campaign is part of a long list of cyber-attacks that target one country at a time, at different time intervals, and use the same tactic.
Malware designed to sneak a peek at your hand
IT and security professionals are doing a terrible job at communicating risk, bogged down in technical jargon and a lack of business context.
Three-quarters of US organizations are not prepared to respond to cyber-attacks, leaving them more vulnerable than ever.
KPMG finds private firms have a long way to go to win consumer trust
Given the nation's big election, the attack was likely hactivist motivated.
Amid fears of government snooping, the data revolution has created a ticking time bomb; sharing personal data is simply not working for anyone at the moment.
Secure Chat, initially available for Android, offers multiple-encrypted SMS and chat communication, and file-sharing.
PwC legal experts predicts “sausage factory” of privacy claims and disputes