> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape reveals a record surge in ransomware attacks, with 1,073 firms targeted globally in August, primarily in the industrial sector. Microsoft has disrupted the AI-powered phishing service, EvilTokens, which compromised over 12,000 inboxes across various organizations. Meanwhile, critical vulnerabilities have been reported in several platforms, including Adobe, WordPress, and F5's BIG-IP, necessitating immediate patches to prevent potential exploitation. Additionally, the ShinyHunters group claims to have breached FBI systems via a zero-day vulnerability in Oracle PeopleSoft, threatening to leak sensitive data. In malware developments, Chinese hackers are leveraging a Chrome-Windows zero-day to deploy CLEANGULP malware, highlighting the ongoing threat posed by exploit chains.
|
// AI-powered summary generated at 12:01
Trend Micro research profiles another China-based threat group
Telcoms giant will offer STAR accredited package
This summer I’ve had the incredible opportunity to work with Trail of Bits as a high school intern. In return, I am obligated to write a blog post about this internship. So without further ado, here it is. Starting with Fuzzing The summer kicked off with fuzzing, a technique I had heard of but had [...
Attack takes advantage of devices’ privileged position
Bit9 + Carbon Black report reveals little sympathy for erring businesses
This summer FireEye’s FLARE team hosted its second annual Flare-On Challenge targeting reverse engineers, malware analysts, and security professionals. In total, there were eleven challenges, each using different anti-reversing techniques and each in different formats. For example, challenges ranged...
System enabling US IP theft said to dwarf Beijing’s home-grown R&D
Review board will conduct research into improving in-vehicle security
Follow-up fraud on the cards after insurer is attacked
Ditch the strength meter and add extra technical controls, says spy agency
Cyber Party urges voters to support its call for improved privacy protection
Attackers were inside the network since 2013
Passive email addresses linked to profiles on the adultery site
Zimperium said that it is publishing the code so that administrators and testers can validate the effectiveness of the Android community’s response.
While only 28% of respondents have fully embraced a context-aware approach to security, 97% see the benefits in it.
Since April 2015, Akamai identified 114 DD4BC attacks, including more aggressive measures that target brand reputation through social media.
Attackers increasingly use methods that leave few traces behind—so we are in an arms race where the key difference is training.
Attackers may have been slurping sensitive bug data for even longer
Researchers’ public disclosure puts security giants on alert
Dell SecureWorks claims stolen credentials and VPNs are becoming increasingly popular