> TODAY'S SUMMARY (21 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. A zero-day vulnerability in F5 BIG-IP is being actively exploited, allowing unauthenticated attackers to achieve remote code execution; F5 has released patches to address this issue. Similarly, a new flaw in Next.js could enable server code execution through crafted SVG input. In a concerning development, the ShinyHunters group claims to have breached the FBI, threatening to leak sensitive data unless a report is retracted. Additionally, vulnerabilities in Chromium and Check Point's management server are also drawing attention, underscoring the ongoing risks associated with software security. As malicious bot activity continues to surge, nearly two-thirds of websites tested are failing bot defenses, signaling a growing cyber threat landscape.
|
// AI-powered summary generated at 08:01
SEC filing claims ‘employee impersonation’ was to blame
Hackers could take control of all connected devices on the network, including door locks, motion sensors, HVAC and smart light bulbs/switches.
At REcon 2015, I demonstrated a new hardware side channel which targets co-located virtual machines in the cloud. This attack exploits the CPU’s pipeline as opposed to cache tiers which are often used in side channel attacks. When designing or looking for hardware based side channels – specifically...
Researchers could remotely turn the car on and off remotely, hit the brakes if the car is moving under 5 MPH, and shift it into neutral.
The Money Shop lost two servers full of customer data
The Cyber Grand Challenge qualifying event was held on June 3rd, at exactly noon Eastern time. At that instant, our Cyber Reasoning System (CRS) was given 131 purposely built insecure programs. During the following 24 hour period, our CRS was able to identify vulnerabilities in 65 of those programs...
Context researchers claim config error is to blame
Exploit kits integrated Hacking Team zero-days into their digital weapons in half the usual time.
Never let a good incident go to waste. Today, we’re using the OPM incident as an excuse to share with you our top recommendations for shoring up the security of your Google Apps for Work account. More than 5 million companies rely on Google Apps to run their critical business functions, like email,...
Various brands of smartwatches present differing risks for data loss.
The buy will help Accenture beef up its security consulting business.
Terracotta is being used as a launch platform for APT actors, including the well-known Shell_Crew/DeepPanda group.
Thunderstrike 2 is a proof-of-concept firmware worm that’s the first to attack Macs.
62% view employees as their biggest threat.
Next Generation Cyber Initiative has problems, says OGI
In addition to MMS, devices can be infected using malicious video files that auto-play when opening a website, or via malicious apps or MP4 files.
Several healthcare providers were affected by the attack, including local companies and national outlets, and the federal government.
Institute will train up 40 applicants ready to step into a job
ESET report reveals five-year targeted attack campaign
Trend Micro report highlights increasing sophistication and professionalism