> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The Canadian regulator is investigating IDScan for potential data privacy violations, while the ransomware PAYLOAD has demonstrated a new tactic, paralyzing an organization without file encryption. Volexity reported a China-aligned threat group exploiting vulnerabilities in Chrome and Microsoft software. The hacking group ShinyHunters claims to have breached the FBI, raising significant counterintelligence concerns. Additionally, ClosedQuorum malware is leveraging AI for attack decisions, indicating a trend towards more sophisticated, autonomous threats. CISA has urged federal agencies to patch a critical Zyxel flaw actively exploited by attackers. Meanwhile, the rise of AI in cybercrime continues, with deepfakes and AI-driven bots posing increasing risks to organizations.
|
// AI-powered summary generated at 20:01
Tim Cook stressed the "awareness piece" and said that 2FA is coming for mobile logins.
Bank jumps aboard the biometrics bandwagon in bid to reduce corporate account fraud
In light of the recent compromises, you’re probably wondering what could have been done to prevent such attacks. According to some unverified articles it would appear that flaws in Apple’s services allowed an attacker to brute force passwords without any rate limiting or account lockout. While its...
Beijing keen to censor and monitor searches made by users of CERNET education network
APT12 keeps a close eye on media coverage to stay one step ahead of defences, says FireEye
In this post, we discuss the creation of a novel software obfuscation toolkit, MAST, implemented in the LLVM compiler and suitable for denying program understanding to even the most well-resourced adversary. Our implementation is inspired by effective obfuscation techniques used by nation-state malw...
Nearly one million new phishing sites have appeared this year so far.
Social engineering lures using Facebook, Twitter and fake 'photos' are proliferating on the web.
We are proud to announce that McSema is now open source! McSema is a framework for analyzing and transforming machine-code programs to LLVM bitcode. It supports translation of x86 machine code, including integer, floating point, and SSE instructions. We previously covered some features of McSema in...
Trend Micro sees participants and message volumes double
Malware targeted third party payment processing systems
A 2-day conference exploring state-of-the-art advances in security automation. We would like to share the call for papers for THREADS 2014, a research and development conference that is part of NYU-Poly’s Cyber Security Awareness Week (CSAW). Trail of Bits is a founding sponsor of THREADS. The final...
Harkonnen Operation sent data to domains registered to false UK companies
n Firefox 32, Mozilla has added public-key pinning as an extra security measure to prevent man-in-the-middle attacks, use of rogue certificates, and other critical security threats.
The spam bot is being used to carry out a large-scale, global offensive bent on fooling search algorithims.
Alliance will invoke collective defense clause if one member country is hit with major online attack
Hackers Use Large Numbers of Transient Domains to Hide Attacks. Research shows 71% of hostnames appear for one day or less
Lookout claims 12-5pm is the most dangerous time for smartphone theft
The billion-plus credential theft by CyberVor hackers is now leading to compromises at Namecheap.
Poor password choices and a lack of two-factor authentication created the hacking opportunity.