> TODAY'S SUMMARY (18 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. A new WordPress vulnerability, Click2Shell, allows remote code execution via a single click, emphasizing the need for immediate updates to version 7.1.1. Additionally, a fake job interview campaign linked to North Korea has infected over 30,000 devices, showcasing the ongoing risks of social engineering attacks. The TryCloudflare service misconfiguration has led to unintended Google indexing, exposing sensitive user services. On the infrastructure side, flaws in Zyxel switches and Veeam software are actively exploited, prompting CISA to add them to its Known Exploited Vulnerabilities catalog. Lastly, security researchers have identified potential backdoor access through Meta's AI assistant, underlining the importance of scrutinizing AI integrations for security flaws.
|
// AI-powered summary generated at 08:01
Security researchers have discovered a new phishing website âunder constructionâ; one designed to take advantage of rapidly growing iOS7-mania.
Security for Apple mobile devices has been looking pretty good in light of the tsunami of Android malware making headlines lately, but a newly discovered hardware vulnerability in the Apple iPhone, iPad and iPod Touch adds new concern when it comes to the iOS platform.
We interrupt our regularly scheduled programming to bring you an important announcement: On Thursday, June 6th, just in time for SummerCon, we will be hosting a free Ruby Security Workshop in NYC! Signups are first-come, first-serve and we only have space for 30 people. Sign up here and we will emai...
Evernote has become the latest online denizen to roll-out two-step verification for accounts, following a hack that required all 50 million users to reset their passwords. Itâs also implemented access history and authorized applications features.
In the wake of a favorite money-laundering service being seized and taken down by the US government, the hacking underworld is mulling what to do next, financially.
In the final part of our three-part series, we investigate the how the toolkit user gained control of program flow and what their strategy means for the reliability of their exploit. Elderwood and the Department of Labor Hack Writing Exploits with the Elderwood Kit (Part 1) Writing Exploits with the...
No facial recognition for Google Glass yet â at least not through the front door - "without having strong privacy protections in place" confirmed Google in a brief Google+ statement Friday.â
A company, assumed to be Google, had challenged the legality of 19 National Security Letters demanding account information on its users; but a judge last week ruled that it must comply.
In the second part of our three-part series, we investigate the tools provided by the Elderwood kit for developing exploits from discovered vulnerabilities. Elderwood and the Department of Labor Hack Writing Exploits with the Elderwood Kit (Part 1) Writing Exploits with the Elderwood Kit (Part 2) Se...
In the wake of high-profile Twitter and Facebook hackings and about a year after it experienced a password heist, LinkedIn is beefing up its security: it has become the latest web denizen to join the optional two-factor verification fray, and is now offering free trials of security software to users...
Microsoft has kicked off the Cyber Threat Intelligence Program (C-TIP), an outgrowth of its information-sharing initiative around botnets.
Recently, the Department of Labor (DoL) and several other websites were compromised to host a new zero-day exploit in Internet Explorer 8 (CVE-2013-1347). Researchers noted similarities between this attack and earlier ones attributed to Elderwood, a distinct set of tools used to develop several past...
Drupal, the open source content management system, is resetting the passwords for nearly one million accounts in the wake of a data breach.
If you haven't already upgraded your Playstation 3 firmware from 4.31 to the 4.41 version released at the end of last month, now might be a good time to do so - it fixes a bug found by Vulnerability Lab six months ago.
Plusieurs rendez-vous français habituels sont consacrés cette année à la cybersécurité industrielle.
Comme pour faire Ă©cho Ă mon prĂ©cĂ©dent article concernant la publication en 2013 de plusieurs normes par lâISA (International Society of Automation), lâantenne française de [...] Lire la suite
Online child pornography, rather than child sexual abuse, may be a useful distinction to help prevent online offenders developing into physical abusers â thought to be a potential rather than inevitable progression.
Chinese hackers have scored two high-profile cyber-heists, according to reports: they have gained access to designs of more than two dozen major US weapons systems, while also stealing the blueprints for Australia's new spy headquarters.
A fresh phishing scam looking to capitalize on the popularity of Facebook Fan Pages has thrown a lure in using a security warning.
When details about Microsoftâs new games console, the Xbox One, first began to emerge, privacy campaigners were immediately concerned: is the Xbox One an intrusive but covert surveillance device?
Skyâs Android users may have woken on Sunday morning to headlines screaming âSky UK Apps Compromised on Play Store, Uninstall Them!â But donât be too hasty.