Found 34202 bookmarks
Newest
British Scattered Spider hacker pleads guilty to crypto theft charges
British Scattered Spider hacker pleads guilty to crypto theft charges
A British man, believed to be the leader of the Scattered Spider cybercrime collective, has pleaded guilty in the United States to charges of wire fraud and aggravated identity theft.
·bleepingcomputer.com·
British Scattered Spider hacker pleads guilty to crypto theft charges
Caso Nightmare-Eclipse: ci sono ancora due zero-day di Microsoft Defender in circolazione
Caso Nightmare-Eclipse: ci sono ancora due zero-day di Microsoft Defender in circolazione
Per due dei tre exploit (quello per ora “disinnescato” è stato ribattezzato BlueHammer) pubblicati su GitHub da un ricercatore di sicurezza non sono ancora disponibili patch. Sfruttandole, sarebbe possibile portare attacchi con un impatto critico. Ecco tutti i dettagli
·cybersecurity360.it·
Caso Nightmare-Eclipse: ci sono ancora due zero-day di Microsoft Defender in circolazione
A nice approach to AWS security group management
A nice approach to AWS security group management
AWS Glossary for the novices Hi, before diving a bit more in the details of this article, is mandatory to explain some core components in the AWS ecosystem we are gonna cite during this post, so even for novice and unfamiliar people can understand better the concepts. * EC2: stands for Elastic Compute your virtual machine located in some region in the world (do not ask me the 2 in EC2 what means) * Security Group: aka SG, a logical resource that acts as a virtual firewall you can put in fron
·blog.sicuranext.com·
A nice approach to AWS security group management
Le cyberladies italiane tra talento e disparità
Le cyberladies italiane tra talento e disparità
La terza survey Women for Security delinea un settore ad alta specializzazione ma ancora segnato da forti disparità. Crescono i ruoli apicali e la multidisciplinarità, pur persistendo criticità su retribuzioni e progressione di carriera. Valorizzare le cyberladies è una leva strategica fondamentale per colmare il cyber skill gap globale
·cybersecurity360.it·
Le cyberladies italiane tra talento e disparità
Il modello dell’EDPB sulla DPIA: pro o contro accountability?
Il modello dell’EDPB sulla DPIA: pro o contro accountability?
Il modello DPIA dell’EDPB, in consultazione pubblica, riapre il dibattito sull’equilibrio tra accountability e standardizzazione nel GDPR. Sarà uno strumento operativo o un nuovo benchmark implicito? Analisi di impatti, criticità e possibili evoluzioni per le organizzazioni
·cybersecurity360.it·
Il modello dell’EDPB sulla DPIA: pro o contro accountability?
Vercel confirms breach as hackers claim to be selling stolen data
Vercel confirms breach as hackers claim to be selling stolen data
Cloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems and are attempting to sell stolen data.
·bleepingcomputer.com·
Vercel confirms breach as hackers claim to be selling stolen data
Apple account change alerts abused to send phishing emails
Apple account change alerts abused to send phishing emails
Apple account change notifications are being abused to send fake iPhone purchase phishing scams within legitimate emails sent from Apple's servers, increasing legitimacy and potentially allowing them to bypass spam filters.
·bleepingcomputer.com·
Apple account change alerts abused to send phishing emails
NIST to stop rating non-priority flaws due to volume increase
NIST to stop rating non-priority flaws due to volume increase
The National Institute of Standards and Technology will stop assigning severity scores to lower-priority vulnerabilities due to the growing workload from rising submission volumes.
·bleepingcomputer.com·
NIST to stop rating non-priority flaws due to volume increase
Fixing uConsole Trackball and Keyboard Issues
Fixing uConsole Trackball and Keyboard Issues
If you’ve been using a ClockworkPi uConsole as a daily device, chances are you’ve noticed something slightly off about the input experience. The keyboard works, the trackball works—but neither feels as precise or refined as you’d expect from such a well‑designed handheld. If you would like to know more about uConcole, check out my previous
·mobile-hacker.com·
Fixing uConsole Trackball and Keyboard Issues
Critical flaw in Protobuf library enables JavaScript code execution
Critical flaw in Protobuf library enables JavaScript code execution
Proof-of-concept exploit code has been published for a critical remote code execution flaw in protobuf.js, a widely used JavaScript implementation of Google's Protocol Buffers.
·bleepingcomputer.com·
Critical flaw in Protobuf library enables JavaScript code execution
Microsoft Teams right-click paste broken by Edge update bug
Microsoft Teams right-click paste broken by Edge update bug
Microsoft is warning that a recent Microsoft Edge browser update introduced a bug that breaks right-click paste in chats in the Microsoft Teams desktop client.
·bleepingcomputer.com·
Microsoft Teams right-click paste broken by Edge update bug
Man who hacked US Supreme Court filing system sentenced to probation
Man who hacked US Supreme Court filing system sentenced to probation
Nicholas Moore hacked into three U.S. government networks using stolen credentials, and then bragged about it and posted victims' personal data on Instagram under the handle @ihackedthegovernment.
·techcrunch.com·
Man who hacked US Supreme Court filing system sentenced to probation
Payouts King ransomware uses QEMU VMs to bypass endpoint security
Payouts King ransomware uses QEMU VMs to bypass endpoint security
The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security.
·bleepingcomputer.com·
Payouts King ransomware uses QEMU VMs to bypass endpoint security
Hackers are abusing unpatched Windows security flaws to hack into organizations
Hackers are abusing unpatched Windows security flaws to hack into organizations
A security researcher published details of three security vulnerabilities in Windows Defender, and the code used to exploit them. Now, hackers are taking advantage of the vulnerabilities in real life attacks, according to a cybersecurity firm.
·techcrunch.com·
Hackers are abusing unpatched Windows security flaws to hack into organizations