Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31485 bookmarks
Custom sorting
Marks & Spencer touché par une cyberattaque, plusieurs services fortement perturbés
Marks & Spencer touché par une cyberattaque, plusieurs services fortement perturbés
La célèbre chaîne de magasins britannique a confirmé gérer un “cyberincident”, créant d'importantes perturbations de paiement et sur les délais...-Cybersécurité
·usine-digitale.fr·
Marks & Spencer touché par une cyberattaque, plusieurs services fortement perturbés
Ripple’s recommended XRP library xrpl.js hacked to steal wallets
Ripple’s recommended XRP library xrpl.js hacked to steal wallets
The recommended Ripple cryptocurrency NPM JavaScript library named "xrpl.js" was compromised to steal XRP wallet seeds and private keys and transfer them to an attacker-controlled server, allowing threat actors to steal all the funds stored in the wallets.
·bleepingcomputer.com·
Ripple’s recommended XRP library xrpl.js hacked to steal wallets
Android Improves Its Security - Schneier on Security
Android Improves Its Security - Schneier on Security
Android phones will soon reboot themselves after sitting idle for three days. iPhones have had this feature for a while; it’s nice to see Google add it to their phones.
·schneier.com·
Android Improves Its Security - Schneier on Security
SuperCard X Enables Contactless ATM Fraud in Real-Time
SuperCard X Enables Contactless ATM Fraud in Real-Time
A new malware campaign utilizing NFC-relay techniques has been identified carrying out unauthorized transactions through POS systems and ATMs
·infosecurity-magazine.com·
SuperCard X Enables Contactless ATM Fraud in Real-Time
Cookie-Bite attack PoC uses Chrome extension to steal session tokens
Cookie-Bite attack PoC uses Chrome extension to steal session tokens
A proof-of-concept attack called "Cookie-Bite" uses a browser extension to steal browser session cookies from Azure Entra ID to bypass multi-factor authentication (MFA) protections and maintain access to cloud services like Microsoft 365, Outlook, and Teams.
·bleepingcomputer.com·
Cookie-Bite attack PoC uses Chrome extension to steal session tokens
WordPress Core 6.2 - Directory Traversal
WordPress Core 6.2 - Directory Traversal
WordPress Core 6.2 - Directory Traversal. CVE-2023-2745 . webapps exploit for PHP platform
·exploit-db.com·
WordPress Core 6.2 - Directory Traversal
Implementing CCM: Data Protection and Privacy Controls | CSA
Implementing CCM: Data Protection and Privacy Controls | CSA
The Data Security and Privacy domain of the Cloud Controls Matrix addresses critical areas of the data lifecycle, like data classification and data disposal.
·cloudsecurityalliance.org·
Implementing CCM: Data Protection and Privacy Controls | CSA
GUEST ESSAY: Ponemon study warns: AI-enhanced deepfake attacks taking aim at senior execs
GUEST ESSAY: Ponemon study warns: AI-enhanced deepfake attacks taking aim at senior execs
A new study by the Ponemon Institute points to a concerning use of AI: deepfake attacks are on the rise and are taking a financial and reputational toll on companies and their executives. Related: Tools to fight deepfakes Deepfake Deception: How AI Harms the Fortunes and Reputations of Executives and Corporations details the results of a
·lastwatchdog.com·
GUEST ESSAY: Ponemon study warns: AI-enhanced deepfake attacks taking aim at senior execs
All Gmail users at risk from clever replay attack
All Gmail users at risk from clever replay attack
All Google accounts could end up compromised by a clever replay attack on Gmail users abusing Google infrastructure.
·malwarebytes.com·
All Gmail users at risk from clever replay attack
Prioritizing Care when Facing Cyber Risks | CSA
Prioritizing Care when Facing Cyber Risks | CSA
​Explore how healthcare organizations can safeguard patient care by addressing cyber risks through modernization and resilient security strategies.
·cloudsecurityalliance.org·
Prioritizing Care when Facing Cyber Risks | CSA