News
-
"DHS S&T Seeks Solutions for Privacy-Preserving Digital Credential Wallets & Verifiers"The US Department of Homeland Security (DHS) Science and Technology Directorate (S&T) has issued a new solicitation for the development, improvement, and implementation of a new set of tools that protect the privacy of individuals when using digital…
-
"Rise of the Script Kiddie: A Tenth of Children Say They Can Hack Websites"One in ten children believe they can hack into websites and online accounts, but only 8 percent of parents are concerned about this possible issue. Censuswide surveyed 500 children in the UK aged 12 to 17. Less than half of parents (44 percent) limit…
-
"DOE Suffers Data Breach; 45K Students Affected"The Department of Education (DOE) recently experienced a data breach incident on Saturday, June 24. The DOE stated that the third-party file-sharing software MOVEit, which is used by the DOE to transfer documents and data internally and to vendors…
-
"Sweetwater UHSD Data Breach Compromises Student, Staff Info"Sweetwater Union High School District recently announced that the personal information of students, families, and current and former employees was compromised in a February data breach. Between Feb. 11 and 12, an unauthorized person gained access…
-
"Dozens of Businesses Hit Recently by ‘8Base’ Ransomware Gang"According to security researchers at VMware, a ransomware gang named 8Base was the second most active group in June 2023. 8Base has been active since March 2022 and mainly focused on small businesses. The researchers noted that the group…
-
"Using Electromagnetic Fault Injection Attacks to Take Over Drones"IOActive researchers explored the development of fault injection attacks against hardened Unmanned Aerial Vehicles (UAVs) as the use of drones continues to increase. The researchers focused on executing code on a commercially available drone, supporting…
-
Pub Crawl #75Pub Crawl summarizes, by hard problems, sets of publications that have been peer reviewed and presented at SoS conferences or referenced in current work. The topics are chosen for their usefulness for current researchers.
-
"Serious Vulnerability Exposes Admin Interface of Arcserve UDP Backup Solution"A new vulnerability, tracked as CVE-2023-26258, was identified in the web management interface of Arcserve UDP by security researchers at MDSec. The researchers noted that successfully exploiting the bug could allow an attacker to access the…
-
"Over 130 Organizations, Millions of Individuals Believed to Be Impacted by MOVEit Hack"More victims of the MOVEit hack have recently come to light, with a total of over 130 organizations and millions of individuals believed to be impacted. Brett Callow, a threat analyst at cybersecurity firm Emisoft, stated that he is aware of 138…
-
"Linux Version of Akira Ransomware Targets VMware ESXi Servers"The "Akira" ransomware operation now uses a Linux encryptor to encrypt VMware ESXi Virtual Machines (VMs) in double extortion attacks against companies globally. Akira first appeared in March 2023, targeting Windows systems in different industries,…
-
"North Korean Hacker Group Andariel Strikes With New EarlyRat Malware""Andariel," a threat actor aligned with North Korea, used "EarlyRat," a previously undocumented malware, in attacks exploiting the Log4j Log4Shell vulnerability. According to researchers, Andariel infects machines by executing a Log4j exploit, which then…
-
"Popular Generative AI Projects Pose Serious Security Threat"According to Rezilion, many popular generative Artificial Intelligence (AI) projects pose an increased security risk. Open source projects that use insecure generative AI and Large Language Models (LLMs) also have a poor security posture, resulting in a…