News
-
"BIND Vulnerabilities Expose DNS Servers to Remote Attacks"The Internet Systems Consortium (ISC) released updates for the BIND DNS software, patching vulnerabilities that could allow threat actors to perform denial-of-service (DoS) attacks and remote code execution. One of the flaws earned a CVSS score of 8.1.…
-
"Emotet Group Harvested Over 4.3 Million Victim Emails"Researchers have discovered that the threat actors behind the notorious Emotet botnet managed to collect over four million victim email addresses over the past few years. In all, 4,324,770 email addresses were found from a wide range of countries…
-
Pub Crawl #49Pub Crawl summarizes, by hard problems, sets of publications that have been peer reviewed and presented at SoS conferences or referenced in current work. The topics are chosen for their usefulness for current researchers.
-
"Penetration Testing Leaving Organizations With Too Many Blind Spots"Researchers at Informa Tech surveyed enterprises with 3,000 or more employees. They found that 70 percent of organizations perform penetration tests as a way to measure their security posture and 69 percent to prevent breaches, yet only 38 percent test…
-
"How to Keep Automated Electric Vehicles Safe"Researchers at the University of Georgia (UGA) have identified weaknesses that pose a threat to the safety and efficiency of automated electric vehicles. In a new paper published in the IEEE Journal of Emerging and Selected Topics in Power Electronics,…
-
"Expect an Increase in Attacks on AI Systems"There has been an increase in research surrounding methods of executing attacks against Machine Learning (ML) and Artificial Intelligence (AI) systems, with nearly 2,000 papers published on the topic in one repository over the last ten years. However,…
-
"CISA, NIST Provide New Resource on Software Supply Chain Attacks"The US Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have released a joint document providing information on software supply chain attacks, the risks presented by such attacks, and…
-
Cyber Scene #55 - Cyber Meteorology - Part One: The Ghost of Cold War PastCyber Scene #55 - Cyber Meteorology - Part One: The Ghost of Cold War Past
-
SoS Musings #48 - Ready to Embrace Zero Trust Security?SoS Musings #48 - Ready to Embrace Zero Trust Security?
-
Cybersecurity Snapshots #17 - DoppelPaymer Ransomware GangCybersecurity Snapshots #17 - DoppelPaymer Ransomware Gang
-
Spotlight on Lablet Research #17 - Scalable Trust Semantics and InfrastructureSpotlight on Lablet Research #17 - Project: Scalable Trust Semantics and Infrastructure
-
"Ransomware Group Threatens DC Cops with Informant Data Leak"Washington DC’s police department has reportedly been hit by Russian-speaking ransomware threat actors who claim to have stolen sensitive information. The group behind the attack is called Babuk. The Babuk group has given the police three…