News
-
"Hackers Rob Thousands of Coinbase Customers Using MFA Flaw"Hackers stole from 6,000 customers of Coinbase, which is the world's second-largest cryptocurrency exchange with nearly 68 million users worldwide. The hackers exploited a vulnerability to circumvent the company's SMS multi-factor authentication security…
-
"Widely Used Bitcoin ATMs Have Major Security Flaws, Researchers Warn"According to a new report from security researchers with the crypto exchange Kraken, many of the Bitcoin ATMs placed at gas stations, bars, malls, and more, across the U.S. contain security vulnerabilities, leaving them open to hacking. The number of…
-
"CISA Kicks Off Cybersecurity Awareness Month"The U.S. Homeland Security Department's Cybersecurity and Infrastructure Security Agency (CISA) has kicked off Cybersecurity Awareness Month. President Biden proclaimed October as Cybersecurity Awareness Month, calling on public and private sectors…
-
"New APT ChamelGang Targets Russian Energy, Aviation Orgs"A new APT group has emerged that is specifically targeting the fuel and energy complex and aviation industry in Russia, exploiting known vulnerabilities like Microsoft Exchange Server’s ProxyShell and leveraging both new and existing malware to…
-
"Scammers Capitalize on Release of New Bond Movie"Researchers from Kaspersky have found that cybercriminals are exploiting the long-awaited release of the new James Bond movie No Time to Die. Adversaries are taking advantage of the bigger than usual buzz around this particular Bond title by operating…
-
"Researchers Discover Vulnerability in Widely-Used Method for Securing Phone Data"Researchers at the Georgia Institute of Technology demonstrated an attack on two different types of low-end Android phones, a ZTE Zfive and an Alcatel Ideal. These attacks showed that one of the measures put in place to secure data on a low-end phone…
-
"Facebook Open-Sources 'Mariana Trench' Code Analysis Tool"Facebook has open-sourced Mariana Trench, a tool that has been used to find potentially dangerous security and privacy flaws in the company's Android and Java applications. The tool has already been trained by Facebook's security and software engineers.…
-
"The Simple, Yet Complex Nature of Social Engineering"According to the 2021 Cybersecurity Statistics report from Purplesec, nearly 100 percent of cyberattacks have relied on the performance of social engineering to manipulate employees within an organization to hand over passwords and other sensitive…
-
NSA Cybersecurity Speaker Series - Embracing a Zero Trust MindsetDr. Josiah Dykstra, host of NSA’s Cybersecurity Speaker Series, speaks with Randy Resnick, the NSA Zero Trust Strategic Lead about the principles of the Zero Trust cybersecurity model for securing enterprise networks. For more on cybersecurity at NSA,…
-
"Canadian Vaccine Passport App Exposes Data"Canadian vaccine passport app PORTpass may have exposed personal information belonging to hundreds of thousands of users. According to a report by CBC News, the app's operators left data, including names, identification documents, and email…
-
"Vulnerability Exposes iPhone Users to Payment Fraud"New research from the University of Birmingham and the University of Surrey has found that many iPhone users are vulnerable to payment fraud due to Apple Pay and Visa vulnerabilities. The researchers stated that they could bypass an iPhone’s Apple…
-
Pub Crawl #54Pub Crawl summarizes, by hard problems, sets of publications that have been peer reviewed and presented at SoS conferences or referenced in current work. The topics are chosen for their usefulness for current researchers.