Sat.Jul 27, 2024

article thumbnail

Weekly Update 410

Troy Hunt

Who would have thought that just a few hours after recording the previous week's video, the world would descend into what has undoubtedly become the largest IT outage we've ever seen: I don’t think it’s too early to call it: this will be the largest IT outage in history — Troy Hunt (@troyhunt) July 19, 2024 By virtue of the CrowdStrike incident occurring in friendly office hours for my corner of the world, I was able to get a thread on it going pretty early on.

Media 256
article thumbnail

Ukraine’s cyber operation shut down the ATM services of major Russian banks

Security Affairs

Ukraine launched a massive cyber operation that shut down the ATM services of the biggest Russian banks on July 27, reported the Kyiv Post. Ukraine has launched a massive cyberattack against ATMs of Russian banks, the cyber operation began on July 23. “This is an opportune moment to fully implement the Kremlin’s long-desired ‘import substitution’ in the form of wooden abacuses, paper savings books, and cave paintings for accounting.” reported the KyivPost. “In Russia, it has al

Banking 145
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

WhatsApp for Windows lets Python, PHP scripts execute with no warning

Bleeping Computer

A security issue in the latest version of WhatsApp for Windows allows sending Python and PHP attachments that are executed without any warning when the recipient opens them. [.

144
144
article thumbnail

BSNL Data Breach: State Telecom Giant Exposed on Hacker Forum

Penetration Testing

On May 27, a user with the alias “kiberphant0m” on Breach Forums, a site renowned among hackers, offered for sale data allegedly hacked from Bharat Sanchar Nigam Limited (BSNL) for $5000. Bharat Sanchar Nigam... The post BSNL Data Breach: State Telecom Giant Exposed on Hacker Forum appeared first on Cybersecurity News.

article thumbnail

Why Giant Content Libraries Do Nothing for Your Employees’ Cyber Resilience

Many cybersecurity awareness platforms offer massive content libraries, yet they fail to enhance employees’ cyber resilience. Without structured, engaging, and personalized training, employees struggle to retain and apply key cybersecurity principles. Phished.io explains why organizations should focus on interactive, scenario-based learning rather than overwhelming employees with excessive content.

article thumbnail

X begins training Grok AI with your posts, here's how to disable

Bleeping Computer

X has quietly begun training its Grok AI chat platform using members' public posts without first alerting anyone that it is doing it by default. Here's how to block Grok from using your data. [.

article thumbnail

W2 Form Phishing Campaign Delivers Brute Ratel and Latrodectus Malware

Penetration Testing

Rapid7, a leading cybersecurity firm, has issued a warning about a new phishing campaign targeting individuals seeking W2 tax forms online. The campaign leverages fake IRS websites that appear in Bing search results, tricking... The post W2 Form Phishing Campaign Delivers Brute Ratel and Latrodectus Malware appeared first on Cybersecurity News.

LifeWorks

More Trending

article thumbnail

The best cheap gaming PCs of 2024: Expert recommended

Zero Day

I found some of the best cheap gaming PCs to help you find the right rig for your budget, so you don't have to sacrifice quality for price.

75
article thumbnail

Palo Alto Networks’ AI-Powered Tool Exposes 15 Vulnerabilities in Easy!Appointments

Penetration Testing

Palo Alto Networks is actively developing security technologies leveraging artificial intelligence. In 2023, the company’s researchers created an automated tool for detecting BOLA (Broken Object-Level Authorization) vulnerabilities. The vulnerability detection tool is based on... The post Palo Alto Networks’ AI-Powered Tool Exposes 15 Vulnerabilities in Easy!

article thumbnail

Stop X’s Grok AI From Training on Your Tweets

WIRED Threat Level

Plus: More Pegasus spyware controversy, a major BIOS controversy, and more of the week’s top security news.

Spyware 64
article thumbnail

USENIX Security ’23 – Hiding in Plain Sight: An Empirical Study of Web Application Abuse in Malware

Security Boulevard

Authors/Presenters:Mingxuan Yao, Jonathan Fuller, Ranjita Pai Kasturi, Saumya Agarwal, Amit Kumar Sikder, Brendan Saltaformaggio Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott ; and via the organizations YouTube channel.

Malware 64
article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

This power station has an irreplaceable emergency feature

Zero Day

The Vtoman FlashSpeed 1500 is a portable power station with tons of power and thoughtful design. Its fast-charging feature is one of the best I've seen.

52
article thumbnail

I can't recommend this rugged power station enough to drone users, and it's now $300 off

Zero Day

The latest DJI Power 1000 is specifically designed for drones but is strong enough to power most high-watt devices, as I found in testing.

40