Aggregator
本周看什么 | 最近值得一看的 9 部作品
疑似APT-C-26(Lazarus)组织利用远程IT伪装部署监控程序的攻击行动分析
Cloudflare Outage: Internal Failure Shuts Down Sites, Exposing Hidden Security Gaps
A major outage in Cloudflare’s infrastructure became an unexpected test of resilience for countless companies. On 18 November,
The post Cloudflare Outage: Internal Failure Shuts Down Sites, Exposing Hidden Security Gaps appeared first on Penetration Testing Tools.
技术语境中那些熟悉又陌生的英语动词(三)
Xubuntu Download Page Hacked: Malicious File Distributed for Several Days
The Xubuntu team has released detailed information about the October incident during which the downloads page at https://xubuntu.org/download/
The post Xubuntu Download Page Hacked: Malicious File Distributed for Several Days appeared first on Penetration Testing Tools.
Прощай, Monitor Plus: приватность Firefox стала жертвой сомнительного прошлого подрядчика
New Sturnus Android Trojan Bypasses Signal/WhatsApp Encryption, Seizes Full Control
Cybersecurity experts have detailed a newly identified Android banking trojan called Sturnus, engineered to steal credentials and seize
The post New Sturnus Android Trojan Bypasses Signal/WhatsApp Encryption, Seizes Full Control appeared first on Penetration Testing Tools.
MEMINSPECT Proposed for Linux Kernel: Simplifies Memory Debugging & Post-Mortem Analysis
A series of patches proposing a MEMINSPECT mechanism for memory analysis and debugging has been submitted to the
The post MEMINSPECT Proposed for Linux Kernel: Simplifies Memory Debugging & Post-Mortem Analysis appeared first on Penetration Testing Tools.
应对5G架构变革:用实战课程夯实安全技能
被忽视的深海威胁:海事行业的无形网络战与系统化防护
Critics Say White House's Draft AI Order Is a Power Grab
A leaked draft executive order would empower federal agencies to override state AI laws, threatening federal funds for noncompliance and creating a litigation task force - drawing sharp backlash over executive overreach and potential harm to consumers.
$5M Settlement in Geisinger Health, Nuance Insider Breach
A federal court has granted preliminary approval of a $5 million settlement in class action litigation filed against Pennsylvania-based Geisinger Health and Nuance Communications - now part of Microsoft - involving a 2023 insider data breach affecting more than 1 million Geisinger patients.
ENISA Is Now a CVE Program Root
The European Union Agency for Cybersecurity is poised to take on a greater role in coordinating vulnerability disclosures across the trading bloc with its elevation as a "Root"-level participant in the Common Vulnerabilities and Exposures program.
ShinyHunters Hack Salesforce Instances Via Gainsight Apps
Customer relationship management giant Salesforce is again notifying customers that hackers may be stealing their data through a third-party app. The San Francisco company late Wednesday disclosed that apps published by Gainsight connected to Salesforce instances may have "enabled unauthorized access."
Google Cracks AirDrop: Pixel 10 Enables Seamless File Sharing with iPhone
Google has unexpectedly done what many had already given up hoping for: Android and AirDrop can now, at
The post Google Cracks AirDrop: Pixel 10 Enables Seamless File Sharing with iPhone appeared first on Penetration Testing Tools.
Windows 11 to Hide BSOD Crash Errors on Public Displays
Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors and signage. This new mode ensures that the dreaded Blue Screen of Death (BSOD) and other disruptive error dialogs are hidden from view on non-interactive displays. Whether the machine is powering a digital restaurant menu, an airport flight schedule, or […]
The post Windows 11 to Hide BSOD Crash Errors on Public Displays appeared first on Cyber Security News.
0 понятных слов, только IP-адреса: AMD зашифровала свои планы в Linux патчах
Skipping Threat Modeling? You’re Risking a Breach You Can’t Recover From
Even mature engineering teams often treat threat modeling as an optional exercise, relying instead on VAPT or other post-development assessments with the assumption that “we’ll fix issues later.” But this approach is risky and reactive. Threat modeling is fundamentally proactive: it compels teams to analyze data flows, trust boundaries, attack surfaces, and potential adversary actions […]
The post Skipping Threat Modeling? You’re Risking a Breach You Can’t Recover From appeared first on Kratikal Blogs.
The post Skipping Threat Modeling? You’re Risking a Breach You Can’t Recover From appeared first on Security Boulevard.