I added hover over text, it messed up some of the formatting. But whatever, I gotta go write my TPS report.

Krebs on Security

2024-04-30 - Man Who Mass-Extorted Psychotherapy Patients Gets Six Years
2024-04-29 - FCC Fines Major U.S. Wireless Carriers for Selling Customer Location Data

Dark Reading

The Hacker News [ THN ] - Best Security Blog

2024-05-02 - Popular Android Apps Like Xiaomi, WPS Office Vulnerable to File Overwrite Flaw
2024-05-02 - Ukrainian REvil Hacker Sentenced to 13 Years and Ordered to Pay $16 Million
2024-05-02 - When is One Vulnerability Scanner Not Enough?
2024-05-02 - Dropbox Discloses Breach of Digital Signature Service Affecting All Users
2024-05-02 - New "Goldoon" Botnet Targets D-Link Routers With Decade-Old Flaw
2024-05-02 - CISA Warns of Active Exploitation of Severe GitLab Password Reset Vulnerability
2024-05-02 - New Cuttlefish Malware Hijacks Router Connections, Sniffs for Cloud Credentials
2024-05-01 - Bitcoin Forensic Analysis Uncovers Money Laundering Clusters and Criminal Proceeds
2024-05-01 - Android Malware Wpeeper Uses Compromised WordPress Sites to Hide C2 Servers
2024-05-01 - How to Make Your Employees Your First Line of Cyber Defense
2024-05-01 - ZLoader Malware Evolves with Anti-Analysis Trick from Zeus Banking Trojan
2024-05-01 - Ex-NSA Employee Sentenced to 22 Years for Trying to Sell U.S. Secrets to Russia
2024-04-30 - Millions of Malicious 'Imageless' Containers Planted on Docker Hub Over 5 Years
2024-04-30 - U.S. Government Releases New AI Security Guidelines for Critical Infrastructure
2024-04-30 - Considerations for Operational Technology Cybersecurity
2024-04-30 - New U.K. Law Bans Default Passwords on Smart Devices Starting April 2024
2024-04-29 - Google Prevented 2.28 Million Malicious Apps from Reaching Play Store in 2023
2024-04-29 - China-Linked 'Muddling Meerkat' Hijacks DNS to Map Internet on Global Scale
2024-04-29 - Navigating the Threat Landscape: Understanding Exposure Management, Pentesting, Red Teaming and RBVM
2024-04-29 - New R Programming Vulnerability Exposes Projects to Supply Chain Attacks
2024-04-29 - Sandbox Escape Vulnerabilities in Judge0 Expose Systems to Complete Takeover
2024-04-28 - Okta Warns of Unprecedented Surge in Proxy-Driven Credential Stuffing Attacks

Schneier on Security

2024-05-02 - ban default passwords on IoT devices.

On Monday, the United Kingdom became the first country in the world to ban default guessable usernames and passwords from these IoT devices. Unique passwords installed by default are still permitted.

The Product Security and Telecommunications Infrastructure Act 2022 (PSTI) introduces new minimum-security standards for manufacturers, and demands that these companies are open with consumers about how long their products will receive security updates for.

The UK may be the first country, but as far as I know, California is the first jurisdiction. It ...

">The UK Bans Default Passwords
2024-04-30 - tricked a company into believing they were dealing with a BBC presenter. They faked her voice, and accepted money intended for her.

">AI Voice Scam
2024-04-29 - pull WhatsApp out of India if the courts try to force it to break its end-to-end encryption.

">WhatsApp in India
2024-04-29 - secret code out of whale song.

The basic plan was to develop coded messages from recordings of whales, dolphins, sea lions, and seals. The submarine would broadcast the noises and a computer—the Combo Signal Recognizer (CSR)—would detect the specific patterns and decode them on the other end. In theory, this idea was relatively simple. As work progressed, the Navy found a number of complicated problems to overcome, the bulk of which centered on the authenticity of the code itself.

The message structure couldn’t just substitute the moaning of a whale or a crying seal for As and Bs or even whole words. In addition, the sounds Navy technicians recorded between 1959 and 1965 all had natural background noise. With the technology available, it would have been hard to scrub that out. Repeated blasts of the same sounds with identical extra noise would stand out to even untrained sonar operators...

">Whale Song Code

ThreatPost

Sydney Morning Herald

New York Times

2024-05-02 - Judge Grills U.S. and Google on Antitrust Claims
2024-05-02 - Google Antitrust Trial Concludes With Closing Arguments
2024-05-02 - The Judge Deciding Google’s Landmark Antitrust Case
2024-05-01 - Meta and Google Are Betting on AI Voice Assistants. Will They Take Off?
2024-05-02 - Campus Protests Give Russia, China and Iran Fuel to Exploit U.S. Divide
2024-04-30 - Amazon Reports $143.3 Billion in Revenue for First Quarter of 2024
2024-05-01 - Tesla Fires Charger Team Amid Hundreds of Layoffs
2024-04-30 - Binance Founder Sentenced to 4 Months in Prison
2024-04-30 - Meet the Men Who Eat Meat
2024-04-30 - ‘Smartphones on Wheels’ Draw Attention From Regulators
2024-04-30 - Killer Asteroid Hunters Spot 27,500 Overlooked Space Rocks
2024-04-30 - Getir, a Rapid Grocery-Delivery Service, Exits the U.S. and Europe
2024-04-30 - Bumble Tells Women They No Longer Have to Make the First Move
2024-04-30 - Meta Faces EU Investigation Over Election Disinformation
2024-04-30 - From Baby Talk to Baby A.I.
2024-04-30 - Even as He Faces Prison Time, Binance’s Founder Plans a Comeback
2024-04-29 - A.I. Start-Ups Face a Rough Financial Reality Check
2024-04-29 - Friends From the Old Neighborhood Turn Rivals in Big Tech’s A.I. Race

Wall Street Journal

2024-05-02 - SK Hynix's AI-Related Memory Chips Sold Out for Year
2024-05-01 - Microsoft to Invest $2.2 Billion in AI Infrastructure in Malaysia
2024-05-01 - For Truly Envy-Inducing Vacation Pictures, Put the Phone Away
2024-05-01 - AI StartupCoreWeaveNearly Triples Valuation to $19 Billion in Five Months
2024-04-30 - Microsoft to Invest $1.7 Billion in AI Infrastructure in Indonesia
2024-04-29 - Samsung's Net Profit Quadruples as Chip Business Rebounds
2024-04-29 - How Big Data Centers Are Slowing the Shift to Clean Energy
2024-04-28 - Why Turning It Off and Turning It Back On Is Gadget-Fixing Magic
2024-04-28 - How TikTok Lost the War in Washington

BBC

2024-05-02 - TikTok and Universal settle music royalties dispute
2024-05-02 - Uber faces £250m London black cab drivers case
2024-05-01 - Apple working to fix alarming iPhone issue
2024-05-01 - OnlyFans investigated over children accessing porn
2024-05-01 - Tesla staff say entire Supercharger team fired
2024-04-30 - Tens of millions secretly use WhatsApp despite bans
2024-04-30 - Binance crypto boss sentenced to 4 months in prison
2024-05-01 - Beijing tightens grip on China social media giants
2024-04-30 - Hacker jailed for blackmailing therapy patients
2024-04-30 - Meta faces EU probe over Russian disinformation
2024-04-30 - Bumble boss: What women in tech can learn from me
2024-04-30 - Tesla China rival BYD sees profits and sales fall
2024-04-29 - Tesla shares jump after reports of China deal
2024-04-29 - US probes Ford hands-free driving tech after crashes
2024-04-28 - New law aims to protect devices from hackers
2024-04-28 - Musk in China to discuss enabling Full Self Driving
2024-04-28 - Airline keeps mistaking 101-year-old woman for baby
2024-04-30 - Tech Life: TikTok world
2024-05-01 - The insect farmers turning to AI to help lower costs
2024-04-29 - After 20 years, what next for World of Warcraft?

SecurityBrief AU

2024-05-02 - Illumio & Wiz partner to boost cloud security resilience
2024-05-02 - Secure Code Warrior launches industry-first SCW Trust Score for developer teams
2024-05-02 - Halcyon introduces Ransomware Warranty Program for enhanced protection
2024-05-02 - Senetas lands record-breaking Middle Eastern encryption hardware order
2024-05-02 - What is vishing? Tips to spot and avoid voice phishing scams
2024-05-02 - Espionage breaches account for 25% in APAC, report reveals
2024-05-02 - Australian firms see customer rates hit by increasing fraud
2024-05-02 - SecurityBridge teams up with Taciti for advanced SAP security solutions
2024-05-02 - The remote desktop tools most targeted by attackers in the last year
2024-05-02 - Let’s dive in! Amperity’s CTO on Gen AI as catalyst for digital transformation

ITNews AU

2024-05-02 - Man arrested after NSW, ACT club data leak
2024-05-02 - NAB tech and investment spend up $80 million
2024-05-02 - NSW Police tries to get website that leaked club data shut down
2024-05-02 - Federal Courts to review endpoint detection and response
2024-05-01 - Qantas app displays wrong flyer info to users
2024-05-01 - Thales could be tempted by some Atos defence assets
2024-05-01 - Amaysim adopts CNAPP to shift its cloud security model
2024-04-30 - UnitedHealth hackers used Citrix vulnerability to break in
2024-04-29 - Teamwork pays off as scam losses fall to $2.74 billion
2024-04-29 - State of Security 2024: XDR
2024-04-29 - State of Security 2024: Email and Collaboration
2024-04-29 - State of Security 2024: Identity & Access Management
2024-04-29 - State of Security 2024: Network & Infrastructure
2024-04-29 - State of Security 2024: SASE
2024-04-29 - State of Security 2024: Endpoint Security
2024-04-29 - State of Security 2024: Cloud Security
2024-04-29 - State of Security 2024
2024-04-29 - AustralianSuper hunts for new CISO

BleepingComputer

2024-05-02 - Microsoft warns of "Dirty Stream" attack impacting Android apps
2024-05-02 - REvil hacker behind Kaseya ransomware attack gets 13 years in prison
2024-05-02 - Microsoft won't fix Windows 0x80070643 errors, manual fix required
2024-05-02 - Cybersecurity consultant arrested after allegedly extorting IT firm
2024-05-01 - HPE Aruba Networking fixes four critical RCE flaws in ArubaOS
2024-05-01 - DropBox says hackers stole customer data, auth secrets from eSignature service
2024-05-01 - US govt warns of pro-Russian hacktivists targeting water facilities
2024-05-01 - Panda Restaurants discloses data breach after corporate systems hack
2024-05-01 - French hospital CHC-SV refuses to pay LockBit extortion demand
2024-05-01 - CISA says GitLab account takeover bug is actively exploited in attacks
2024-05-01 - Microsoft: April Windows Server updates cause NTLM auth failures
2024-05-01 - Microsoft says April Windows updates break VPN connections
2024-05-01 - Qantas app exposed sensitive traveler details to random users

/r/NetSec

2024-05-02 - /u/thewatcher_
[link] [comments]">It’s Morphin’ Time: Self-Modifying Code Sections with WriteProcessMemory for EDR Evasion
2024-04-30 -

This tutorial gives an example showing how to fuzz a function out of a compiled binary using AFL's QEMU mode.

submitted by
/u/cy1337
[link] [comments]">A Basic Guide to AFL QEMU
2024-04-30 - /u/SRMish3
[link] [comments]">Nearly 20% of Docker Hub Repositories were used to spread malware & phishing scams
2024-04-30 - /u/xiongchiamiov
[link] [comments]">How an empty S3 bucket can make your AWS bill explode
2024-04-30 - /u/alon_za
[link] [comments]">Your NVMe Had Been Syz’ed: Fuzzing NVMe-oF/TCP with Syzkaller
2024-04-30 - /u/louis11
[link] [comments]">Exploit Education :: Andrew Griffiths' Exploit Education
2024-04-30 - /u/Lightricks_Tech
[link] [comments]">How Not To Protect Your Android Applications
2024-04-29 - /u/TheDFIRReport
[link] [comments]">From IcedID to Dagon Locker Ransomware in 29 Days
2024-04-29 - /u/clod81
[link] [comments]">LSASS rings KsecDD ext. 0 - Overview of the recent KexecDD exploit
2024-04-29 - /u/_pimps
[link] [comments]">Judge0 Sandbox Escape - CVE-2024-29021, CVE-2024-28185 and CVE-2024-28189
2024-04-28 - /u/nindustries
[link] [comments]">Just-in-Time admin and production access using Azure PIM

/r/InfoSecNews

2024-05-02 - 'DuneQuixote' Shows Stealth Cyberattack Methods Are Evolving. Can Defenders Keep Up? submitted by /u/quellaman
[link] [comments] ">'DuneQuixote' Shows Stealth Cyberattack Methods Are Evolving. Can Defenders Keep Up?
2024-05-02 - DropBox says hackers stole customer data, auth secrets from eSignature service submitted by /u/quellaman
[link] [comments] ">DropBox says hackers stole customer data, auth secrets from eSignature service
2024-05-01 - US govt warns of pro-Russian hacktivists targeting water facilities submitted by /u/quellaman
[link] [comments] ">US govt warns of pro-Russian hacktivists targeting water facilities
2024-05-02 - HPE Aruba Networking fixes four critical RCE flaws in ArubaOS submitted by /u/quellaman
[link] [comments] ">HPE Aruba Networking fixes four critical RCE flaws in ArubaOS
2024-05-01 - 'Cuttlefish' Zero-Click Malware Steals Private Cloud Data submitted by /u/quellaman
[link] [comments] ">'Cuttlefish' Zero-Click Malware Steals Private Cloud Data
2024-05-01 - ZLoader Malware Evolves with Anti-Analysis Trick from Zeus Banking Trojan submitted by /u/quellaman
[link] [comments] ">ZLoader Malware Evolves with Anti-Analysis Trick from Zeus Banking Trojan
2024-05-01 - Lawsuits and Company Devaluations Await For Breached Firms submitted by /u/quellaman
[link] [comments] ">Lawsuits and Company Devaluations Await For Breached Firms
2024-05-01 - Qantas app exposed sensitive traveler details to random users submitted by /u/quellaman
[link] [comments] ">Qantas app exposed sensitive traveler details to random users
2024-05-01 - Panda Restaurants discloses data breach after corporate systems hack submitted by /u/quellaman
[link] [comments] ">Panda Restaurants discloses data breach after corporate systems hack
2024-05-01 - French hospital CHC-SV refuses to pay LockBit extortion demand submitted by /u/quellaman
[link] [comments] ">French hospital CHC-SV refuses to pay LockBit extortion demand
2024-05-01 - /u/jamessonnycrockett
[link] [comments]">New Muddling Meerkat Group Suspected of Espionage via Great Firewall of China
2024-04-30 - /u/quellaman
[link] [comments]">Notorious Finnish Hacker sentenced to more than six years in prison
2024-04-30 - R language flaw allows code execution via RDS/RDX files submitted by /u/quellaman
[link] [comments] ">R language flaw allows code execution via RDS/RDX files
2024-04-30 - Attackers Planted Millions of Imageless Repositories on Docker Hub submitted by /u/quellaman
[link] [comments] ">Attackers Planted Millions of Imageless Repositories on Docker Hub
2024-04-30 - New Latrodectus malware attacks use Microsoft, Cloudflare themes submitted by /u/quellaman
[link] [comments] ">New Latrodectus malware attacks use Microsoft, Cloudflare themes
2024-04-30 - Google now pays up to $450,000 for RCE bugs in some Android apps submitted by /u/quellaman
[link] [comments] ">Google now pays up to $450,000 for RCE bugs in some Android apps
2024-04-30 - Change Healthcare hacked using stolen Citrix account with no MFA submitted by /u/quellaman
[link] [comments] ">Change Healthcare hacked using stolen Citrix account with no MFA
2024-04-30 - /u/quellaman
[link] [comments]">Man Who Mass-Extorted Psychotherapy Patients Gets Six Years
2024-04-30 - New Wpeeper Android malware hides behind hacked WordPress sites submitted by /u/quellaman
[link] [comments] ">New Wpeeper Android malware hides behind hacked WordPress sites
2024-04-30 - NCSC: New UK law bans default passwords on smart devices submitted by /u/quellaman
[link] [comments] ">NCSC: New UK law bans default passwords on smart devices
2024-04-30 - KapeKa Backdoor: Russian Threat Actor Group’s Recent Attacks submitted by /u/quellaman
[link] [comments] ">KapeKa Backdoor: Russian Threat Actor Group’s Recent Attacks
2024-04-30 - R Programming Bug Exposes Orgs to Vast Supply Chain Risk submitted by /u/quellaman
[link] [comments] ">R Programming Bug Exposes Orgs to Vast Supply Chain Risk
2024-04-30 - Muddling Meerkat hackers manipulate DNS using China’s Great Firewall submitted by /u/quellaman
[link] [comments] ">Muddling Meerkat hackers manipulate DNS using China’s Great Firewall
2024-04-29 - Cyber-Partisans hacktivists claim to have breached Belarus KGB submitted by /u/quellaman
[link] [comments] ">Cyber-Partisans hacktivists claim to have breached Belarus KGB
2024-04-29 - London Drugs pharmacy chain closes stores after cyberattack submitted by /u/quellaman
[link] [comments] ">London Drugs pharmacy chain closes stores after cyberattack