FreshRSS

πŸ”’
☐ β˜† βœ‡ WIRED

The Biggest Deepfake Porn Website Is Now Blocked in the UK

By Matt Burgess β€” April 19th 2024 at 16:54
The world's most-visited deepfake website and another large competing site are stopping people in the UK from accessing them, days after the UK government announced a crackdown.
☐ β˜† βœ‡ WIRED

The Trump Jury Has a Doxing Problem

By Andrew Couts β€” April 18th 2024 at 19:25
One juror in former US president Donald Trump’s criminal case in New York has been excused over fears she could be identified. It could get even messier.
☐ β˜† βœ‡ WIRED

The Real-Time Deepfake Romance Scams Have Arrived

By Matt Burgess β€” April 18th 2024 at 11:00
Watch how smooth-talking scammers known as β€œYahoo Boys” use widely available face-swapping tech to carry out elaborate romance scams.
☐ β˜† βœ‡ WIRED

Big Tech Says Spy Bill Turns Its Workers Into Informants

By Dell Cameron β€” April 17th 2024 at 18:11
One of Silicon Valley’s most influential lobbying arms joins privacy reformers in a fight against the Biden administration–backed expansion of a major US surveillance program.
☐ β˜† βœ‡ WIRED

Hackers Linked to Russia’s Military Claim Credit for Sabotaging US Water Utilities

By Andy Greenberg β€” April 17th 2024 at 10:00
Cyber Army of Russia Reborn, a group with ties to the Kremlin’s Sandworm unit, is crossing lines even that notorious cyberwarfare unit wouldn’t dare to.
☐ β˜† βœ‡ WIRED

Change Healthcare’s New Ransomware Nightmare Goes From Bad to Worse

By Eric Geller β€” April 16th 2024 at 19:09
A cybercriminal gang called RansomHub claims to be selling highly sensitive patient information stolen from Change Healthcare following a ransomware attack by another group in February.
☐ β˜† βœ‡ WIRED

US Senate to Vote on a Wiretap Bill That Critics Call β€˜Stasi-Like’

By Dell Cameron β€” April 16th 2024 at 17:02
A controversial bill reauthorizing the Section 702 spy program may force whole new categories of businesses to eavesdrop on the US government’s behalf, including on fellow Americans.
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

[Article] Sniping at web applications to discover input-handling vulnerabilities

By /u/daindragon2 β€” April 15th 2024 at 20:24

Web applications play a crucial role in modern businesses, offering various services and often exposing sensitive data that can be enticing to attackers. As a result, there is a growing interest in finding innovative approaches for discovering vulnerabilities in web applications. In the evolving landscape of web security, the realm of fuzz testing has garnered substantial attention for its effectiveness in identifying vulnerabilities. However, existing literature has often underemphasized the nuances of web-centric fuzzing methodologies. This article presents a comprehensive exploration of fuzzing techniques specifically tailored to web applications, addressing the gap in the current research. Our work presents a holistic perspective on web-centric fuzzing, introduces a modular architecture that improves fuzzing effectiveness, demonstrates the reusability of certain fuzzing steps, and offers an open-source software package for the broader security community. By addressing these key contributions, we aim to facilitate advancements in web application security, empower researchers to explore new fuzzing techniques, and ultimately enhance the overall cybersecurity landscape

submitted by /u/daindragon2
[link] [comments]
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

Customised CVE Notifier based on keywords

By /u/shantanu14g β€” April 15th 2024 at 14:00

I coded this over the weekend. It's my first hands-on experience with Golang, and I had fun.

This basically scrapes the RSS feed from vuldb.com and notifies on Slack when any CVEs matching the keywords are added.

Keywords can be any technology or product that you want to track, e.g., CVEs related to Apple, WordPress, Ivanti VPN, etc.

The intended users are bug bounty hunters who want to look out for interesting CVEs and organizations that want to take action when any CVE affecting them is released.

Feedback and criticism are always welcome.

Ideally, I would like to scrape the NVD API instead of vuldb, but I will work on that later.

submitted by /u/shantanu14g
[link] [comments]
☐ β˜† βœ‡ WIRED

The US Government Has a Microsoft Problem

By Eric Geller β€” April 15th 2024 at 10:30
Microsoft has stumbled through a series of major cybersecurity failures over the past few years. Experts say the US government’s reliance on its systems means the company continues to get a free pass.
☐ β˜† βœ‡ WIRED

How Israel Defended Against Iran's Drone and Missile Attack

By Brian Barrett β€” April 14th 2024 at 01:01
The Iron Dome, US allies, and long-range interceptor missiles all came into play.
☐ β˜† βœ‡ WIRED

Space Force Is Planning a Military Exercise in Orbit

By Stephen Clark, Ars Technica β€” April 13th 2024 at 11:30
Two satellites will engage in a β€œrealistic threat response scenario” when Victus Haze gets underway.
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

Security headers audit tool

By /u/SmokeyShark_777 β€” April 13th 2024 at 11:06

Hello guys! Here's a Go tool to check HTTP security headers insecure configuration. It supports Content-Security-Policy directives audit as well and can be used to assess multiple webpages/domains. If someone wants to collaborate or just leave feedback, here's the repo!

submitted by /u/SmokeyShark_777
[link] [comments]
☐ β˜† βœ‡ WIRED

Roku Breach Hits 567,000 Users

By Andy Greenberg, Andrew Couts β€” April 13th 2024 at 10:30
Plus: Apple warns iPhone users about spyware attacks, CISA issues an emergency directive about a Microsoft breach, and a ransomware hacker tangles with an unimpressed HR manager named Beth.
☐ β˜† βœ‡ WIRED

House Votes to Extendβ€”and Expandβ€”a Major US Spy Program

By Dell Cameron β€” April 12th 2024 at 19:30
The US House of Representatives voted on Friday to extend the Section 702 spy program. It passed without an amendment that would have required the FBI to obtain a warrant to access Americans’ information.
☐ β˜† βœ‡ WIRED

Change Healthcare Faces Another Ransomware Threatβ€”and It Looks Credible

By Andy Greenberg, Matt Burgess β€” April 12th 2024 at 18:25
Change Healthcare ransomware hackers already received a $22 million payment. Now a second group is demanding money, and it has sent WIRED samples of what they claim is the company's stolen data.
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

CVE 10.0 vulnerability in PAN-OS

By /u/kerubi β€” April 12th 2024 at 09:29

This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls with the configurations for both GlobalProtect gateway and device telemetry enabled.

No patch yet, apply mitigations. Actively exploited.

submitted by /u/kerubi
[link] [comments]
☐ β˜† βœ‡ WIRED

DuckDuckGo Is Taking Its Privacy Fight to Data Brokers

By Matt Burgess β€” April 11th 2024 at 12:00
Privacy-focused company DuckDuckGo is launching a tool to remove data from people-search websites, a VPN, and an identity theft restoration service.
☐ β˜† βœ‡ WIRED

Trump Loyalists Kill Vote on US Wiretap Program

By Dell Cameron β€” April 10th 2024 at 20:15
An attempt to reauthorize Section 702, the so-called crown jewel of US spy powers, failed for a third time in the House of Representatives after former president Donald Trump criticized the law.
☐ β˜† βœ‡ WIRED

How to Stop Your Data From Being Used to Train AI

By Matt Burgess, Reece Rogers β€” April 10th 2024 at 11:30
Some companies let you opt out of allowing your content to be used for generative AI. Here’s how to take back (at least a little) control from ChatGPT, Google’s Gemini, and more.
❌