Cybersecurity

https://www.bleepingcomputer.com/news/security/intel-amd-cpus-on-linux-impacted-by-newly-disclosed-spectre-bypass/

> he latest generations of Intel processors, including Xeon chips, and AMD's older microarchitectures on Linux are vulnerable to new speculative execution attacks that bypass existing ‘Spectre’ mitigations.

48
7
www.darkreading.com

> Microsoft researchers toyed with app permissions to uncover CVE-2024-44133, using it to access sensitive user data. Adware merchants may have as well.

30
2
techcrunch.com

> Missing logs could make it more difficult to identify unauthorized access to the customers' networks during that two-week window.

62
4
https://www.bleepingcomputer.com/news/security/eset-partner-breached-to-send-data-wipers-to-israeli-orgs/

> Hackers breached ESET's exclusive partner in Israel to send phishing emails to Israeli businesses that pushed data wipers disguised as antivirus software for destructive attacks.

13
0

I'm not in the security field so sorry if I seem like a newbie. Not sure where else to ask. I setup my own email domain thing with the help of some kind Lemmy folk. I'm on Namecheap, it was a little tricky for me to set up but it seems to have been working out great. But yesterday, and again today I got this notice from DMARC that Mail . ru is doing stuff with my account. advice I was able to google suggest I needed to change a setting from "none" to "reject". can anyone tell me if I've done this right? also has any damage been done by me not having this set sooner?

8
1
www.csoonline.com

> The research team, led by Wang Chao from Shanghai University, found that D-Wave’s quantum computers can optimize problem-solving in a way that makes it possible to attack encryption methods such as RSA. Paper: http://cjc.ict.ac.cn/online/onlinepaper/wc-202458160402.pdf Follow up to https://lemmy.ca/post/30853830

52
19
https://www.bleepingcomputer.com/news/security/new-fastcash-malware-linux-variant-helps-steal-money-from-atms/

> North Korean hackers are using a new Linux variant of the FASTCash malware to infect the payment switch systems of financial institutions and perform unauthorized cash withdrawals.

15
0
securityonline.info

EDRSilencer “disrupts the transmission of telemetry or alerts to EDR management consoles,” rendering these security tools ineffective at identifying and removing malware. By leveraging the Windows Filtering Platform (WFP), EDRSilencer blocks network communication from processes associated with various EDR products, creating a blind spot in an organization’s security defenses.

4
0
gist.github.com

> 1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies - zendesk.md

79
11