The Cybersecurity (CS) Digest is a curated bi-weekly news summary for cybersecurity professionals. It is transmitted in an HTML-formatted email and provides links to articles and news summaries across a spectrum of cybersecurity topics.
CSIAC ANNOUNCEMENTS:
CSIAC Podcast Series – C++ Models - CSIAC
This is a 6-part video series entitled C++ Models by Dr. James Fawcett. Each video describes different conceptual models underlying the C++ programming language. Discussion with exemplars is used to illustrate how the models apply to aspects of the language for effective use. In this series, eight fundamental models are covered: Code Structure, Compilation, Program Execution, Use of Memory, Classes, Object Model, and Templates.
CSIAC Webinar, TODAY @ 1300 EDT: USAF Software Assurance (SwA) Training Approach - CSIAC
This presentation will examine the 76 SWEG approach from selection, onboarding, integration, and continuing education. Are we doing all the right things? The answer to that should be represented by the performance of the resilient products that we deliver. We haven't gotten all the training right, but our evolutions are continuing to bring us closer.
RECENT HEADLINES:
DHS’s cyber division has stepped up protections for coronavirus research, official says - Cyber Scoop
The Department of Homeland Security's cybersecurity wing says it has put heightened defense measures for health-care-focused organizations and research facilities in place as foreign government-backed hackers continue to try to steal U.S. coronavirus research.
Tags: Coronavirus, Department of Homeland Security (DHS)
Riding the State Unemployment Fraud ‘Wave’ - Krebs on Security
When a reliable method of scamming money out of people, companies or governments becomes widely known, underground forums and chat networks tend to light up with activity as more fraudsters pile on to claim their share. And that's exactly what appears to be going on right now as multiple U.S. states struggle to combat a tsunami of phony Pandemic Unemployment Assistance (PUA) claims.
Tags: Computer Fraud, Coronavirus, Unemployment Fraud
Ukraine Nabs Suspect in 773M Password ‘Megabreach’ - Krebs on Security
In January 2019, dozens of media outlets raised the alarm about a new "megabreach" involving the release of some 773 million stolen usernames and passwords that was breathlessly labeled "the largest collection of stolen data in history."
Tags: Data Breach
Hackers Target Oil Producers During COVID-19 Slump - Security Affairs
Recent research shows that the oil industry - already experiencing difficulties due to COVID-19 - must remain abreast of threats to stay safe from hackers.
Tags: Coronavirus, Oil Industry
Red Cross leads call to halt healthcare cyberattacks - TechRadar
While the world has been busy fighting the coronavirus pandemic, attacks on various healthcare institutions like hospitals, research organisations, healthcare officials and other staff have increased.
Tags: Coronavirus
RangeAmp attacks can take down websites and CDN servers - ZDNet
A team of Chinese academics has found a new way to abuse HTTP packets to amplify web traffic and bring down websites and content delivery networks (CDNs).
Tags: DDoS, RangeAmp
Hong Kong demand for VPNs surges on heels of China’s plan for national security laws - Reuters
Demand for virtual private networks in Hong Kong surged more than six-fold last Thursday as Beijing proposed tough new national security laws for the financial hub, reflecting concerns over internet privacy, according to a VPN provider.
Tags: Hong Kong, VPN
Bugs in open-source libraries impact 70% of modern software - Security Affairs
70 percent of mobile and desktop applications that today we use are affected at least by one security flaw that is present in open-source libraries.
Tags: Open Source Software, Vulnerabilities
Docker fixes Windows client bug letting programs run as SYSTEM - Bleeping Computer
Docker fixed a security vulnerability in Docker for Windows that allowed attackers on the system to execute commands with the highest privileges.
Tags: CVE-2020-11492, Docker
eBay port scans visitors’ computers for remote access programs - Bleeping Computer
When visiting the eBay.com site, a script will run that performs a local port scan of your computer to detect remote support and remote access applications.
Tags: eBay, Port scan, Privacy
CSIAC Supported Communities
CSIAC supports several communities of practice, such as the Cyber Community of Interest (COI) Group and research & development working groups.
Technical Resources, Policy and Guidance
This list of related sites provides additional sources to pursue the topic of Cybersecurity. The sites include Government organizations, including federal agencies, Department of Defense and military service agencies, commercial organizations, and academic institutions.
The CS Digest provides links to third party Websites. The CSIAC is not responsible for the availability of, and content provided on, third party Websites. You should refer to the policies posted by other Websites regarding their privacy and other topics before you use them. The CSIAC is not responsible for third party content accessible through the CSIAC CS Digest, including opinions, advice, statements, advertisements and endorsements, and you bear all risks associated with the use of such content.
Leave a Comment
You must be logged in to post a comment.