Aggregator
NIST Releases First Post-Quantum Encryption Algorithms
From the Federal Register:
After three rounds of evaluation and analysis, NIST selected four algorithms it will standardize as a result of the PQC Standardization Process. The public-key encapsulation mechanism selected was CRYSTALS-KYBER, along with three digital signature schemes: CRYSTALS-Dilithium, FALCON, and SPHINCS+.
These algorithms are part of three NIST standards that have been finalized:
- FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard
- FIPS 204: Module-Lattice-Based Digital Signature Standard
- FIPS 205: Stateless Hash-Based Digital Signature Standard...
The post NIST Releases First Post-Quantum Encryption Algorithms appeared first on Security Boulevard.
5 SecOps automation challenges — and how to overcome them
LG Simple Editor 3.21.0 Command Injection
Microsoft disables BitLocker security fix, advises manual mitigation
OpenMetadata 1.2.3 Authentication Bypass / SpEL Injection
Cryptography for Hackers
Microsoft disables BitLocker security fix, advises manual mitigation
Белый дом готовится к киберкатастрофам
Iranian APT42 Group Launch A Massive Phishing Campaign To Attack U.S. Presidential Election
APT42 is an APT group that is believed to be backed by the Iranian government, and this group primarily focuses on cyber espionage. Besides this, APT42 is also well-known for other illicit activities. Apart from cyber espionage, they also conduct phishing campaigns, and data exfiltration against a wide range of entities. However, specifically, they target […]
The post Iranian APT42 Group Launch A Massive Phishing Campaign To Attack U.S. Presidential Election appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-6347 | Nissan Altima 2022 Blind Spot Detection Sensor ECU Firmware denial of service
CVE-2024-43373 | j4k0xb webcrack up to 2.14.0 on Windows path traversal
CVE-2024-7845 | SourceCodester Online Graduate Tracer System 1.0 fetch_it.php request sql injection
CVE-2024-7844 | SourceCodester Online Graduate Tracer System 1.0 add_acc.php name/user/position cross site scripting
CVE-2024-7843 | SourceCodester Online Graduate Tracer System 1.0 exportcs.php information disclosure
CVE-2024-7842 | SourceCodester Online Graduate Tracer System 1.0 export_it.php information disclosure
Advanced ValleyRAT Campaign Hits Windows Users in China
USENIX Security ’23 – Strategies and Vulnerabilities of Participants in Venezuelan Influence Operations
Authors/Presenters:Ruben Recabarren, Bogdan Carbunar, Nestor Hernandez, and Ashfaq Ali Shafin,
Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the organizations YouTube channel.
The post USENIX Security ’23 – Strategies and Vulnerabilities of Participants in Venezuelan Influence Operations appeared first on Security Boulevard.