Source: www.hackerone.com – Author: HackerOne. Addressing security risks at scale is more important than ever. With a global pandemic accelerating digital transformations, organizations are shipping new...
Day: October 24, 2024
Cisco ASA, FTD Software Under Active VPN Exploitation – Source: www.darkreading.com
Source: www.darkreading.com – Author: Dark Reading Staff Source: Palamarchuk via Shutterstock Cisco has rushed a patch for a brute-force denial-of-service (DoS) vulnerability in its VPN that’s...
AI Chatbots Ditch Guardrails After ‘Deceptive Delight’ Cocktail – Source: www.darkreading.com
Source: www.darkreading.com – Author: Tara Seals, Managing Editor, News, Dark Reading Source: Brent Hofacker via Alamy Stock Photo An artificial intelligence (AI) jailbreak method that mixes...
Why Cybersecurity Acumen Matters in the C-Suite – Source: www.darkreading.com
Source: www.darkreading.com – Author: Erik Gaston Erik Gaston, CIO & Vice President of Global Executive Engagement, Tanium October 24, 2024 6 Min Read Source: Stephen Barnes/Business...
‘Prometei’ Botnet Spreads Its Cryptojacker Worldwide – Source: www.darkreading.com
Source: www.darkreading.com – Author: Nate Nelson, Contributing Writer Source: Artimages via Alamy Stock Photo An 8-year-old modular botnet is still kicking, spreading a cryptojacker and Web...
Codasip Donates Tools to Develop Memory-Safe Chips – Source: www.darkreading.com
Source: www.darkreading.com – Author: Dark Reading Staff Source: Mentor58 via Alamy Stock Photo German processor design company Codasip has donated its latest RISC-V software development kit...
What Is PCI Compliance? A Simple Guide for Businesses – Source: www.techrepublic.com
Source: www.techrepublic.com – Author: Ian Agar You likely accept credit and debit card payments every day. But with so much sensitive data, you need robust protection...
Get Advanced Ad Blocking and Superior Data Privacy Tools for Just $11 – Source: www.techrepublic.com
Source: www.techrepublic.com – Author: TechRepublic Academy Published October 24, 2024 We may earn from vendors via affiliate links or sponsorships. This might affect product placement on...
Emergency patch: Cisco fixes bug under exploit in brute-force attacks – Source: go.theregister.com
Source: go.theregister.com – Author: Jessica Lyons Cisco has patched an already exploited security hole in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software...
Bitwarden’s FOSS halo slips as new SDK requirement locks down freedoms – Source: go.theregister.com
Source: go.theregister.com – Author: Liam Proven The Bitwarden online credentials storage service is changing its build requirements – which some commentators feel mean it’s no longer...
Ransomware’s ripple effect felt across ERs as patient care suffers – Source: go.theregister.com
Source: go.theregister.com – Author: Jessica Lyons Ransomware infected 389 US healthcare organizations this fiscal year, putting patients’ lives at risk and costing facilities up to $900,000...
Voice-enabled AI agents can automate everything, even your phone scams – Source: go.theregister.com
Source: go.theregister.com – Author: Thomas Claburn Scammers, rejoice. OpenAI’s real-time voice API can be used to build AI agents capable of conducting successful phone call scams...
China’s top messaging app WeChat banned from Hong Kong government computers – Source: go.theregister.com
Source: go.theregister.com – Author: Laura Dobberstein Hong Kong’s government has updated infosec guidelines to restrict the use of Chinese messaging app WeChat, alongside Meta and Google...
Anthropic’s latest Claude model can interact with computers – what could go wrong? – Source: go.theregister.com
Source: go.theregister.com – Author: Thomas Claburn The latest version of AI startup Anthropic’s Claude 3.5 Sonnet model can use computers – and the developer makes it...
Perfctl malware strikes again as crypto-crooks target Docker Remote API servers – Source: go.theregister.com
Source: go.theregister.com – Author: Jessica Lyons An unknown attacker is abusing exposed Docker Remote API servers to deploy perfctl cryptomining malware on victims’ systems, according to...
Samsung phone users under attack, Google warns – Source: go.theregister.com
Source: go.theregister.com – Author: Jessica Lyons A nasty bug in Samsung’s mobile chips is being exploited by miscreants as part of an exploit chain to escalate...
Penn State pays DoJ $1.25M to settle cybersecurity compliance case – Source: go.theregister.com
Source: go.theregister.com – Author: Brandon Vigliarolo Pennsylvania State University has agreed to pay the Justice Department $1.25 million to settle claims of misrepresenting its cybersecurity compliance...
FortiManager critical vulnerability under active attack – Source: go.theregister.com
Source: go.theregister.com – Author: Iain Thomson Updated Fortinet has gone public with news of a critical flaw in its software management platform. The security vendor apparently...
North Korean Hackers Exploited Chrome Zero-Day for Cryptocurrency Theft – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire The North Korean advanced persistent threat (APT) actor Lazarus was caught exploiting a zero-day vulnerability in Chrome to steal cryptocurrency...
‘Deceptive Delight’ Jailbreak Tricks Gen-AI by Embedding Unsafe Topics in Benign Narratives – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Palo Alto Networks has detailed a new AI jailbreak method that can be used to trick gen-AI by embedding unsafe...
New Fortinet Zero-Day Exploited for Months Before Patch – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs A zero-day vulnerability patched recently by Fortinet has been exploited by threat actors since at least June 2024, according to...
Penn State Settles for $1.25M Over Failure to Comply With DoD, NASA Cybersecurity Requirements – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire The Pennsylvania State University (Penn State) has agreed to pay $1.25 million to settle alleged failures to comply with cybersecurity...
New Scoring System Helps Secure the Open Source AI Model Supply Chain – Source: www.securityweek.com
Source: www.securityweek.com – Author: Kevin Townsend Artificial intelligence models from Hugging Face can contain similar hidden problems to open source software downloads from repositories such as...
Cisco Patches Vulnerability Exploited in Large-Scale Brute-Force Campaign – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Cisco on Wednesday announced patches for multiple vulnerabilities in Adaptive Security Appliance (ASA), Secure Firewall Management Center (FMC), and Firepower...
Samsung Galaxy S24 Hacked at Pwn2Own Ireland 2024 – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Over $350,000 was paid out on the second day of Pwn2Own Ireland 2024, including for an exploit targeting the Samsung...
Are Automatic License Plate Scanners Constitutional? – Source: www.schneier.com
Source: www.schneier.com – Author: Bruce Schneier An advocacy groups is filing a Fourth Amendment challenge against automatic license plate readers. “The City of Norfolk, Virginia, has...
Fortinet Confirms Zero-Day Exploit Targeting FortiManager Systems – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ryan Naraine Another critical Fortinet zero-day has been discovered being exploited in-the-wild. The US government’s cybersecurity agency CISA on Wednesday called urgent...
Lazarus Group Exploits Google Chrome Flaw in New Campaign – Source: www.infosecurity-magazine.com
Source: www.infosecurity-magazine.com – Author: A recently discovered cyber-attack by the notorious Lazarus Group, including its BlueNoroff subgroup, has exposed a new vulnerability in Google Chrome. The...
Penn State Settles for $1.25M Over Cybersecurity Violations – Source: www.infosecurity-magazine.com
Source: www.infosecurity-magazine.com – Author: Pennsylvania State University (Penn State) has agreed to pay $1.25m to resolve allegations of failing to meet federal cybersecurity requirements tied to...
White House Issues AI National Security Memo – Source: www.infosecurity-magazine.com
Source: www.infosecurity-magazine.com – Author: The White House has issued a National Security Memorandum (NSM) on AI, setting out key actions for the federal government to advance...