News
-
"GitHub Scrambles to Rotate Keys After Credentials in Production Containers Were Potentially Exposed"Due to a high-severity vulnerability that exposed credentials, GitHub has rotated a number of its keys. The vulnerability, disclosed through its bug bounty program, would give attackers access to credentials within a production container.
-
"FBI, CISA Warn of AndroxGh0st Botnet for Victim Identification and Exploitation"The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have released a joint Cybersecurity Advisory (CSA) about the AndroxGh0st malware.
-
"Swiss Govt Websites Hit by Pro-Russia Hackers After Zelensky Visit"Switzerland recently announced that a cyberattack claimed by a pro-Russian group temporarily disrupted access to a number of government websites following Ukrainian President Volodymyr Zelensky's visit to Davos.
-
"PAX PoS Terminal Flaw Could Allow Attackers to Tamper with Transactions"PAX Technology's Point-of-Sale (PoS) terminals are vulnerable to attacks due to a set of high-severity flaws that threat actors can exploit to execute arbitrary code.
-
"Sophisticated macOS Infostealers Get Past Apple's Built-In Detection"As attackers gain more knowledge about how to crack static signature-detection engines, increasingly sophisticated infostealers are targeting macOS with the ability to evade Apple's built-in malware protection.
-
"ChatGPT Creator Pairing With Pentagon on Suicide Prevention and Cybersecurity, Executive Says"The artificial intelligence company behind the popular chatbot ChatGPT has recently teamed up with the Defense Department to explore ways of using its technology to prevent veteran suicide.
-
"Release Cybersecurity Guidance on Chinese-Manufactured UAS for Critical Infrastructure Owners and Operators"The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have released "Cybersecurity Guidance: Chinese-Manufactured Unmanned Aircraft Systems (UAS)." The guidance aims to raise awareness of threats pose
-
"Nearly 7K WordPress Sites Compromised by Balada Injector"According to security researchers at Jscrambler, about 6,700 WordPress websites have been infected with the Balada Injector malware after using a Popup Builder plug-in with a cross-site scripting (XSS) vulnerability tracked as CVE-2023-6000.
-
"PixieFail Flaws Impact PXE Network Boot in Enterprise Systems"Quarkslab researchers discovered a set of vulnerabilities called PixieFail affecting the IPv6 network protocol stack of TianoCore's EDK II, an open-source reference implementation of the Unified Extensible Firmware Interface (UEFI) specification that i
-
"Majorca Tourist Hotspot Hit With $11m Ransom Demand"A major Spanish holiday destination became the victim of ransomware last weekend, with reports claiming digital extortionists are demanding €10m ($11m).
-
"OpenAI Announces Plans to Combat Misinformation Amid 2024 Elections"OpenAI, the developer of the AI chatbot ChatGPT and the image generator DALL-E has recently announced new measures to prevent abuse and misinformation ahead of big elections this year.
-
"A Flaw in Millions of Apple, AMD, and Qualcomm GPUs Could Expose AI Data"According to new research, a vulnerability called LeftoverLocals exists in multiple brands and models of mainstream GPUs, including Apple, Qualcomm, and AMD chips, and can allow an attacker to steal large amounts of data from a GPU's memory.