"Commonwealth Cyber Initiative Funds 11 Inclusive Cybersecurity Projects"

"Commonwealth Cyber Initiative Funds 11 Inclusive Cybersecurity Projects"

A new Commonwealth Cyber Initiative (CCI)-funded inclusive cybersecurity program in Virginia is helping people feel safer and more secure on computer networks and other devices. CCI awarded 11 projects for its 2024 Addressing Inclusion and Accessibility in Cybersecurity Program.

Submitted by Gregory Rigby on

"Cisco Finds 15 Vulnerabilities in AutomationDirect PLCs"

"Cisco Finds 15 Vulnerabilities in AutomationDirect PLCs"

Cisco's Talos research and threat intelligence unit found 15 vulnerabilities impacting AutomationDirect’s Productivity series Programmable Logic Controllers (PLCs). The vulnerabilities are all classified as being of high or critical severity. They can be exploited for Remote Code Execution (RCE) or Denial-of-Service (DoS) attacks, potentially disrupting industrial environments and causing significant costs.

Submitted by Gregory Rigby on

"IoT Vulnerabilities Skyrocket, Becoming Key Entry Point for Attackers"

"IoT Vulnerabilities Skyrocket, Becoming Key Entry Point for Attackers"

According to Forescout's "The Riskiest Connected Devices in 2024" report, the number of Internet of Things (IoT) devices with vulnerabilities has increased by 136 percent. The study, involving the analysis of data from about 19 million devices, discovered that the proportion of IoT devices containing vulnerabilities increased from 14 percent in 2023 to 33 percent in 2024. Wireless access points, routers, printers, and IP cameras were the most vulnerable IoT devices. This article continues to discuss key findings from Forescout's report on the riskiest connected devices.

Submitted by Gregory Rigby on

"Critical PyTorch Vulnerability Can Lead to Sensitive AI Data Theft"

"Critical PyTorch Vulnerability Can Lead to Sensitive AI Data Theft"

Security researchers at Huntr discovered a critical-severity vulnerability in the PyTorch machine learning library that could be exploited for remote code execution.  The vulnerability CVE-2024-5480 impacts the distributed RPC (Remote Procedure Call) framework of PyTorch.  The researchers said that the issue exists because the framework does not verify the functions called during RPC operations.

Submitted by Adam Ekwall on

"Threat Actor Claims to Leak 270GB of New York Times Data"

"Threat Actor Claims to Leak 270GB of New York Times Data"

An anonymous threat actor has recently posted what they claim to be 270GB of source code stolen from the New York Times.  The alleged leak was first spotted by security researchers at vx-underground.  The researchers believe the actor targeted the New York Times’ GitHub account.

Submitted by Adam Ekwall on

"Christie’s Says Ransomware Attack Impacts 45,000 People"

"Christie’s Says Ransomware Attack Impacts 45,000 People"

In a new update, Auction house Christie’s informed authorities that the data breach caused by a recent ransomware attack impacted the information of roughly 45,000 individuals.  The intrusion was discovered on May 9.  An investigation showed that the attackers managed to steal some files containing personal information. The notification letter sample submitted by Christie’s to the Maine AG does not specify what type of data was compromised besides names, driver’s license numbers, and non-driver identification card numbers.

Submitted by Adam Ekwall on

"Ohio City Hit by Cyber Incident: What We Know"

"Ohio City Hit by Cyber Incident: What We Know"

Cleveland City Hall recently announced a temporary closure after a significant "cyber incident" that impacted the city's systems.  The city has been forced to shut down most internal systems to prevent further damage and investigate a significant cybersecurity breach.  The extent of the damage is not yet known.  City staff were told on Sunday night that they could not access most internal systems in the morning, with only essential and emergency services being maintained.

Submitted by Adam Ekwall on

"EmailGPT Exposed to Prompt Injection Attacks"

"EmailGPT Exposed to Prompt Injection Attacks"

A new vulnerability has been discovered in EmailGPT, a Google Chrome extension and Application Programming Interface (API) service that uses OpenAI's GPT models to help Gmail users write emails. According to the Synopsys Cybersecurity Research Center (CyRC), the flaw allows attackers to control the Artificial Intelligence (AI) service by entering harmful prompts. The system may reveal sensitive information or execute unauthorized commands due to these malicious prompts. The issue can be exploited by anyone with EmailGPT access, raising concerns about widespread abuse.

Submitted by Gregory Rigby on

NSA and Universities Partnering to Advance Cybersecurity Research

NSA and Universities Partnering to Advance Cybersecurity Research

NSA Research invited leading university research institutions across the country to the National Cryptologic Museum for a day-long event to tackle the ongoing challenge of securing critical cyber systems.
Submitted by Amy Karns on

"Tech Cybersecurity Duo Recognized for Data Research"

"Tech Cybersecurity Duo Recognized for Data Research"

Bo Chen and Niusen Chen won Michigan Technological University's 2024 Bhakta Rath Research Award for their work to ensure information on today's mobile devices can be stored securely and deleted permanently. They were the first to develop the capability for Plausibly Deniable Encryption (PDE) for computing devices. They also addressed sensitive data remnants in flash storage that can resist normal secure deletion techniques. This article continues to discuss the duo's cybersecurity work that won Michigan Technological University's 2024 Bhakta Rath Research Award.

Submitted by Gregory Rigby on
Subscribe to