"Is Q-Day Closer Than We Think? IBM Researchers Say Hybrid Quantum-AI May Poses Near-Term Threats"

"Is Q-Day Closer Than We Think? IBM Researchers Say Hybrid Quantum-AI May Poses Near-Term Threats"

A team of IBM researchers reported in a study that combining Hybrid Quantum-Classical Computing (HQCC) and Artificial Intelligence (AI) technologies could bring us closer to the day quantum computing undermines current encryption methods. The team emphasizes the importance of making a quantum-proof shift as Q-Day approaches when quantum computers become powerful and stable enough to crack today's encryption schemes. This article continues to discuss the study "Advancements in Quantum Computing and AI May Impact PQC Migration Timelines."

Submitted by grigby1 CPVI on

"Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious Extensions"

"Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious Extensions"

A now-patched security flaw in the Microsoft Edge web browser could have been exploited to install arbitrary extensions on users' systems and perform malicious activities. According to Guardio Labs security researcher Oleg Zaytsev, this flaw could have enabled an attacker to use a private Application Programming Interface (API) originally intended for marketing purposes to covertly install additional browser extensions with broad permissions without the user knowing.

Submitted by grigby1 CPVI on

"Code Execution Flaws Haunt NVIDIA ChatRTX for Windows"

"Code Execution Flaws Haunt NVIDIA ChatRTX for Windows"

NVIDIA, the Artificial Intelligence (AI) computing giant, has patched two software flaws in its ChatRTX for Windows app, warning that users are vulnerable to code execution and data tampering attacks. According to NVIDIA, the flaws have a 'high-risk' rating and could be used to launch malicious code through Cross-Site Scripting (XSS) attacks. The security flaws, tracked as CVE-2024-0082 and CVE-2024-0083, impact ChatRTX for Windows 0.2 and earlier versions.

Submitted by grigby1 CPVI on

"INC Ransom Threatens to Leak 3TB of NHS Scotland Stolen Data"

"INC Ransom Threatens to Leak 3TB of NHS Scotland Stolen Data"

The INC Ransom extortion gang has threatened that it is going to publish three terabytes of data allegedly stolen after breaching the National Health Service (NHS) of Scotland.  In a post yesterday, the cybercriminals shared multiple images containing medical details and said that they would leak data "soon" unless the NHS pays a ransom.  Scotland's NHS is the country's public health system, providing services ranging from primary care, hospital care, dental care, pharmaceutical, and long-term care.

Submitted by Adam Ekwall on

"$700 Cybercrime Software Turns Raspberry Pi Into an Evasive Fraud Tool"

"$700 Cybercrime Software Turns Raspberry Pi Into an Evasive Fraud Tool"

Cybercriminals have been selling custom Raspberry Pi software called "GEOBOX" on Telegram that allows inexperienced hackers to turn the mini-computers into anonymous cyberattack tools. Researchers at Resecurity discovered the tool while investigating a high-profile banking theft incident involving a Fortune 100 company. Malicious individuals used several GEOBOX devices, with each connected to the Internet and strategically placed in different remote locations. These devices functioned as proxies, increasing their anonymity.

Submitted by grigby1 CPVI on

"Only 3% of Businesses Resilient Against Modern Cyber Threats"

"Only 3% of Businesses Resilient Against Modern Cyber Threats"

Cisco's 2024 Cybersecurity Readiness Index reveals that only 3 percent of organizations are resilient against cybersecurity threats, representing a significant drop in the proportion of global organizations with a mature level of readiness. Nearly 71 percent of organizations fell into the bottom two categories: 'formative' (60 percent) and 'beginner' (11 percent).

Submitted by grigby1 CPVI on

"VPN Apps on Google Play Turn Android Devices Into Proxies"

"VPN Apps on Google Play Turn Android Devices Into Proxies"

Security researchers at Human Security discovered that dozens of VPN applications that turn Android devices into residential proxies were being offered on the Google Play store.  The researchers noted that all the identified malicious applications contained a Golang library responsible for enrolling the device as a proxy node and appeared linked to Asocks, a residential proxy seller.  At least 28 VPN applications containing the malicious library were submitted to Google Play.  After being notified, all apps have been removed from the store.

Submitted by Adam Ekwall on

"'Darcula' Phishing-as-a-Service Operation Bleeds Victims Worldwide"

"'Darcula' Phishing-as-a-Service Operation Bleeds Victims Worldwide"

According to researchers at Netcraft, the Chinese-language Phishing-as-a-Service (PhaaS) platform "Darcula" created 19,000 phishing domains in cyberattacks against over 100 countries. The platform provides cybercriminals with easy access to branded phishing campaigns for a monthly subscription fee of around $250. Darcula is said to be more sophisticated than other PhaaS platforms. It supports many of the same tools used by application developers, such as JavaScript, React, Docker, and Harbor.

Submitted by grigby1 CPVI on

"Zero-Day Vulnerabilities Surged by Over 50% Annually, Says Google"

"Zero-Day Vulnerabilities Surged by Over 50% Annually, Says Google"

According to Google, the volume of zero-day vulnerabilities it detected increased by over 50% from 2022 to 2023, with bugs in third-party components on the rise.  Google discovered a total of 97 zero days in 2023, just shy of the record 106 detected in 2021.  Google claimed end-user platform vendors like Apple, Google, and Microsoft have made “notable investments” to reduce the number of exploitable zero days threat actors can find, making certain types “virtually non-existent” today.

Submitted by Adam Ekwall on
Subscribe to