News
-
"NIST Seeks Collaborators for Consortium Supporting Artificial Intelligence Safety"The US Department of Commerce's National Institute of Standards and Technology (NIST) is seeking participants in a new consortium to support the development of innovative methods for assessing Artificial Intelligence (AI) systems in order to impr
-
"Suspected Exploitation of Apache ActiveMQ Flaw To Install HelloKitty Ransomware"Rapid7 cybersecurity researchers have issued a warning regarding the potential exploitation of a recently disclosed critical vulnerability in the Apache ActiveMQ, tracked as CVE-2023-46604, to launch the HelloKitty ransomware.
-
"AI Image Generators Can Be Tricked Into Making NSFW Content"New research on popular Artificial Intelligence (AI) image generators reveals that they could be hacked to create inappropriate and potentially harmful content.
-
"Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover"Non-privileged threat actors could exploit 34 different vulnerable Windows Driver Model (WDM) and Windows Driver Frameworks (WDF) drivers in order to gain complete control of the devices and run arbitrary code on the underlying systems.
-
"Learning To Forget – A Weapon in the Arsenal Against Harmful AI"Researchers are bringing attention to a real issue that accompanies Artificial Intelligence (AI) technology, which is teaching it how to forget. According to scientists, 'Machine Unlearning' is an essential weapon against AI risks.
-
"Boeing Confirms Impact From 'Cyber Incident,' Vanishes From LockBit Ransom List"The Boeing Company has confirmed that a cyber incident, previously claimed by the LockBit ransomware gang, impacted some operations. The LockBit ransomware group claimed the cyber incident on its leak site on October 27.
-
"More Than 100 Vulns in Microsoft 365 Tied to SketchUp 3D Library"Microsoft's decision to add support to Microsoft 365 for the SketchUp 3D Library in June 2022 seems to have resulted in the introduction of many vulnerabilities within its suite of cloud-based collaboration and productivity tools.
-
"Malicious Package Campaign on NuGet Abuses MSBuild Integrations"Threat actors are always finding new ways to deploy malicious packages on public registries for programming languages. They want to execute malware code when those packages are imported and used in projects.
-
"FIRST - New CVSS 4.0 Vulnerability Severity Rating Standard Released"The Forum of Incident Response and Security Teams (FIRST) has released the fourth version of the Common Vulnerability Scoring System (CVSS).
-
"MITRE ATT&CK v14 Released"MITRE ATT&CK v14 is the newest iteration of the popular investigation framework and knowledge base of cyberattackers' tactics and techniques. ATT&CK aims to classify and catalog cyber adversaries' behaviors in real-world attacks.
-
"Alliance of 40 Countries to Vow Not To Pay Ransom to Cybercriminals, US Says"A senior White House official announced on October 31 that 40 countries in an alliance led by the US plan to sign a pledge to never pay ransom to cybercriminals and to make an effort to eliminate the hackers' funding mechanism.
-
"Most Websites Do Not Publish Privacy Policies, Researchers Say"According to researchers at the Pennsylvania State University who crawled millions of websites, online privacy policies may not only be difficult to find but also nonexistent.