News
-
"'Log in With...' Feature Allows Full Online Account Takeover for Millions"Vulnerabilities in the implementation of the Open Authorization (OAuth) standard across three major online services may have exposed users to credential theft, financial fraud, and other cybercriminal activities.
-
"Generative AI Can Save Phishers Two Days of Work"According to security researchers at IBM, generative AI tools can save phishing actors 16 hours of work designing a scam email but still can’t match a human.
-
"New Assistant Professor Aims to Make AI Safe and Secure"Muaho Chen, a new assistant professor in the Department of Computer Science at the University of California, Davis, will study jailbreaking attacks and other security problems associated with Large Language Models (LLMs) such as ChatGPT.
-
"NSA - Cybersecurity Speaker Series: D3FEND"The National Security Agency (NSA)'s Cybersecurity Collaboration Center (CCC) has posted the latest installment of its Cybersecurity Speaker Series, which focuses on the D3FEND cybersecurity framework.
-
"CISA Releases New Resource to Help Small and Medium-Sized Businesses Develop Supply Chain Resilience Plans"The US Cybersecurity and Infrastructure Security Agency (CISA) has released a new resource guide titled "Empowering Small and Medium-Sized Businesses (SMB): A Resource Guide for Developing a Resilient Supply Chain Risk Management Plan." It aims to help
-
"The SEC's Cybersecurity Rules"The US Securities and Exchange Commission (SEC) has recently adopted rules requiring public companies to disclose cybersecurity incidents within four business days.
-
"Quasar RAT Leverages DLL Side-Loading to Fly Under the Radar"Quasar RAT, also known as CinaRAT or Yggdrasil, is an open-source Remote Access Trojan (RAT) that has been using DLL side-loading to avoid detection and stealthily steal data from compromised Windows hosts.
-
"US Energy Firm Shares How Akira Ransomware Hacked Its Systems"The US energy services company BHI Energy has detailed how the Akira ransomware operation breached its network and stole data.
-
"FBI: Thousands of Remote IT Workers Sent Wages to North Korea to Help Fund Weapons Program"The FBI and Department of Justice (DoJ) have recently announced that thousands of information technology workers contracting with U.S.
-
"Critical SolarWinds RCE Bugs Enable Unauthorized Network Takeover"Eight recently discovered vulnerabilities in the SolarWinds Access Rights Manager Tool (ARM), including three of critical severity, could allow attackers to gain access to unpatched systems with the highest levels of privilege.
-
"'Disappearing' Implants, Followed by First Fixes for Exploited Cisco IOS XE Zero-Day"Cisco has released the first fixes for the IOS XE zero-day vulnerability, tracked as CVE-2023-20198, which attackers exploited to deliver a malicious implant.
-
"Low-Power Hardware Accelerator Offers Outsize Security"A research team in the US has developed a novel hardware accelerator prototype for edge devices that can encrypt cloud-sent and -received messages with 1,000 to 6,000 times the energy efficiency of a standard RISC-V processor.