-
"Malicious AI Models on Hugging Face Backdoor Users' Machines"At least 100 malicious Artificial Intelligence (AI)/Machine Learning (ML) models were discovered on the Hugging Face platform, with some capable of executing code on the victim's machine, providing attackers with a persistent backdoor.
-
"Meta Patches Facebook Account Takeover Vulnerability"Meta recently patched a critical vulnerability that could have been exploited to take control of any Facebook account.
-
"'Side-Channel' Attacks, New Cyberdefense Techniques Focus of Montana State U. Research"The Idaho National Laboratory has announced the award of two grants to Montana State University researchers to help them advance their efforts to make the country's critical infrastructure more secure against cyberattacks.
-
"Iran-Linked UNC1549 Hackers Target Middle East Aerospace & Defense Sectors"UNC1549, an Iran-linked threat actor, has been attributed to new attacks targeting aerospace, aviation, and defense industries in the Middle East.
-
-
-
-
"CISA Publishes Guide to Support University Cybersecurity Clinics"According to Clayton Romans, US Cybersecurity and Infrastructure Security Agency (CISA) Associate Director of the Joint Cyber Defense Collaborative (JCDC), small and local organizations face a unique cybersecurity challenge.
-
"State-Sponsored Hackers Know Enterprise VPN Appliances Inside Out"According to Mandiant incident responders and threat hunters, suspected Chinese state-sponsored hackers who exploited Ivanti Connect Secure VPN flaws to breach a number of organizations have showed "a nuanced understanding of the appliance." They
-
"US Bans Trading With Canadian Network Intelligence Firm Sandvine"The US government recently added Canadian network intelligence firm Sandvine to its Entity List, effectively banning organizations from trading with it.
-
"'Savvy Seahorse' Hackers Debut Novel DNS CNAME Trick"A threat actor is conducting an investment scam using a Traffic Distribution System (TDS) that leverages the Domain Name System (DNS) to keep its malicious domains changing and resistant to takedowns.
-
"Lazarus Hackers Exploited Windows Zero-Day to Gain Kernel Privileges"Lazarus Group, the North Korean state-sponsored cyber threat group, exploited a flaw in the Windows AppLocker driver to gain kernel-level access and disable security tools, bypassing Bring Your Own Vulnerable Driver (BYOVD) techniques.
News