News
-
"ChatGPT Just Passed an MBA-Level Exam at Wharton"ChatGPT has made some poor attempts to be a journalist and a therapist, but could it be a good student? Professor Christian Terwiesch from the Wharton School of the University of Pennsylvania believes it can. After Terwiesch proctored a final…
-
"LastPass Owner GoTo Says Hackers Stole Customers' Backups"LastPass' parent company GoTo has revealed that attackers stole customers' encrypted backups during a recent breach. LastPass initially confirmed the breach on November 30, 2022. At the time, the LastPass chief executive Karim Toubba stated that an…
-
"Malware Blurs Line Between Banking Trojan and Surveillance"Hook is an Android banking Trojan that can take remote control of mobile devices. The Trojan, which the cybersecurity company ThreatFabric identifies as an improved variant of the existing Ermac Trojan, can carry out an entire attack chain, from…
-
"Arm Vulnerability Leads to Code Execution, Root on Pixel 6 Phones"A security researcher recently published technical details on an Arm Mali GPU vulnerability leading to arbitrary kernel code execution and root on Pixel 6 phones using a malicious app installed on the targeted device. The vulnerability is tracked…
-
"Apple Patches WebKit Code Execution in iPhones, MacBooks"Apple’s product security response team recently rolled out patches to cover numerous serious security vulnerabilities affecting users of its flagship iOS and macOS platforms. Apple warned that the most serious documented vulnerabilities affect…
-
"Attacks Targeting Realtek SDK Vulnerability Ramping Up"Palo Alto Networks recently warned of an increase in cyberattacks targeting CVE-2021-35394, a remote code execution (RCE) vulnerability in the Realtek Jungle SDK. The vulnerability was disclosed in August 2021, and the vulnerability impacts…
-
"Record-Breaking Year for DDoS Attacks Targeting Russia"According to Russia's largest internet service provider, Russian organizations were deluged with web and DDoS attacks last year in a bid to disrupt operations, deface websites, and "sow panic." Rostelecom said in a new report that in 2022 it recorded "a…
-
"Up to 350,000 Open-Source Projects Vulnerable to 15-Year-Old Python Bug"A 15-year-old Python vulnerability has impacted hundreds of thousands of open-source projects over the course of its existence. The vulnerability, tracked as CVE-2007-4559, is a path traversal flaw in the extract and extractall functions of the Python…
-
"Companies Impacted by Mailchimp Data Breach Warn Their Customers"Multiple organizations have been hit by the recent Mailchimp data breach, with some already notifying their customers. Mailchimp, a popular email marketing and newsletter creation platform, revealed facing a data breach that exposed the personal…
-
"Hunting Insider Threats on the Dark Web"Malicious employees have been found to be responsible for 20 percent of security incidents. Attacks carried out by insiders are 10 times larger, on average, than those carried out by external actors. All organizations should monitor marketplaces,…
-
"Hackers Use Golang Source Code Interpreter to Evade Detection"A Chinese-speaking hacking group called DragonSpark was seen using Golang source code interpretation to avoid detection while conducting espionage attacks against East Asian companies. SentinelLabs is monitoring the attacks and reports that DragonSpark…
-
"FBI Says North Korean Hackers Behind $100 Million Horizon Bridge Crypto Theft"The FBI has confirmed that North Korean threat actors stole $100 million in cryptocurrency assets from the Harmony Horizon Bridge in June 2022. According to the law enforcement agency, the hack was attributed to the Lazarus Group and APT38, the latter of…