"The Major Hardware Flaw in Apple M-Series Chips"

"The Major Hardware Flaw in Apple M-Series Chips"

Apple M-series chips, designed to perform more consistently and faster than Intel processors, have a vulnerability that can expose cryptographic keys, enabling a malicious actor to reveal encrypted data. "GoFetch," a critical side-channel security flaw, exploits a vulnerability in M-chips Data Memory-Dependent Prefetcher (DMP). By scanning the cache and prefetching information, DMP predicts which memory addresses the code will most likely access. This technology enhances computer speed and overall computing performance.

Submitted by Gregory Rigby on

"DHS Publishes Guidelines and Report to Secure Critical Infrastructure and Weapons of Mass Destruction from AI-Related Threats"

"DHS Publishes Guidelines and Report to Secure Critical Infrastructure and Weapons of Mass Destruction from AI-Related Threats"

The US Department of Homeland Security (DHS), in collaboration with the Cybersecurity and Infrastructure Security Agency (CISA), has published new safety and security guidelines that address cross-sector Artificial Intelligence (AI) risks to the safety and security of critical infrastructure in the US. The guidelines cover three broad categories of system-level risk: attacks using AI, attacks targeting AI systems, and failures in AI design and implementation.

Submitted by Gregory Rigby on

"Collection Agency FBCS Says Data Breach Exposed Nearly 2 million People"

"Collection Agency FBCS Says Data Breach Exposed Nearly 2 million People"

Debt collection agency Financial Business and Consumer Solutions (FBCS) is starting to notify roughly 2 million individuals that their personal information was compromised in a recent data breach. The incident was discovered on February 26, 2024, and involved “unauthorized access to certain systems in its network.” FBCS’ investigation revealed that a third party had access to those systems between February 14 and February 26 and that certain information was viewed or accessed during that time frame.

Submitted by Adam Ekwall on

"Researcher Strips ROM for Binary Code"

"Researcher Strips ROM for Binary Code"

The security key has served as a barrier to Multi-Factor Authentication (MFA) hacks. A physical device outperforms other methods, such as one-time codes, which hackers can intercept, and provides protection against Machine-in-the-Middle (MitM) attacks. However, research shows that attackers could, in theory, physically extract secrets from Read-Only Memory (ROM) inexpensively.

Submitted by Gregory Rigby on

"DHS Establishes AI Safety and Security Board to Protect Critical Infrastructure"

"DHS Establishes AI Safety and Security Board to Protect Critical Infrastructure"

The US Department of Homeland Security (DHS) has established the Artificial Intelligence (AI) Safety and Security Board. The Board will help DHS stay ahead of growing threats posed by hostile nation-state actors. It will also help strengthen national security by helping deter and prevent such threats. The DHS Homeland Threat Assessment for 2024 warns that AI-assisted tools threaten economic security and critical infrastructure as they could enable larger-scale, faster, more efficient, and more evasive cyberattacks.

Submitted by Gregory Rigby on

"London Drugs Pharmacy Chain Closes Stores After Cyberattack"

"London Drugs Pharmacy Chain Closes Stores After Cyberattack"

Canadian pharmacy chain London Drugs has recently closed all its retail stores to contain what it described as a "cybersecurity incident." The company has also hired external experts to investigate the cyberattack that impacted its systems. The company noted that on April 28, 2024, it discovered it was the victim of a cybersecurity incident. London Drugs said that it currently has found no evidence pointing to customer or employee data being impacted.

Submitted by Adam Ekwall on

"Researchers Create Innovative Verification Techniques to Increase Security in Artificial Intelligence and Image Processing"

"Researchers Create Innovative Verification Techniques to Increase Security in Artificial Intelligence and Image Processing"

Researchers from the IMDEA Software Institute, Carlos III University of Madrid, and NEC Laboratories Europe have developed a framework to improve verifiable computation efficiency and practicality. Their paper, "Modular Sumcheck Proofs with Applications to Machine Learning and Image Processing," addresses the scalability and modularity issues faced by general proof systems and solutions for specific AI and image processing applications.

Submitted by Gregory Rigby on

"Google Rejected 2.28 Million Risky Android Apps From Play Store in 2023"

"Google Rejected 2.28 Million Risky Android Apps From Play Store in 2023"

In 2023, Google blocked 2.28 million Android apps from Google Play for policy violations that could compromise user security. Google also blocked 333,000 Google Play accounts that uploaded malware and fraudulent apps, or repeated grave policy violations.

Submitted by Gregory Rigby on

"Honeywell: USB Malware Attacks on Industrial Orgs Becoming More Sophisticated"

"Honeywell: USB Malware Attacks on Industrial Orgs Becoming More Sophisticated"

Honeywell released its sixth annual report on USB malware attacks faced by industrial organizations, warning of increased sophistication. The company's Global Analysis, Research, and Defense (GARD) team analyzed data from a security product that detects and blocks malware on USB drives used in customers' industrial environments. Thirty-one percent of all the malware detected by Honeywell's product on USB drives was found to be part of a campaign targeting industrial systems or companies.

Submitted by Gregory Rigby on

"Thousands of Qlik Sense Servers Open to Cactus Ransomware"

"Thousands of Qlik Sense Servers Open to Cactus Ransomware"

Many organizations remain vulnerable to the Cactus ransomware group's exploitation of three flaws in the Qlik Sense data analytics and Business Intelligence (BI) platform nearly five months after security researchers warned about them. In August, the company disclosed two bugs in multiple versions of Qlik Sense Enterprise for Windows. When chained, the vulnerabilities enable remote, unauthenticated attackers to execute arbitrary code on impacted systems. In September, Qlik disclosed a vulnerability that bypassed its fixes for August's two flaws.

Submitted by Gregory Rigby on
Subscribe to