"Companies Have Good Reasons To Be Concerned About Generative AI"

"Companies Have Good Reasons To Be Concerned About Generative AI"

According to Portal26, companies need help gaining visibility into their Artificial Intelligence (AI) programs' operations. A lack of visibility may reduce productivity and introduce significant risks in governance, data security, and other areas. In the past year, two-thirds of respondents reported a generative AI security or misuse incident. Seventy-three percent have already faced generative AI-related security incidents, with 67 percent occurring in the last year alone.

Submitted by Gregory Rigby on

"Marina Bay Sands Discloses Data Breach Impacting 665k Customers"

"Marina Bay Sands Discloses Data Breach Impacting 665k Customers"

Singapore's Marina Bay Sands luxury resort has recently revealed that 665,000 of its customers are impacted by a recent data breach.  The incident affects Marina Bay Sands' shopping loyalty program members.  There is no indication to date that the Sands Rewards Club casino rewards program was impacted as well.  The resort is owned by US casino and resort giant Las Vegas Sands.  The company discovered on October 20 that an unauthorized third party had gained access to shopping membership program data on October 19 and 20.

Submitted by Adam Ekwall on

"DHS Unveils New Shields Ready Campaign to Promote Critical Infrastructure Security and Resilience"

"DHS Unveils New Shields Ready Campaign to Promote Critical Infrastructure Security and Resilience"

To encourage the critical infrastructure community to focus on bolstering resilience, the Department of Homeland Security (DHS), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Emergency Management Agency (FEMA) have launched the new "Shields Ready" campaign. The Shields Ready campaign, spearheaded by CISA and supported by FEMA, will work to ensure the nation's critical infrastructure is better prepared and more resilient against all threats, including cyberattacks.

Submitted by Gregory Rigby on

"Sumo Logic Urges Users to Change Credentials Due to Security Breach"

"Sumo Logic Urges Users to Change Credentials Due to Security Breach"

Cloud monitoring, log management, and SIEM tools provider Sumo Logic recently discovered a security breach and is urging customers to change credentials.  The company revealed on Tuesday that a "potential security incident" found on November 3 involved unauthorized access to a Sumo Logic AWS account through the use of compromised credentials.  The company noted that there is no indication that the company's systems, networks, or customer data have been impacted.

Submitted by Adam Ekwall on

"Researchers Spot an Increase in Jupyter Infostealer Infections"

"Researchers Spot an Increase in Jupyter Infostealer Infections"

Jupyter infostealer infections have increased, mostly targeting organizations in the education and healthcare sectors. According to a new report from VMware's Carbon Black Threat Analysis Unit, there has been a surge in new incidents involving the malware, which was first discovered in late 2020. The malware enables hackers to steal credentials and exfiltrate data. It has evolved to target Chrome, Edge, and Firefox browsers, and the hackers who use it have also used search engines to trick people into downloading malicious files containing the malware.

Submitted by Gregory Rigby on

"MITRE and Microsoft Collaborate to Address Generative AI Security Risks"

"MITRE and Microsoft Collaborate to Address Generative AI Security Risks"

MITRE and Microsoft have enhanced MITRE ATLAS (Adversarial Threat Landscape for Artificial Intelligence Systems), a community knowledge base that security professionals, Artificial Intelligence (AI) developers, and AI operators can use in the protection of AI-enabled systems. MITRE ATLAS now focuses more on generative AI vulnerabilities to catalyze secure AI use. This new framework update, as well as the accompanying new case studies, directly address the unique vulnerabilities of systems involving generative AI and Large Language Models (LLMs).

Submitted by Gregory Rigby on

"The SEI SBOM Framework: Informing Third-Party Software Management in Your Supply Chain"

"The SEI SBOM Framework: Informing Third-Party Software Management in Your Supply Chain"

Those responsible for managing software systems must think about third-party software dependencies and risks in new ways and team up with business experts to develop new techniques for identifying and handling potential risks. A Software Bill of Materials (SBOM) can help with these tasks. Carnegie Mellon University Software Engineering Institute (SEI) researchers have highlighted their work on building upon SEI's Acquisition Security Framework for Supply Chain Risk Management (SCRM) and tailoring it for third-party software management. Their work resulted in the SEI SBOM Framework.

Submitted by Gregory Rigby on

"Reliable Security Online for Protection Against Fraud"

"Reliable Security Online for Protection Against Fraud"

Researchers at the University of Bonn are working on a platform that prevents Internet fraud and complies with data protection laws. The University of Bonn researchers are collaborating with the Leibniz Institute for Information Infrastructure (FIZ) in Karlsruhe and the University of Duisburg-Essen to create an online platform that provides better protection against identity data misuse for both consumers and merchants. The DARIA research project focuses on data protection-compliant information fusion and risk assessment to prevent identity fraud and limit non-payment risk.

Submitted by Gregory Rigby on

"University of Central Florida Team Crowned Champion at the 2023 CyberForce Competition"

"University of Central Florida Team Crowned Champion at the 2023 CyberForce Competition"

A team from the University of Central Florida won first place in this year's CyberForce Competition hosted by the Department of Energy's (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and supported by DOE's Argonne National Laboratory (ANL) and several other national laboratories. During the all-day event, students from universities and colleges across the US dealt with real-world cybersecurity issues involving distributed energy resources like solar panels and wind turbines.

Submitted by Gregory Rigby on

"Royal Mail Jeopardizes Users With Open Redirect Flaw"

"Royal Mail Jeopardizes Users With Open Redirect Flaw"

The Royal Mail postal service and courier company in the UK had an open redirect vulnerability on one of its websites, exposing its customers to phishing attacks and malware infections. The company made headlines earlier this year when it refused to pay LockBit's $80 million ransom. The ransomware attack by a Russia-linked group disrupted Royal Mail, and it was temporarily unable to ship items overseas.

Submitted by Gregory Rigby on
Subscribe to