News
Microsoft drops its second-largest monthly batch of defects on record
2+ hour, 48+ min ago (647+ words) By my count, this is the second-largest monthly release in Microsoft's history," Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, wrote in a blog post Tuesday. Microsoft didn't explain why its monthly batch of patches grew…...
Space Force official touts AI's impact on cyber compliance
3+ hour, 15+ min ago (493+ words) Seth Whitworth, who is both acting Associate Deputy Chief of Space Operations for Cyber and Data and acting chief information security officer, said he believes AI tools are shifting the way defenders review cyber risk, both for individual systems and…...
Black Basta's playbook lives on as former affiliates launch fast-scale intrusion campaign
2+ hour, 6+ min ago (569+ words) A small group of former Black Basta affiliates have targeted more than 100 employees across dozens of organizations to intrude network systems for potential data theft, ransomware deployment and extortion, according to Relia Quest. The social engineering campaign, which involves mass…...
Here's how cyber heavyweights in the US and UK are dealing with Claude Mythos
21+ hour, 22+ min ago (793+ words) A joint report from the Cloud Security Alliance (CSA), the SANS Institute and the Open Worldwide Application Security Project (OWASP) concludes that in the near term, organizations are "likely to be overwhelmed" by threat actors using AI to find and…...
Open AI's Mac apps needs an update thanks to the Axios hack
1+ day, 2+ hour ago (392+ words) Open AI updated its security certificates and is requiring all mac OS users to update to the latest versions after determining its products, along with many others, were impacted by a widespread supply-chain attack that briefly infected a popular open-source…...
What does industry think of the White House's cybersecurity strategy?
4+ day, 9+ hour ago (174+ words) Cyber Scoop Bob Ackerman (founder of Allegiance Cyber and a partner at Data Tribe) joins Safe Mode to talk about where the new national cybersecurity strategy is trying to push the industry'especially around more open, coordinated "active disruption" with government…...
Iranian attacks on US critical infrastructure puts 3, 900 devices in crosshairs
4+ day, 21+ hour ago (362+ words) The fallout and potential exposure from Iran's state-backed targeting of U. S. critical infrastructure extends to more than 5, 200 internet-connected devices, researchers at Censys said in a threat intelligence brief Wednesday." "Of the programmable logic controllers manufactured by Rockwell Automation/Allen-Bradley that Censys…...
Why is the timeline to quantum-proof everything constantly shrinking?
5+ day, 2+ hour ago (734+ words) When Google announced last month it was moving up its own internal timeline for migrating to quantum-resistant forms of encryption, it started a broader conversation in the cybersecurity and cryptography communities: Just what was pushing one of the largest tech…...
Tech giants launch AI-powered "Project Glasswing" to identify critical software vulnerabilities
1+ week, 5+ hour ago (224+ words) Major technology companies have joined forces in an effort to use advanced artificial intelligence to identify and address security flaws in the world's most critical software systems, marking a significant shift in how the industry approaches cybersecurity threats. Anthropic will…...
Grafana Ghost" bypasses Grafana's AI defenses without leaving a trace
1+ week, 9+ hour ago (333+ words) Security researchers at Noma Security have disclosed a new vulnerability they are calling Grafana Ghost, an exploit capable of silently stealing sensitive data from Grafana environments by chaining multiple security bypasses, including a method that circumvents the platform's AI model…...