IT Security News: today roundup
- ENISA warned that frontier AI is drastically accelerating cyberattacks, urging European defenders to respond at machine speed.
- Microsoft warned that passkey-themed phishing attacks are hijacking Microsoft 365 accounts to steal enterprise cloud data.
- A Telegram Desktop vulnerability allowed malicious JavaScript embedded in HTML chat exports to steal exported messages.
- A cybersecurity tool uses WebRTC to tunnel network traffic through video-calling platforms to bypass domain whitelists.
- An attacker breached Thai broadband provider 3BB, using the legitimate MeshCentral management tool to maintain remote root access.
- Security expert Bruce Schneier published his schedule of upcoming public speaking engagements across several conferences and institutions.
- China rejected Anthropic CEO Dario Amodei's AI slowdown proposal, labeling it an effort by the US to contain its tech sector.
- Researchers demonstrated a new hardware attack requiring physical server access to breach DDR5 RAM and expose encrypted memory.
- Hackers are actively exploiting an unauthenticated file upload vulnerability in a WooCommerce plugin to gain remote code execution.
- Apple patched a record 261 vulnerabilities across all of its operating systems in its latest round of software updates.
Sources
- ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up
- Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
- whitelist-bypass – WebRTC Tunnels Through Video-Calling Platforms
- 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
- Upcoming Speaking Engagements
- China Calls Amodei’s AI Proposal a New Cold War Playbook
- New hardware device can RAM into encrypted memory, expose your data
- Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
- Apple Updates Everything, (Mon, Sep 14th)