A U.S.
Tag: EN
Growing Up The Hard Way
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once…
Orca on securing AI-powered enterprises
Orca Security has released new guidance aimed at helping enterprises secure their AI-powered infrastructure as organizations rapidly adopt artificial…
ChainDrop Worm Infects 400+ npm Packages to Steal GitHub and Cloud Credentials
ChainDrop has turned routine software installs into a route for credential theft. The self-propagating worm infected more than 400 npm packages, putting…
UNC6671 Vishing Group Rebrands After Millions
A prolific vishing extortion group tracked as UNC6671 has successfully rebranded its operations multiple times after accumulating millions of dollars…
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a…
AI patching tools miss security risks, need human oversight
AI-powered code generation tools are producing security patches that fail to properly remediate vulnerabilities more than half the time, according to new…
New NatJack NAT Attack Lets Hackers Hijack TCP Connections and DNS Responses
A newly disclosed attack class, NatJack, reveals significant weaknesses in the implementation of Network Address Translation (NAT) across modern network…
Attacker phished way into US defense supplier’s Microsoft 365 account
Intruder gained access to engineering files and potentially export-controlled technical data
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions
UNC6671 is carrying out data theft campaigns that begin with a phone call. The group poses as an IT helpdesk, claiming an urgent security migration is…
ISA VDA 6.0.3 – The Data Protection sheet explained
The Data Protection catalog is the shortest of the three in ISA 6.0.3 and the one most often underestimated. Twelve control questions across eight…
Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case
Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill…
Papyrus Mobile Ad Fraud Uses Hidden WebViews to Fake Clicks, Scrolls and Attention
Papyrus is a mobile ad fraud operation hiding behind apps built for reading serialized fiction. While people turn pages and follow stories, the apps can…
AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says
Leading AI companies have learned important lessons from recent incidents, the official said, and regulation isn’t necessary to preserve those lessons.
Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a…
Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix
NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.
ICE Is Buying Access to Credit Card Records
Through data brokers, ICE is buying the information you provided to open a credit card.
Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor
‘Asimov was right’ about rules for robots, says ex-US Cyber Director
Humans will get the AI models they deserve