Tag: Information Security Buzz

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

A security breach notification process has been initiated by 7-Eleven as a result of a security incident where an outside party was able to gain access to their systems containing franchisers’  information.  According to a breach notification filed with the state of Maine, the company discovered that threat…

NCSC warns organisations not to rush into agentic AI

UK’s National Cyber Security Centre (NCSC) has advised businesses to proceed with caution when considering the implementation of agent-based AI, suggesting that agentic AI represents an entirely different kind of security problem compared to generative AI.  According to a recent blog post and global guidance, produced in…

How EM is Boosting the Career Trajectory of VM Analysts

As organizations shift from vulnerability management (VM) to exposure management (EM), the role of the VM analyst must evolve or become outmoded.   This necessary transition forces analysts to move beyond the job description of scanning and patching and into more…

Microsoft discloses Exchange zero-day with no patch yet available

Microsoft has disclosed a zero-day vulnerability that affects Exchange Server 2016, 2019, and Subscription Edition. This vulnerability would give bad actors an opportunity to run arbitrary code remotely on the Exchange server.  Although Microsoft has not issued any patches for this security vulnerability, they…

Cyberattack on West Pharmaceutical halts manufacturing across multiple sites

West Pharmaceutical Services has disclosed a ransomware attack that disrupted manufacturing, shipping, and receiving operations across multiple global facilities after bad actors breached the company’s network on 4 May.   The pharmaceutical packaging manufacturer said attackers exfiltrated data and encrypted systems, forcing the company to proactively shut down portions of…

What to do when your AI’s guardrails fail

I want to talk about the Microsoft 365 Copilot bug. Not because it was exceptional, but because what it exposed should change how every organization architects AI governance. For weeks at the beginning of the year, Microsoft 365 Copilot read…

Foxconn confirms cyberattack following Nitrogen ransomware claims

Foxconn has confirmed that several of its North American factories were hit by a cyberattack, after the Nitrogen ransomware group claimed to have stolen 8TB of data comprising more than 11 million files.  According to the bad actor, the information supposedly obtained contains private directives, project details,…

Trelix admits breach on a ‘portion’ of its source code repository

Trellix has disclosed unauthorized access to a portion of its source code repository.   However, it did not specify which portion of its source code was accessed, nor did it provide many further details about the incident.  “Upon learning of this matter, we immediately began working with leading forensic experts to resolve…

Microsoft Edge Found Holding Saved Credentials in Plaintext Memory

Security researcher Tom Jøran Sønstebyseter Rønning, posting as @L1v1ng0ffTh3L4N, has revealed that Microsoft Edge decrypts every saved password at startup and holds all of them in process memory, in cleartext, for the entire browser session.   He says this includes passwords for sites the user is visiting as…