AI tools help hacker break in for $25 per target
It’s cheap to set yourself up as a hacker these days using AI. Someone attacked 105 online retailers over a period of five days, compromising 27 of them — all for an average of $25 per attack,...
View ArticleDocumentation placeholder domain used in ClickFix attacks
The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party...
View ArticleGitLab issue email’s only security is obscurity
It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor security defaults and a long-lived token embedded...
View ArticleFixing Flock: The controls needed now that misuse patterns are clear
Flock Safety has stirred widespread debate of late. Flock builds interconnected networks of automated license-plate readers and other public safety cameras. Those systems can help police solve serious...
View ArticleWordPress patches a critical severity security vulnerability
WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already...
View ArticleMicrosoft integrates SOC capabilities with Defender for enterprises
Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost. Microsoft is delivering the capability through the...
View ArticleOn-prem VeloCloud Orchestrator under attack, only some versions patched
A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devices it controls. Arista, which now owns the...
View ArticleAviation solved the vigilance problem. AI just gave security a worse one
An air traffic controller watching a busy scope will, sooner or later, miss the one aircraft that matters. Sustained attention decays under load, a limit aviation named the vigilance decrement and has...
View Article58 hardware vulnerabilities: A guide to the threats
In January 2018, the entire computer industry was put on alert by two new processor vulnerabilities dubbed Meltdown and Spectre that defeated the fundamental OS security boundaries separating kernel...
View ArticleCheck Point hacked: The security software protecting your network has become...
A firewall is supposed to be the barrier between attackers and the enterprise network, but that barrier can itself become a threat actors’ tool. Check Point has revealed that attackers are actively...
View ArticleF5 fixes actively exploited zero-day flaw in BIG-IP APM
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization...
View ArticleGitHub App keys can still enable takeovers long after they are forgotten
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories and permissions. But the private keys these...
View ArticleOkta bets on identity to control AI agents, but is identity enough?
Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s making the moves of a would-be leader in this emerging cyber market. “Identity is the primary...
View ArticleAI malware just removed the human from the attack loop
Attackers using AI have greatly benefited when it comes to speed and scale, and now, says Cisco Talos, the technology has evolved to execute large portions of the attack chain entirely without human...
View ArticleMicrosoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime
Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000...
View ArticleZ.ai disables coding assistant feature after flaw exposed enterprise code...
Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users’ local code repositories to...
View ArticleBeware these fake websites selling subscriptions to AI assistants
Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes. The...
View ArticleThe cyber AI parity window now has a deadline
In April, I wrote about what I called the Cyber AI Parity Window. This is the rare period in which defenders and adversaries gained access to the same transformative technology at roughly the same...
View ArticleCISOs can no longer ignore the nation-state threat
Flare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity landscape, with the balance swinging between deep collaboration and...
View ArticleGemini broke into 3 companies, but Google kept it quiet because ‘no damage...
A Google Gemini AI agent broke into three companies in May, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday. But...
View Article