Viry a Červi

Infosec experts divided on AI's potential to assist red teams

The Register - Anti-Virus - 20 Prosinec, 2024 - 04:22
Yes, LLMs can do the heavy lifting. But good luck getting one to give evidence

CANALYS FORUMS APAC  Generative AI is being enthusiastically adopted in almost every field, but infosec experts are divided on whether it is truly helpful for red team raiders who test enterprise systems.…

Kategorie: Viry a Červi

Don't fall for a mail asking for rapid Docusign action – it may be an Azure account hijack phish

The Register - Anti-Virus - 19 Prosinec, 2024 - 06:30
Recent campaign targeted 20,000 folk across UK and Europe with this tactic, Unit 42 warns

Unknown criminals went on a phishing expedition that targeted about 20,000 users across the automotive, chemical and industrial compound manufacturing sectors in Europe, and tried to steal account credentials and then hijack the victims' Microsoft Azure cloud infrastructure.…

Kategorie: Viry a Červi

US reportedly mulls TP-Link router ban over national security risk

The Register - Anti-Virus - 18 Prosinec, 2024 - 21:52
It could end up like Huawei -Trump's gonna get ya, get ya, get ya

updated  The Feds may ban the sale of TP-Link routers in the US over ongoing national security concerns about Chinese-made devices being used in cyberattacks.…

Kategorie: Viry a Červi

Microsoft won't let customers opt out of passkey push

The Register - Anti-Virus - 18 Prosinec, 2024 - 18:30
Enrollment invitations will continue until security improves

Microsoft last week lauded the success of its efforts to convince customers to use passkeys instead of passwords, without actually quantifying that success.…

Kategorie: Viry a Červi

Boffins trick AI model into giving up its secrets

The Register - Anti-Virus - 18 Prosinec, 2024 - 16:30
All it took to make an Google Edge TPU give up model hyperparameters was specific hardware, a novel attack technique … and several days

Computer scientists from North Carolina State University have devised a way to copy AI models running on Google Edge Tensor Processing Units (TPUs), as used in Google Pixel phones and third-party machine learning accelerators.…

Kategorie: Viry a Červi

Phishers cast wide net with spoofed Google Calendar invites

The Register - Anti-Virus - 18 Prosinec, 2024 - 01:58
Not that you needed another reason to enable the 'known senders' setting

Criminals are spoofing Google Calendar emails in a financially motivated phishing expedition that has already affected about 300 organizations with more than 4,000 emails sent over four weeks, according to Check Point researchers.…

Kategorie: Viry a Červi

Interpol wants everyone to stop saying 'pig butchering'

The Register - Anti-Virus - 18 Prosinec, 2024 - 00:29
Victims' feelings might get hurt, global cops contend, and that could hinder reporting

Interpol wants to put an end to the online scam known as "pig butchering" – through linguistic policing, rather than law enforcement.…

Kategorie: Viry a Červi

Critical security hole in Apache Struts under exploit

The Register - Anti-Virus - 17 Prosinec, 2024 - 22:57
You applied the patch that could stop possible RCE attacks last week, right?

A critical security hole in Apache Struts 2 – patched last week – is currently being exploited using publicly available proof-of-concept (PoC) code.…

Kategorie: Viry a Červi

Ireland fines Meta for 2018 'View As' breach that exposed 30M accounts

The Register - Anti-Virus - 17 Prosinec, 2024 - 16:30
€251 million? Zuck can find that in his couch cushions, but Meta still vows to appeal

It's been six years since miscreants abused some sloppy Facebook code to steal access tokens belonging to 30 million users, and the slow-turning wheels of Irish justice have finally caught up with a €251 million ($264 million) fine for the social media biz. …

Kategorie: Viry a Červi

BlackBerry offloads Cylance's endpoint security products to Arctic Wolf

The Register - Anti-Virus - 17 Prosinec, 2024 - 07:02
Fresh attempt to mix the perfect cocktail of IoT and Infosec

BlackBerry's ambition to mix infosec and the Internet of Things has been squeezed, after the Canadian firm announced it is offloading Cylance's endpoint security products.…

Kategorie: Viry a Červi

Australia moves to drop some cryptography by 2030 – before quantum carves it up

The Register - Anti-Virus - 17 Prosinec, 2024 - 04:58
The likes of SHA-256, RSA, ECDSA and ECDH won't be welcome in just five years

Australia's chief cyber security agency has decided local orgs should stop using the tech that forms the current cryptographic foundation of the internet by the year 2030 – years before other nations plan to do so – over fears that advances in quantum computing could render it insecure.…

Kategorie: Viry a Červi

Ransomware scum blow holes in Cleo software patches, Cl0p (sort of) claims responsibility

The Register - Anti-Virus - 17 Prosinec, 2024 - 00:45
But can you really take crims at their word?

Supply chain integration vendor Cleo has urged its customers to upgrade three of its products after an October security update was circumvented, leading to widespread ransomware attacks that Russia-linked gang Cl0p has claimed are its evil work.…

Kategorie: Viry a Červi

Trump administration wants to go on cyber offensive against China

The Register - Anti-Virus - 16 Prosinec, 2024 - 20:30
The US has never attacked Chinese critical infrastructure before, right?

President-elect Donald Trump's team wants to go on the offensive against America's cyber adversaries, though it isn't clear how the incoming administration plans to achieve this. …

Kategorie: Viry a Červi

Deloitte says cyberattack on Rhode Island benefits portal carries 'major security threat'

The Register - Anti-Virus - 16 Prosinec, 2024 - 19:01
Personal and financial data probably stolen

A cyberattack on a Deloitte-managed government system in Rhode Island carries a "high probability" of sensitive data theft, the state says.…

Kategorie: Viry a Červi

Are your Prometheus servers and exporters secure? Probably not

The Register - Anti-Virus - 16 Prosinec, 2024 - 00:58
Plus: Netscaler brute force barrage; BeyondTrust API key stolen; and more

Infosec in brief  There's a problem of titanic proportions brewing for users of the Prometheus open source monitoring toolkit: hundreds of thousands of servers and exporters are exposed to the internet, creating significant security risks and leaving organizations vulnerable to attack.…

Kategorie: Viry a Červi

Iran-linked crew used custom 'cyberweapon' in US critical infrastructure attacks

The Register - Anti-Virus - 14 Prosinec, 2024 - 00:56
IOCONTROL targets IoT and OT devices from a ton of makers, apparently

An Iranian government-linked cybercriminal crew used custom malware called IOCONTROL to attack and remotely control US and Israel-based water and fuel management systems, according to security researchers.…

Kategorie: Viry a Červi

Scumbag gets 30 years in the clink for running CSAM dark-web chatrooms, abusing kids

The Register - Anti-Virus - 13 Prosinec, 2024 - 23:50
'Today’s sentencing is more than just a punishment. It’s a message'

A Texan who ran a forum on the dark web where depraved netizens could swap child sex abuse material (CSAM), and chat freely about abusing kids, has been sentenced to 30 years in prison.…

Kategorie: Viry a Červi

Google Timeline location purge causes collateral damage

The Register - Anti-Virus - 13 Prosinec, 2024 - 22:08
Privacy measure leaves some mourning lost memories

A year ago, Google announced plans to save people's Location History, which it now calls Timeline, locally on devices rather than on its servers.…

Kategorie: Viry a Červi

Cyber protection made intuitive and affordable

The Register - Anti-Virus - 13 Prosinec, 2024 - 15:37
How Cynet delivered 100 percent Protection and 100 percent Detection Visibility in 2024 MITRE ATT&CK Evaluation

Partner Content  Across small-to-medium enterprises (SMEs) and managed service providers (MSPs), the top priority for cybersecurity leaders is to keep IT environments up and running.…

Kategorie: Viry a Červi

Taming the multi-vault beast

The Register - Anti-Virus - 13 Prosinec, 2024 - 10:02
GitGuardian takes on enterprise secrets sprawl

Partner Content  With Non-Human Identities (NHIs) now outnumbering human users 100 to one in enterprise environments, managing secrets across multiple vaults has become a significant security concern.…

Kategorie: Viry a Červi
Syndikovat obsah