20 Oct

Open source LLM tool primed to sniff out Python zero-days

Researchers with Seattle-based Protect AI plan to release a free, open source tool that can find zero-day vulnerabilities in Python codebases with the help of

Author rabih
18 Oct

Jetpack fixes 8-year-old flaw affecting millions of WordPress sites

in brief A critical security update for the near-ubiquitous WordPress plugin Jetpack was released last week. Site administrators should ensure the latest version is installed

Author rabih
18 Oct

Alleged Bitcoin crook faces 5 years after SEC’s X account pwned

An Alabama man faces five years in prison for allegedly attempting to manipulate the price of Bitcoin by pwning the US Securities and Exchange Commission’s

Author rabih
18 Oct

Intel hits back at China’s accusations it bakes in NSA backdoors

Intel has responded to Chinese claims that its chips include security backdoors at the direction of America’s NSA. The accusations were made earlier this week

Author rabih
18 Oct

Threat actors exploiting zero-days faster than ever – Week in security with Tony Anscombe

Video The average time it takes attackers to weaponize a vulnerability, either before or after a patch is released, shrank from 63 days in 2018-2019

Author rabih
18 Oct

ESET denies it was compromised as Israeli orgs targeted with ‘ESET-branded’ wipers

ESET denies being compromised after an infosec researcher highlighted a wiper campaign that appeared to victims as if it was launched using the Slovak security

Author rabih
18 Oct

Critical default credential in Kubernetes Image Builder allows SSH root access

A critical bug in Kubernetes Image Builder could allow unauthorized SSH access to virtual machines (VMs) thanks to default credentials being included during the image

Author rabih
18 Oct

Intel lightly hits back at China’s accusations it bakes in NSA backdoors

Intel has responded to Chinese claims that its chips include security backdoors at the direction of America’s NSA. The accusations were made earlier this week

Author rabih
18 Oct

Intel robustly refutes China’s accusations it bakes in NSA backdoors

Intel has roundly rebutted Chinese accusations that its chips include security backdoors at the direction of the US National Security Agency (NSA). The accusations were

Author rabih
18 Oct

Biz hired, and fired, a fake North Korean IT worker – then the ransom demands began

It’s a pattern cropping up more and more frequently: a company fills an IT contractor post, not realizing it’s mistakenly hired a North Korean operative.

Author rabih
18 Oct

Uncle Sam puts $10M bounty on Russian troll farm Rybar

The US has placed a $10 million bounty on Russian media network Rybar and a number of its key staffers following alleged attempts to sway

Author rabih
17 Oct

Troubled US insurance giant hit by extortion after data leak

US insurance provider Globe Life, already grappling with legal troubles, now faces a fresh headache: an extortion attempt involving stolen customer data. In a report

Author rabih
17 Oct

Brazilian police claim they’ve cuffed serial cybercrook behind FBI and Airbus attacks

Brazilian police are being cagey with the details about the arrest of a person suspected to be responsible for various high-profile data thefts. The policia

Author rabih
17 Oct

WeChat devs introduced security flaws when they modded TLS, say researchers

Messaging giant WeChat uses a network protocol that the app’s developers modified – and by doing so introduced security weaknesses, researchers claim. WeChat uses MMTLS, a

Author rabih
17 Oct

Anonymous Sudan isn’t any more: Two alleged operators named, charged

Hacktivist gang Anonymous Sudan appears to have lost its anonymity after the US Attorney’s Office on Wednesday unsealed an indictment identifying two of its alleged

Author rabih
16 Oct

US contractor pays $300k to settle accusation it didn’t properly look after Medicare users’ data

A US government contractor will settle claims it violated cybersecurity rules prior to a breach that compromised Medicare beneficiaries’ personal data. Virginia-based ASRC Federal Data

Author rabih
16 Oct

Critical default credential bug in Kubernetes Image Builder allows SSH root access

A critical bug in Kubernetes Image Builder could allow unauthorized SSH access to virtual machines (VMs) due to default credentials being enabled during the image

Author rabih
16 Oct

Critical hardcoded SolarWinds credential now exploited in the wild

A critical, hardcoded login credential in SolarWinds’ Web Help Desk line has been exploited in the wild by criminals, according to the US Cybersecurity and

Author rabih
Load moreLoadingAll items loaded