16 Apr

Americans who masterminded Nork IT worker fraud sentenced to 200 months behind bars

Two Americans have been jailed for a combined 200 months for helping North Korea generate $5 million through fraudulent IT worker schemes. Kejia “Tony” Wang,

Author rabih
16 Apr

Git identity spoof fools Claude into giving bad code the nod

Security boffins say Anthropic’s Claude can be tricked into approving malicious code with just two Git commands by spoofing a trusted developer’s identity. In a

Author rabih
16 Apr

Supply chain dependencies: Have you checked your blind spot?

Some cyber business risks only show up when you take a closer look. Supply chain blind spots are a perfect example. Behind these essential third-party

Author rabih
16 Apr

Textbook titan McGraw Hill on ransomware crew’s reading list after 13.5M records exposed

Textbook giant McGraw Hill has landed on a ransomware crew’s leak site after an alleged Salesforce-linked misconfiguration spilled 13.5 million records into the wild. Have

Author rabih
16 Apr

Microsoft announces product it doesn’t want you to buy: Extended security updates for old Exchange, and Skype for Biz

Microsoft will keep delivering security updates for old versions of Exchange Server and Skype for Business Server, after admitting that some customers aren’t ready to

Author rabih
16 Apr

Server-room lock was nothing but a crock

PWNED Welcome back to Pwned, the column where we immortalize the worst vulns that organizations opened up for themselves. If you’re the kind of person

Author rabih
16 Apr

Google Chrome lacks protection against one of the most basic and common ways to track users online

Google markets its Chrome browser by citing its superior safety features, but according to privacy consultant Alexander Hanff, Chrome does not protect against browser fingerprinting

Author rabih
15 Apr

Anthropic’s Project Glasswing CVE tally is still anyone’s guess

Last week, Anthropic surprised the world by declaring that its latest model, Mythos, is so good at finding vulns that it would create chaos if

Author rabih
15 Apr

Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP

Watch out for more Fortinet vulns! Two critical bugs in Fortinet’s sandbox could allow unauthenticated attackers to bypass authentication or execute unauthorized code on vulnerable

Author rabih
15 Apr

Automotive data biz Autovista blames ransomware for service disruption

Autovista confirms that it called in outside support to help clean up a ransomware infection currently affecting systems in Europe and Australia. The automotive data

Author rabih
15 Apr

French cops free mother and son after 20-hour crypto kidnap ordeal

A mother and her ten-year-old son are now free after being kidnapped for around 20 hours while the father was being extorted for hundreds of

Author rabih
15 Apr

Ancient Excel bug comes out of retirement for active attacks

While Microsoft was rolling out its bumper Patch Tuesday updates this week, US cybersecurity agency CISA was readying an alert about a 17-year-old critical Excel

Author rabih
15 Apr

Raspberry Pi OS ends open-door policy for sudo

The latest version of Raspberry Pi OS now requires a password for sudo by default. The change affects only new installations – existing setups are

Author rabih
15 Apr

UK told its Big Tech habit is now a national security risk

Britain has spent years wiring its public sector into US Big Tech, and a new report says that dependence could quickly become a national security

Author rabih
15 Apr

Agents hooked into GitHub can steal creds – but Anthropic, Google, and Microsoft haven’t warned users

Exclusive Security researchers hijacked three popular AI agents that integrate with GitHub Actions by using a new type of prompt injection attack to steal API

Author rabih
14 Apr

Microsoft’s massive Patch Tuesday: It’s raining bugs

Attackers exploited a spoofing vulnerability in Microsoft SharePoint Server before Redmond issued a fix as part of April’s mega Patch Tuesday. The monthly patch party

Author rabih
14 Apr

Commvault has a Ctrl+Z for rogue AI agents

Keep your agents close and your agent-monitoring software closer. Commvault’s new AI Protect can discover and monitor AI agents running inside AWS, Azure, and GCP

Author rabih
14 Apr

No honor among thieves as 0APT threatens rival ransomware gang Krybit

Two rival ransomware gangs have locked horns after 0APT threatened to expose people affiliated with Krybit. Dark web watchers spotted the move on Sunday, though

Author rabih
Load moreLoadingAll items loaded