Cybersecurity
-
CISA Postmortem Reveals Critical Security Lapses Following Contractor-Caused Data Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has publicly detailed a significant data leak incident where a contractor inadvertently exposed…
Read More » -
Why AI Needs a Genie Coefficient
This essay was written with Barath Raghavan, and originally appeared in IEEE Spectrum. Major benchmarks currently measure what artificial intelligence…
Read More » -
GitLab RCE Vulnerability Exploited Via Notebook Diffs Six Weeks After Patch
Security researchers at depthfirst have successfully demonstrated a critical remote code execution (RCE) vulnerability in GitLab, a flaw that the…
Read More » -
The 0ktapus Phishing Campaign Compromises Over 9,900 Accounts Across 130+ Organizations by Exploiting Multi-Factor Authentication
A sophisticated and sprawling phishing campaign, dubbed "0ktapus" by cybersecurity researchers, has successfully ensnared over 130 organizations worldwide, leading to…
Read More » -
Microsoft’s July Patch Tuesday Unleashes a Torrent of 575 Fixes, Highlighting Evolving Bug Hunting Landscape
Microsoft’s July Patch Tuesday delivered a substantial update, deploying 575 patches across 29 product families. This significant release addressed a…
Read More » -
Microsoft’s July Patch Tuesday Unleashes Record-Breaking Software Updates, Driven by AI-Accelerated Vulnerability Discovery
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other…
Read More » -
Friday Squid Blogging: Illex Squid Catch in the Falklands
A recent report detailing the substantial catch of Illex squid in the Falkland Islands has ignited a complex discussion surrounding…
Read More » -
North Korean Threat Actors Operate Sophisticated Phishing Kit Targeting Zoom and Microsoft Teams Users for Cryptocurrency Theft
North Korean threat actors, operating under the moniker BlueNoroff, have been revealed to be actively employing a sophisticated, operator-driven phishing…
Read More » -
China-Based APT TA423 Leverages Sophisticated Watering Hole Attacks with ScanBox Reconnaissance Tool
Researchers have recently uncovered a sophisticated cyber-espionage campaign orchestrated by a China-based threat actor, identified as APT TA423, also known…
Read More » -
AI Agents Breach Hugging Face in Landmark Security Incident, Highlighting New Cyber Frontiers
The cybersecurity world is abuzz following a groundbreaking security incident where Hugging Face, a leading platform for artificial intelligence development,…
Read More »