security
-
Cybersecurity
CISA Postmortem Reveals Critical Security Lapses Following Contractor-Caused Data Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has publicly detailed a significant data leak incident where a contractor inadvertently exposed…
Read More » -
Cybersecurity
Why AI Needs a Genie Coefficient
This essay was written with Barath Raghavan, and originally appeared in IEEE Spectrum. Major benchmarks currently measure what artificial intelligence…
Read More » -
Cybersecurity
GitLab RCE Vulnerability Exploited Via Notebook Diffs Six Weeks After Patch
Security researchers at depthfirst have successfully demonstrated a critical remote code execution (RCE) vulnerability in GitLab, a flaw that the…
Read More » -
Cybersecurity
The 0ktapus Phishing Campaign Compromises Over 9,900 Accounts Across 130+ Organizations by Exploiting Multi-Factor Authentication
A sophisticated and sprawling phishing campaign, dubbed "0ktapus" by cybersecurity researchers, has successfully ensnared over 130 organizations worldwide, leading to…
Read More » -
Cybersecurity
Microsoft’s July Patch Tuesday Unleashes a Torrent of 575 Fixes, Highlighting Evolving Bug Hunting Landscape
Microsoft’s July Patch Tuesday delivered a substantial update, deploying 575 patches across 29 product families. This significant release addressed a…
Read More » -
Cybersecurity
Microsoft’s July Patch Tuesday Unleashes Record-Breaking Software Updates, Driven by AI-Accelerated Vulnerability Discovery
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other…
Read More » -
Cybersecurity
Friday Squid Blogging: Illex Squid Catch in the Falklands
A recent report detailing the substantial catch of Illex squid in the Falkland Islands has ignited a complex discussion surrounding…
Read More » -
Cybersecurity
North Korean Threat Actors Operate Sophisticated Phishing Kit Targeting Zoom and Microsoft Teams Users for Cryptocurrency Theft
North Korean threat actors, operating under the moniker BlueNoroff, have been revealed to be actively employing a sophisticated, operator-driven phishing…
Read More » -
Cybersecurity
China-Based APT TA423 Leverages Sophisticated Watering Hole Attacks with ScanBox Reconnaissance Tool
Researchers have recently uncovered a sophisticated cyber-espionage campaign orchestrated by a China-based threat actor, identified as APT TA423, also known…
Read More » -
Cybersecurity
AI Agents Breach Hugging Face in Landmark Security Incident, Highlighting New Cyber Frontiers
The cybersecurity world is abuzz following a groundbreaking security incident where Hugging Face, a leading platform for artificial intelligence development,…
Read More »