❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 4 May 2024SecurityWeek
Before yesterdaySecurityWeek

Microsoft Overhauls Cybersecurity Strategy After Scathing CSRB Report

3 May 2024 at 13:47

Microsoft security chief Charlie Bell pledges significant reforms and a strategic shift to prioritize security above all other product features.

The post Microsoft Overhauls Cybersecurity Strategy After Scathing CSRB Report appeared first on SecurityWeek.

In Other News: Locked Shields 2024, Data Exposure Bugs, NVIDIA Patches

3 May 2024 at 09:15

Noteworthy stories that might have slipped under the radar: 4,000 take part in Locked Shields 2024 exercise, Qantas and JP Morgan hit by data exposure bugs, NVIDIA patches critical flaw.Β 

The post In Other News: Locked Shields 2024, Data Exposure Bugs, NVIDIA Patches appeared first on SecurityWeek.

Ransomware Defense Startup Mimic Raises Hefty $27M Seed RoundΒ 

2 May 2024 at 12:11

A new Silicon Valley startup called Mimic is coming out of the shadows with a hefty $27 million seed-stage funding round led by Ballistic Ventures.

The post Ransomware Defense Startup Mimic Raises Hefty $27M Seed RoundΒ  appeared first on SecurityWeek.

Verizon DBIR 2024 Shows Surge in Vulnerability Exploitation, Confirmed Data BreachesΒ 

2 May 2024 at 09:26

Verizon’s 2024 DBIR shows that vulnerability exploitation increased three times and confirmed data breaches doubled compared to the previous year.

The post Verizon DBIR 2024 Shows Surge in Vulnerability Exploitation, Confirmed Data BreachesΒ  appeared first on SecurityWeek.

Japan’s Kishida Unveils a Framework for Global Regulation of Generative AI

2 May 2024 at 08:30

Japan's Prime Minister unveiled an international framework for regulation and use of generative AI, adding to global efforts on governance for the rapidly advancing technology.

The post Japan’s Kishida Unveils a Framework for Global Regulation of Generative AI appeared first on SecurityWeek.

Deepfake of Principal’s Voice Is the Latest Case of AI Being Used for Harm

1 May 2024 at 20:45

Everyone β€” not just politicians and celebrities β€” should be concerned about this increasingly powerful deep-fake technology, experts say.

The post Deepfake of Principal’s Voice Is the Latest Case of AI Being Used for Harm appeared first on SecurityWeek.

Traceable AI Raises $30 Million to Safeguard Cloud APIs

1 May 2024 at 14:24

Traceable AI has raised $110 million since launching in 2018 with ambitious plans in the competitive API security and observability space.Β Β 

The post Traceable AI Raises $30 Million to Safeguard Cloud APIs appeared first on SecurityWeek.

Adobe Adds Content Credentials and Firefly to Bug Bounty Program

1 May 2024 at 10:55

Adobe is providing incentives for bug bounty hackers to report security flaws in its implementation of Content Credentials and Adobe Firefly.

The post Adobe Adds Content Credentials and Firefly to Bug Bounty Program appeared first on SecurityWeek.

Cuttlefish Malware Targets Routers, Harvests Cloud Authentication DataΒ 

1 May 2024 at 10:33

Cuttlefish malware platform roaming around enterprise SOHO routers capable of covertly harvesting public cloud authentication data from internet traffic.

The post Cuttlefish Malware Targets Routers, Harvests Cloud Authentication DataΒ  appeared first on SecurityWeek.

Machine Identity Firm Venafi Readies for the 90-day Certificate Lifecycle

1 May 2024 at 09:58

Venafi introduced a 90-Day TLS Readiness solution to help enterprises prepare for Google’s proposed 90-day limit for the lifecycle of a digital certificate.

The post Machine Identity Firm Venafi Readies for the 90-day Certificate Lifecycle appeared first on SecurityWeek.

UnitedHealth CEO Says Hackers Lurked in Network for Nine Days Before Ransomware Strike

30 April 2024 at 21:52

UnitedHealth Group’s CEO Andrew Witty shares details on the damaging cyberattack in testimony before a US Congress committee set for May 1, 2024.

The post UnitedHealth CEO Says Hackers Lurked in Network for Nine Days Before Ransomware Strike appeared first on SecurityWeek.

Finnish Hacker Gets Prison for Accessing Thousands of Psychotherapy Records and Demanding Ransoms

30 April 2024 at 13:10

In February 2023, French police arrested well-known Finnish hacker Aleksanteri KivimΓ€ki, who was living under a false identity near Paris. He was deported to Finland. His trial ended last month.

The post Finnish Hacker Gets Prison for Accessing Thousands of Psychotherapy Records and Demanding Ransoms appeared first on SecurityWeek.

Critical Vulnerabilities in Judge0 Lead to Sandbox Escape, Host Takeover

30 April 2024 at 12:56

Three vulnerabilities in the Judge0 open source service could allow attackers to escape the sandbox and obtain root privileges on the host.

The post Critical Vulnerabilities in Judge0 Lead to Sandbox Escape, Host Takeover appeared first on SecurityWeek.

Island Secures $175M Investment as Enterprise Browser Startups Defy Tech Giants

30 April 2024 at 12:26

Despite competitive pressures from industry behemoths like Microsoft and Google, investors are still betting big on startups in the specialized enterprise browser space.

The post Island Secures $175M Investment as Enterprise Browser Startups Defy Tech Giants appeared first on SecurityWeek.

Chinese Hackers Have Been Probing DNS Networks Globally for Years: Report

30 April 2024 at 12:06

While China-linked Muddling Meerkat’s operations look like DNS DDoS attacks, it seems unlikely that denial of service is their goal, at least in the near term.

The post Chinese Hackers Have Been Probing DNS Networks Globally for Years: Report appeared first on SecurityWeek.

FCC Fines Wireless Carriers for Sharing User Locations Without Consent

30 April 2024 at 10:43

The Federal Communications Commission leveraged nearly $200 million in fines against wireless carriers AT&T, Sprint, T-Mobile and Verizon for illegally sharing customers’ location data.

The post FCC Fines Wireless Carriers for Sharing User Locations Without Consent appeared first on SecurityWeek.

Vulnerability in R Programming Language Could Fuel Supply Chain Attacks

30 April 2024 at 09:07

A vulnerability (CVE-2024-27322) in the R programming language implementation can be exploited to execute arbitrary and be used as part of a supply chain attack.

The post Vulnerability in R Programming Language Could Fuel Supply Chain Attacks appeared first on SecurityWeek.

Tech CEOs Altman, Nadella, Pichai and Others Join Government AI Safety Board Led by DHS’ Mayorkas

29 April 2024 at 21:49

CEOs of major tech companies are joining a new artificial intelligence safety board to advise the federal government on how to protect the nation’s critical services from β€œAI-related disruptions.”

The post Tech CEOs Altman, Nadella, Pichai and Others Join Government AI Safety Board Led by DHS’ Mayorkas appeared first on SecurityWeek.

❌
❌