News
Trend Micro offers weak workaround for already-exploited critical vuln in management console
Infosec In Brief A critical vulnerability in the on-prem version of Trend Micro's Apex One endpoint security platform is under active exploitation, the company admitted last week, and there's no patch available.…
DEF CON hackers plug security holes in US water systems amid tsunami of threats
def con A DEF CON hacker walks into a small-town water facility…no, this is not the setup for a joke or a (super-geeky) odd-couple rom-com. It's a true story that happened at five utilities across four states.…
The inside story of the Telemessage saga, and how you can view the data
DEF CON On Saturday at DEF CON, security boffin Micah Lee explained just how he hacked into TeleMessage, the supposedly secure messaging app used by White House officials, which in turn led to a massive database dump of their communications.…
Chinese biz using AI to hit US politicians, influencers with propaganda
DEF CON A cache of documents uncovered by Vanderbilt University has revealed disturbing details about how a Chinese company is building up a database of US politicians and influencers with whom to share propaganda.…
Star leaky app of the week: StarDict
As Trixie gets ready to début, a little-known app is hogging the limelight: StarDict, which sends whatever text you select, unencrypted, to servers in China.…
Ex-White House cyber, counter-terrorism guru: Microsoft considers security an annoyance, not a necessity
Comment Roger Cressey served two US presidents as a senior cybersecurity and counter-terrorism advisor and currently worries he'll experience a "political aneurysm" due to Microsoft's many security messes.…
Infosec hounds spot prompt injection vuln in Google Gemini apps
Black hat A trio of researchers has disclosed a major prompt injection vulnerability in Google's Gemini large language model-powered applications.…
UK secretly allows facial recognition scans of passport, immigration databases
Privacy groups report a surge in UK police facial recognition scans of databases secretly stocked with passport photos lacking parliamentary oversight.…
UK proxy traffic surges as users consider VPN alternatives amid Online Safety Act
Amid the furor around surging VPN usage in the UK, many users are eyeing proxies as a potential alternative to the technology.…
Prohibition never works, but that didn't stop the UK's Online Safety Act
Opinion You might think, since I write about tech all the time, my degrees are in computer science. Nope. I'm a bona fide, degreed historian, which is why I can say with confidence that the UK's recently passed Online Safety Act is doomed to fail.…
Why blow up satellites when you can just hack them?
Black Hat Four countries have now tested anti-satellite missiles (the US, China, Russia, and India), but it's much easier and cheaper just to hack them.…
German security researchers say 'Windows Hell No' to Microsoft biometrics for biz
Black Hat Microsoft is pushing hard for Windows users to shift from using passwords to its Hello biometrics system, but researchers sponsored by the German government have found a critical flaw in its business implementation.…
Microsoft, CISA warn yet another Exchange server bug can lead to 'total domain compromise'
Microsoft and the feds late Wednesday sounded the alarm on another high-severity bug in Exchange Server hybrid deployments that could allow attackers to escalate privileges from on-premises Exchange to the cloud.…
Black Hat's network ops center brings rivals together for a common cause
Black Hat Neil "Grifter" Wyler is spending the week "looking for a needle in a needle stack," a task he'll perform from the network operations center (NOC) that powers the Black Hat security conference in Las Vegas.…
CISA releases malware analysis for Sharepoint Server attack
CISA has published a malware analysis report with compromise indicators and Sigma rules for "ToolShell" attacks targeting specific Microsoft SharePoint Server versions.…
KLM, Air France latest major organizations looted for customer data
European airline giants Air France and KLM say they are the latest in a string of major organizations to have their customers' data stolen by way of a break-in at a third party org.…
Meta training AI on social media posts? Only 7% in Europe think it's OK
Meta's enthusiasm for training its AI on user data is not shared by the users themselves – at least for some Europeans – according a study commissioned by Facebook legal nemesis Max Schrems and his privacy advocacy group Noyb.…
Amnesty slams Elon Musk's X for 'central role' in fueling 2024 UK riots
Amnesty International claims Elon Musk's X platform "played a central role" in pushing the misinformation that stoked racially charged violence following last year's Southport murders.…
Could agentic AI save us from the cybercrisis?
Sponsored feature The cyberthreat landscape is evolving fast, with highly organized bad actors launching ever more devastating and sophisticated attacks against often ill-prepared targets.…
Microsoft researchers bullish on AI security agent even though it let 74% of malware slip through
Microsoft has rolled out an autonomous AI agent that it claims can detect malware without human assistance.…
Pages
