Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

Jan Leike, who ran OpenAI’s “Super Alignment” team, believes there should be more focus on preparing for the next generation of AI models, including on things like safety.

Slack reveals it has been training AI/ML models on customer data, including messages, files and usage information. It’s opt-in by default.

Noteworthy stories that might have slipped under the radar: FBI is targeting Scattered Spider, Australia’s MediSecure hacked, new Wi-Fi attack.

CISA has added two vulnerabilities in discontinued D-Link products to its KEV catalog, including a decade-old flaw.

A critical vulnerability tracked as CVE-2024-34359 and dubbed Llama Drama can allow hackers to target AI product developers.

The Antidot Android banking trojan snoops on users and steals their credentials, contacts, and SMS messages.

The Black Basta group abuses remote connection tool Quick Assist in vishing attacks leading to ransomware deployment.

The US government has announced charges, seizures, arrests and rewards as part of an effort to disrupt a scheme that generates revenue for North Korea.

C/side has emerged from stealth mode with $1.7 million in pre-seed funding from Scribble Ventures and angel investors

Network infrastructure as-a-service Alkira has raised $100 million in a Series C funding round led by Tiger Global Management.

Honoring my father by translating his timeless life lessons into practical wisdom for the cybersecurity profession.

People on the Move

OT zero trust access and control company Dispel has appointed Dean Macris as its CISO.

Cloud identity and security solutions firm Saviynt has hired former Gartner Analyst Henrique Teixeira as Senior Vice President of Strategy.

PR and marketing firm FleishmanHillard named Scott Radcliffe as the agency’s global director of cybersecurity.

Portnox, a provider of zero trust access control solutions, announced that Joseph Rodriguez has joined the company as Chief Revenue Officer.

Cybersecurity awareness training firm NINJIO has appointed Jon Dion as its Chief Revenue Officer.

More People On The Move
Slack data for AI Slack data for AI

Slack reveals it has been training AI/ML models on customer data, including messages, files and usage information. It’s opt-in by default.

Microsoft Quick Assist Tool Abused for Ransomware Delivery

The Black Basta group abuses remote connection tool Quick Assist in vishing attacks leading to ransomware deployment.

Palo Alto Networks partners with IBM on cybersecurity Palo Alto Networks partners with IBM on cybersecurity

Palo Alto Networks and IBM announced a significant partnership to jointly provide cybersecurity solutions.

Top Cybersecurity Headlines

Jan Leike, who ran OpenAI’s “Super Alignment” team, believes there should be more focus on preparing for the next generation of AI models, including…

Slack reveals it has been training AI/ML models on customer data, including messages, files and usage information. It’s opt-in by default.

Noteworthy stories that might have slipped under the radar: FBI is targeting Scattered Spider, Australia’s MediSecure hacked, new Wi-Fi attack.

CISA has added two vulnerabilities in discontinued D-Link products to its KEV catalog, including a decade-old flaw.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Upcoming Cybersecurity Events

The AI Risk Summit brings together security and risk management executives, AI researchers, policy makers, software developers and influential business and government stakeholders. [June 25-26, Ritz-Carlton, Half Moon Bay, CA]

Learn More

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Learn More

Designed for senior level cybersecurity leaders to discuss, share and learn innovative information security and risk management strategies, SecurityWeek’s CISO Forum, will take place June 25-26 at the Ritz-Carlton, Half Moon Bay, CA

Learn More

SecurityWeek’s Threat Detection and Incident Response (TDIR) Summit dives into Threat hunting tools and frameworks, and explores the value of threat intelligence data in the defender’s security stack.

Learn More

Vulnerabilities

Cybercrime

Last Friday, the Gioconda Law Group, a New York-based brand protection and anti-counterfeiting law firm, filed a suit against Arthur Wesley Kenzie, a self-styled cyber security expert living in Canada.Kenzie is accused of trademark infringement and Cybersquatting – the act of intentionally registering a domain with a deliberate misspelling of a protected name for the purpose of personal gain or misdirection. In addition, he used the misspelled domain to acquire emails intended for the law-firm.

F5 Networks has launched a cloud-based service that will detect and stop IP addresses associated with malicious activities from accessing the network. Powered by Webroot’s IP Reputation Service and integrated into F5's Traffic Management Operating System (TMOS), F5’s newest offering is designed to merge with their other subscription-based solutions.

Two members of LulzSec, Ryan Cleary (19), and Jake Davis (18), appeared in a London court on Monday. During their appearance, Cleary and Davis each admitted to being members of LulzSec and pled guilty to launching DDoS attacks against the CIA and Sony Corp websites.

Qualys, the soon-to-go-public provider of cloud security and compliance solutions, today said that its flagship QualysGuard Web Application Scanning (WAS) service will be able to help customers identify Web application cookies in order to help organizations comply with the European Union (EU) Cookie Directive that will be enforced in the United Kingdom (UK) effective on May 26, 2012.

Each year, security experts and IT experts take a hard look at the threats that dominated in years past in an effort to prepare for the future. While hacker groups and technology are evolving faster than ever, there are still trends we can spot if we take a far and wide enough step back to see the whole picture. The annual Verizon Data Breach Investigations report shines some holistic light on what’s been happening in the world of cybercrime. Here’s...

Cisco Addresses Code execution and DoS Vulnerabilities Cisco has issued three security advisories that address vulnerabilities within Cisco ASA and ASASM, their AnyConnect Secure Mobility Client, and Application Control Engine (ACE). According to their warnings, Cisco says that the issues could lead to code execution in some cases, or denial of service in others.

Michael Barrett, PayPal's CISO, was initially against the idea of paying people who reported security problems properly. However, after seeing the success of the bug bounty programs launched by Mozilla, Google, and Facebook, he’s had a change of heart. So on Thursday, PayPal officially launched a bounty program of their own, becoming the first financial firm on the Web to do so in the process.

A Russian security firm, using a combination of TCP scans and Google, found that nearly a quarter of the organizations running vulnerable versions of SAP are tempting fate by leaving them exposed to the Internet. This discovery, the research says, dispels the myth that SAP systems are only available from the internal network, leading to the misconception that they are protected by design.

According to comments made on Iran’s state-ran television by Intelligence Minister Heydar Moslehi, the nation has detected another cyber attack aimed at their nuclear facilities. These claims come shortly after the New York Times and Washington Post independently revealed that the U.S., along with Israel, used Stuxnet and Flame to target Iran’s nuclear program.Iran's Intelligence Minister Heydar Moslehi made the comments Thursday afternoon.

Researchers at ESET have uncovered a new worm that is stealing AutoCAD drawings and designs, and shipping them off to an email account that appears to be in China. Given the hype around Stuxnet and other focused code, the appearance of this worm took ESET researchers by surprise.The malware itself is written in AutoLISP, the scripting language used by AutoCAD. Over the last two months, the worm – called ACAD/Medre.A – has remained focused on Latin America, most notably Peru.

Face.com, the facial recognition start-up recently purchased by Facebook, has patched a vulnerability in its KLIK application that could have enabled attackers to compromise Twitter and Facebook accounts. The vulnerability was reported by independent security researcher Ashkan Soltani. KLIK is an iPhone camera app designed to make it easy for Facebook users to tag their friends in photos using facial recognition technology.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

A critical vulnerability tracked as CVE-2024-34359 and dubbed Llama Drama can allow hackers to target AI product developers.

Cloud Security

Cloud Security

Financial terms were not released but the price tag is expected to be hefty with Exabeam’s most recent valuation pegged at $2.5 billion.