July 2024

New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection

New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection 2024-07-15 at 08:46 By Cybersecurity researchers have shed light on a new version of a ransomware strain called HardBit that comes packaged with new obfuscation techniques to deter analysis efforts. “Unlike previous versions, HardBit Ransomware group enhanced the version 4.0 with passphrase protection,” Cybereason researchers […]

New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection Read More »

Risk related to non-human identities: Believe the hype, reject the FUD

Risk related to non-human identities: Believe the hype, reject the FUD 2024-07-15 at 08:01 By Help Net Security The hype surrounding unmanaged and exposed non-human identities (NHIs), or machine-to-machine credentials – such as service accounts, system accounts, certificates and API keys – has recently skyrocketed. A steady stream of NHI-related breaches is causing some of

Risk related to non-human identities: Believe the hype, reject the FUD Read More »

Realm: Open-source adversary emulation framework

Realm: Open-source adversary emulation framework 2024-07-15 at 07:32 By Mirko Zorz Realm is an open-source adversary emulation framework emphasizing scalability, reliability, and automation. It’s designed to handle engagements of any size. “Realm is unique in its custom interpreter written in Rust. This allows us to write complex TTPs as code. With these actions as code,

Realm: Open-source adversary emulation framework Read More »

Discover the growing threats to data security

Discover the growing threats to data security 2024-07-15 at 07:01 By Mirko Zorz In this Help Net Security interview, Pranava Adduri, CEO at Bedrock Security, discusses how businesses can identify and prioritize their data security risks. Adduri emphasizes the necessity of ongoing monitoring and automation to keep up with evolving threats and maintain the shortest

Discover the growing threats to data security Read More »

Encrypted traffic: A double-edged sword for network defenders

Encrypted traffic: A double-edged sword for network defenders 2024-07-15 at 06:31 By Help Net Security Organizations are ramping up their use of encrypted traffic to lock down data. Could they be making it easier to hide threats in the process? On one hand, encryption means enhanced privacy, but it can also make the job of

Encrypted traffic: A double-edged sword for network defenders Read More »

Pressure mounts for C-Suite executives to implement GenAI solutions

Pressure mounts for C-Suite executives to implement GenAI solutions 2024-07-15 at 06:01 By Help Net Security 87% of C-Suite executives feel under pressure to implement GenAI solutions at speed and scale, according to RWS. Despite these pressures, 76% expressed an overwhelming excitement across their organization for the potential benefits of GenAI. However, this excitement is

Pressure mounts for C-Suite executives to implement GenAI solutions Read More »

UK cyber-boss slams China’s bug-hoarding laws

UK cyber-boss slams China’s bug-hoarding laws 2024-07-15 at 03:21 By Laura Dobberstein Plus: Japanese scientists ID ancient supernova; AWS dismisses China trouble rumor; and more ASIA IN BRIEF  The interim CEO of the UK’s National Cyber Security Centre (NCSC) has criticized China’s approach to bug reporting.… This article is an excerpt from The Register View

UK cyber-boss slams China’s bug-hoarding laws Read More »

Windows MSHTML Zero-Day Exploited to Install Malware

Windows MSHTML Zero-Day Exploited to Install Malware 2024-07-15 at 00:01 Check Point Researchers have discovered that a Windows MSHTML zero-day vulnerability has been exploited in malware attacks for over a year. The flaw, tracked as CVE-2024-38112, allows threat actors to bypass built-in security features and launch malicious scripts, which led to the installation of password-stealing

Windows MSHTML Zero-Day Exploited to Install Malware Read More »

Google in Advanced Talks to Buy Wiz for $23B: WSJ Report

Google in Advanced Talks to Buy Wiz for $23B: WSJ Report 2024-07-14 at 22:55 By SecurityWeek News Google’s parent company Alphabet is reportedly in advanced talks to acquire the hotshot Israeli data security startup. The post Google in Advanced Talks to Buy Wiz for $23B: WSJ Report appeared first on SecurityWeek. This article is an

Google in Advanced Talks to Buy Wiz for $23B: WSJ Report Read More »

Honey, I shrunk the LLM! A beginner’s guide to quantization – and testing it

Honey, I shrunk the LLM! A beginner’s guide to quantization – and testing it 2024-07-14 at 14:46 By Tobias Mann Just be careful not to shave off too many bits … These things are known to hallucinate as it is Hands on  If you hop on Hugging Face and start browsing through large language models,

Honey, I shrunk the LLM! A beginner’s guide to quantization – and testing it Read More »

Week in review: RADIUS protocol critical vuln, Microsoft 0-day exploited for a year, AT&T breach

Week in review: RADIUS protocol critical vuln, Microsoft 0-day exploited for a year, AT&T breach 2024-07-14 at 11:02 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Hackers stole call, text records of “nearly all” of AT&T’s cellular customers Hackers leveraging stolen Snowflake account credentials

Week in review: RADIUS protocol critical vuln, Microsoft 0-day exploited for a year, AT&T breach Read More »

Game dev accuses Intel of selling ‘defective’ Raptor Lake CPUs

Game dev accuses Intel of selling ‘defective’ Raptor Lake CPUs 2024-07-13 at 10:16 By Matthew Connatser High-end processor instability headaches, failures pushed one studio to switch to AMD One game developer says it’s had enough of Intel’s 13th and 14th-generation Core microprocessors, calling them “defective.”… This article is an excerpt from The Register View Original

Game dev accuses Intel of selling ‘defective’ Raptor Lake CPUs Read More »

AT&T Confirms Data Breach Affecting Nearly All Wireless Customers

AT&T Confirms Data Breach Affecting Nearly All Wireless Customers 2024-07-13 at 09:31 By American telecom service provider AT&T has confirmed that threat actors managed to access data belonging to “nearly all” of its wireless customers as well as customers of mobile virtual network operators (MVNOs) using AT&T’s wireless network. “Threat actors unlawfully accessed an AT&T

AT&T Confirms Data Breach Affecting Nearly All Wireless Customers Read More »

Car dealer software slinger CDK Global said to have paid $25M ransom after cyberattack

Car dealer software slinger CDK Global said to have paid $25M ransom after cyberattack 2024-07-13 at 03:01 By Matthew Connatser 15,000 dealerships take estimated $600M+ hit CDK Global reportedly paid a $25 million ransom in Bitcoin after its servers were knocked offline by crippling ransomware.… This article is an excerpt from The Register View Original

Car dealer software slinger CDK Global said to have paid $25M ransom after cyberattack Read More »

White House urged to double check Microsoft isn’t funneling AI to China via G42 deal

White House urged to double check Microsoft isn’t funneling AI to China via G42 deal 2024-07-12 at 23:31 By Matthew Connatser Windows maker insisted everything will be locked down and secure – which given its reputation, uh-oh! Two House committee chairs have sent a public letter to the White House asking it to look into

White House urged to double check Microsoft isn’t funneling AI to China via G42 deal Read More »

CISA broke into a US federal agency, and no one noticed for a full 5 months

CISA broke into a US federal agency, and no one noticed for a full 5 months 2024-07-12 at 21:16 By Connor Jones Red team exercise revealed a score of security fails The US Cybersecurity and Infrastructure Security Agency (CISA) says a red team exercise at a certain unnamed federal agency in 2023 revealed a string

CISA broke into a US federal agency, and no one noticed for a full 5 months Read More »

Scroll to Top