Category: Uncategorized
-

North Korean Hackers Targeting Developers with Malicious npm Packages [email protected] (The Hacker News)
A set of fake npm packages discovered on the Node.js repository has been found to share ties with North Korean state-sponsored actors, new findings from Phylum show. The packages are named execution-time-async, data-time-utils, login-time-utils, mongodb-connection-utils, and mongodb-execution-utils. One of the packages in question, execution-time-async, masquerades as its legitimateRead More
-

Three Tips to Protect Your Secrets from AI Accidents [email protected] (The Hacker News)
Last year, the Open Worldwide Application Security Project (OWASP) published multiple versions of the “OWASP Top 10 For Large Language Models,” reaching a 1.0 document in August and a 1.1 document in October. These documents not only demonstrate the rapidly evolving nature of Large Language Models, but the evolving ways in which they can be…
-

Banking Trojans Target Latin America and Europe Through Google Cloud Run [email protected] (The Hacker News)
Cybersecurity researchers are warning about a spike in email phishing campaigns that are weaponizing the Google Cloud Run service to deliver various banking trojans such as Astaroth (aka Guildma), Mekotio, and Ousaban (aka Javali) to targets across Latin America (LATAM) and Europe. “The infection chains associated with these malware families feature the use of maliciousRead More
-

LockBit Ransomware Group Resurfaces After Law Enforcement Takedown [email protected] (The Hacker News)
The threat actors behind the LockBit ransomware operation have resurfaced on the dark web using new infrastructure, days after an international law enforcement exercise seized control of its servers. To that end, the notorious group has moved its data leak portal to a new .onion address on the TOR network, listing 12 new victims as of writing.…
-

Authorities Claim LockBit Admin “LockBitSupp” Has Engaged with Law Enforcement [email protected] (The Hacker News)
LockBitSupp, the individual(s) behind the persona representing the LockBit ransomware service on cybercrime forums such as Exploit and XSS, “has engaged with law enforcement,” authorities said. The development comes following the takedown of the prolific ransomware-as-a-service (RaaS) operation as part of a coordinated international operation codenamed Cronos. Over 14,000 rogueRead More
-
White House Wades Into Debate on ‘Open’ Versus ‘Closed’ Artificial Intelligence Systems Associated Press
The White House is seeking public comment on the risks and benefits of having an AI system’s key components publicly available for anyone to use and modify. The post White House Wades Into Debate on ‘Open’ Versus ‘Closed’ Artificial Intelligence Systems appeared first on SecurityWeek. Read More
-

Microsoft Expands Free Logging Capabilities for all U.S. Federal Agencies [email protected] (The Hacker News)
Microsoft has expanded free logging capabilities to all U.S. federal agencies using Microsoft Purview Audit irrespective of the license tier, more than six months after a China-linked cyber espionage campaign targeting two dozen organizations came to light. “Microsoft will automatically enable the logs in customer accounts and increase the default log retention period from 90…
-

Dormant PyPI Package Compromised to Spread Nova Sentinel Malware [email protected] (The Hacker News)
A dormant package available on the Python Package Index (PyPI) repository was updated nearly after two years to propagate an information stealer malware called Nova Sentinel. The package, named django-log-tracker, was first published to PyPI in April 2022, according to software supply chain security firm Phylum, which detected an anomalous update to the library on February 21,Read More
-
Toward Better Patching — A New Approach with a Dose of AI Kevin Townsend
Use of AI to cut through the noise and confusion of the current vulnerability prioritization approaches suggests an exciting future for AI-assisted operations to vulnerability triaging. The post Toward Better Patching — A New Approach with a Dose of AI appeared first on SecurityWeek. Read More
-
Apple Shortcuts Vulnerability Exposes Sensitive Information Ionut Arghire
High-severity vulnerability in Apple Shortcuts could lead to sensitive information leak without user’s knowledge. The post Apple Shortcuts Vulnerability Exposes Sensitive Information appeared first on SecurityWeek. Read More
