A ChatGPT vulnerability documented in a new report causes training data, some containing personal information, to randomly appear when one tells the chatbot to repeat a particular word.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Over the next 10 years, we will see companies continue to replace their on-premise network and security appliances with a secured corporate network over the internet. Remote access solutions like zero trust network access (ZTNA) and secure access server edge (SASE) are here to stay.
Cybercriminals aren’t just hacking for activism or for fun. They’re running their attacks like a business, targeting organisations to extort money – and they’re getting smarter at it. Don’t get complacent, don’t cut corners and shore yourself up against the people lurking in the cyber-shadows.
MetaMask, a popular crypto wallet app, has a default setting, apparently unbeknownst to many users, that automatically writes the recovery seed phrase for the wallet to the user's iCloud backups.
Security researchers discovered a “package planting” flaw that allows malware developers to add respected open-source contributors to malicious NPM packages without notification or approval.
The new “agentjacking” attack takes almost no real hacking ability to pull off. It's predicated on pulling a public credential that can readily be found in a web site's JavaScript source code, which can be used by anyone to get Sentry to accept an error event full of malicious instructions that is passed on to AI coding agents.
We're storing too much sensitive information, and our budgets are way too small to protect it. As long as we continue to undervalue data, we will underspend on protecting it.
Amazon has confirmed that it was impacted by the MOVEit third party breach that took place in 2023, and that a large amount of employee data was included with a massive trove that was offered for sale on a hacking forum.
U.S. face cyber challenges amidst the pandemic with a DDoS attack on Federal health agency and an ongoing disinformation campaign that sows fear and confusion in the public.
Digital Shadows Photon Research team found that over 24 billion stolen user credentials were available for sale on the dark web market in 2022, an increase of 65% in two years.










