The government is addressing software supply chain security with new requirements. The OMB has issued a new memorandum that sets a year-long framework for vendors to provide assurances of secure software development.
UK law enforcement has shared over half a million compromised passwords found in cloud storage with Have I Been Pwned. The headline item is that over one-third of these passwords (about 225 million) have not been logged before.
A spyware vendor in Spain has been linked to a zero-day exploitation framework that impacted Windows, as well as the Chrome and Firefox browsers, from 2018 to 2021. Google researchers present markers found in its code including a script that is signed by the company.
Chinese actors are deploying thousands of LLM gateways to clone U.S. frontier models, share credentials, and bypass geographic restrictions, rate limits, and usage metering.
An attacker could use a vulnerability to issue fake alerts via the Emergency Alert Systems. The vulnerable software is in the possession of television and radio stations throughout the country, who are being called upon to download a software update.
Joint federal cybersecurity advisory warns of a tenacious cyber espionage campaign by Russian hackers against U.S. and allied networks using evolving TTPs of varying sophistication.
Hacktivist group has taken it upon itself to expose the sites users, dumping some 70 gigabytes of hacked data that includes highly sensitive personal information, messages and passwords.
Both suspected state-backed foreign adversaries and more run-of-the-mill cyber criminals appear to mostly still be focused on using AI tools to make their existing operations faster, more efficient and more error-free. OpenAI's ChatGPT and other models appear to have fairly strong guardrails that are highly resistant to creation of malware or automation of attack operations.
23andMe will pay $30 million to settle a data breach lawsuit from the 2023 credential stuffing attack that exposed the personal and genetic information of 6.9 million customers.
Thycotic survey of global CISOs shows that board decisions about cybersecurity spending are decidedly reflexive, with the primary drivers being fear of regulatory penalties or the costs of a repeat breach.










