Guardicore discovered that the Microsoft Exchange server’s Autodiscover feature design flaw leaked credentials of 100,000 users by trying to authenticate on untrusted third-party servers.
A new executive order from the Biden administration addresses a wide range of the potential harms that AI can cause, putting new safeguards in place for everything from biological materials engineering to deepfakes.
Digital Services Act would bring new restrictions on how targeted advertising can use sensitive personal information and a requirement that the inner workings of recommender algorithms be visible to the public.
Australian Clinical Labs reportedly detected the attack not long after it occurred and was contacted by government authorities in March, and were also notified in June that some of the patient data had been found available for sale on the dark web.
CISA and the "Five Eyes" national intelligence agencies have issued their annual advisory on the top exploited vulnerabilities for the prior year, and its findings bolster some other recent reports that a successful attack is becoming increasingly likely to be the result of a zero-day.
Verizon Visible experienced an attack recently that saw customer accounts taken over and orders placed using stored payment information. Verizon has verified that the hacked accounts were compromised by a credential stuffing campaign.
Zelle fraud has become rampant, and attacks frequently begin with a fake notification of a suspicious transaction that appears to be coming from the bank itself.
GRU-affiliated Russian hackers targeted 20 Ukrainian critical infrastructure facilities in March 2024, Ukraine’s Computer Emergency Response Team (CERT-UA) has disclosed.
Cit0Day leaked more than 23,000 hacked databases containing over 13 billion records. The data was shared on the MEGA file hosting site, Telegram channels, and underground hacking forums.
Italy’s data protection authority has ruled that Google's data transfers to servers in the United States fall afoul of the rules of the GDPR, with the company not anonymizing IP addresses sufficiently.










