The AI hacking apocalypse is not inevitable
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy cho...
20 articles
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy cho...
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-gen...
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those ...
Cyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on...
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran. The post Cyberattacks on Two ...
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.
OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searche...
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere...
An offensive strategy can put private companies at risk -- that's why businesses will need closer relationships with the FBI.
ESET said FamousSparrow has replaced SparrowDoor with SparroWocky
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hacke...
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vuln...
Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia.
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based ...
Security researchers at ADEX have documented a cloaking technique that requires no cloaking code at all. Instead of running user-agent detection on attacker-...
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity securi...
CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks