4chan détaille les coulisses du plus grand piratage de son histoire
Le sulfureux site 4chan est de retour sur le web, deux semaines après une panne causée par une cyberattaque. La plateforme a expliqué les causes de son indisponibilité et détaillé les mesures prises pour ne plus se faire avoir à l'avenir. La « poubelle du web », comme est parfois surnommé 4chan, est de retour. Quasi
MY TAKE: As RSAC 2025 opens, Microsoft, Amazon make GenAI grab — will control tighten?
SAN FRANCISCO — RSAC 2025 kicks off today at Moscone Center, with more than 40,000 cybersecurity pros, tech executives, and policy leaders gathering to chart the future of digital risk management. Related: RSAC 2025's full agenda One dominant undercurrent is already clear: GenAI isn’t coming. It’s here — embedded in enterprise security architectures, compliance tools,
Key Takeaways An open directory associated with a ransomware affiliate, likely linked to the Fog ransomware group, was discovered in December 2024. It contained tools and scripts for reconnaissance…
WooCommerce admins targeted by fake security patches that hijack sites
A large-scale phishing campaign targets WooCommerce users with a fake security alert urging them to download a "critical patch" that adds a Wordpress backdoor to the site.
Brave's Cookiecrumbler tool taps community to help block cookie notices
Brave has open-sourceed a new tool called "Cookiecrumbler," which uses large language models (LLMs) to detect cookie consent notices and then community-driven reviews to block those that won't break site functionality.
MY TAKE: Notes on how GenAI is shifting tension lines in cybersecurity on the eve of RSAC 2025
SAN FRANCISCO -- The first rule of reporting is to follow the tension lines—the places where old assumptions no longer quite hold. Related: GenAI disrupting tech jobs I’ve been feeling that tension lately. Just arrived in the City by the Bay. Trekked here with some 40,000-plus cyber security pros and company execs flocking to RSAC
What Is the New Trusted AI Safety Knowledge Certification? | CSA
CSA and Northeastern University’s Trusted AI Safety Knowledge Certification Program trains professionals to build, secure, and manage AI responsibly across its lifecycle.
Friday Squid Blogging: Squid Facts on Your Phone - Schneier on Security
Text “SQUID” to 1-833-SCI-TEXT for daily squid facts. The website has merch. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Windows 11 KB5055627 update released with 30 new changes, fixes
Microsoft has released the KB5055627 preview cumulative update for Windows 11 24H2 with many new features gradually rolling out, and some new bug fixes for everyone.
Craft CMS RCE exploit chain used in zero-day attacks to steal data
Two vulnerabilities impacting Craft CMS were chained together in zero-day attacks to breach servers and steal data, with exploitation ongoing, according to CERT Orange Cyberdefense.