Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

30551 bookmarks
Custom sorting
RSAC Fireside Chat: Enterprise browsers arise to align security with the modern flow of work
RSAC Fireside Chat: Enterprise browsers arise to align security with the modern flow of work
A quiet but consequential shift is underway in enterprise workspace security. The browser has effectively become the new operating system of business. Related: Gartner's enterprise browser review It didn’t happen all at once. But as SaaS took over, remote work went mainstream, and generative AI entered the picture, the browser quietly assumed a central role.
·lastwatchdog.com·
RSAC Fireside Chat: Enterprise browsers arise to align security with the modern flow of work
Securing CI/CD workflows with Wazuh
Securing CI/CD workflows with Wazuh
Wazuh detects container vulnerabilities, monitors CI/CD workflows, and automates incident response to prevent breaches.
·thehackernews.com·
Securing CI/CD workflows with Wazuh
Kettering Health hit by system-wide outage after ransomware attack
Kettering Health hit by system-wide outage after ransomware attack
Kettering Health, a healthcare network that operates 14 medical centers in Ohio, was forced to cancel inpatient and outpatient procedures following a cyberattack that caused a system-wide technology outage.
·bleepingcomputer.com·
Kettering Health hit by system-wide outage after ransomware attack
MCP: The Protocol Revolutionizing AI Integration | CSA
MCP: The Protocol Revolutionizing AI Integration | CSA
Model Context Protocol is a one-size-fits-all connector that bridges LLMs & the real-world. Learn how next-gen AI assistants are being wired to get things done.
·cloudsecurityalliance.org·
MCP: The Protocol Revolutionizing AI Integration | CSA
More AIs Are Taking Polls and Surveys - Schneier on Security
More AIs Are Taking Polls and Surveys - Schneier on Security
I already knew about the declining response rate for polls and surveys. The percentage of AI bots that respond to surveys is also increasing. Solutions are hard: 1. Make surveys less boring. We need to move past bland, grid-filled surveys and start designing experiences people actually want to complete. That means mobile-first layouts, shorter runtimes, and maybe even a dash of storytelling. TikTok or dating app style surveys wouldn’t be a bad idea or is that just me being too much Gen Z? 2. Bot detection. There’s a growing toolkit of ways to spot AI-generated responses—using things like response entropy, writing style patterns or even metadata like keystroke timing. Platforms should start integrating these detection tools more widely. Ideally, you introduce an element that only humans can do, e.g., you have to pick up your price somewhere in-person. Btw, note that these bots can easily be designed to find ways around the most common detection tactics such as Captcha’s, timed responses and postcode and IP recognition. Believe me, way less code than you suspect is needed to do this...
·schneier.com·
More AIs Are Taking Polls and Surveys - Schneier on Security
U.S. CISA adds Ivanti EPMM, MDaemon Email Server, Srimax Output Messenger, Zimbra Collaboration, and ZKTeco BioTime flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Ivanti EPMM, MDaemon Email Server, Srimax Output Messenger, Zimbra Collaboration, and ZKTeco BioTime flaws to its Known Exploited Vulnerabilities catalog
CISA adds Ivanti, MDaemon Email Server, Srimax Output Messenger, Zimbra, ZKTeco BioTime flaws to its Known Exploited Vulnerabilities catalog
·securityaffairs.com·
U.S. CISA adds Ivanti EPMM, MDaemon Email Server, Srimax Output Messenger, Zimbra Collaboration, and ZKTeco BioTime flaws to its Known Exploited Vulnerabilities catalog
M&S Braces for £300 Million Cyber-Attack Costs
M&S Braces for £300 Million Cyber-Attack Costs
An M&S trading update estimates the ongoing cyber-incident will cost £300m, largely from lost sales due to the suspension of online orders
·infosecurity-magazine.com·
M&S Braces for £300 Million Cyber-Attack Costs
Marks & Spencer faces $402 million profit hit after cyberattack
Marks & Spencer faces $402 million profit hit after cyberattack
British retailer giant Marks & Spencer (M&S) is bracing for a potential profit hit of up to £300 million £300 million ($402 million) following a recent cyberattack that led to widespread operational and sales disruptions.
·bleepingcomputer.com·
Marks & Spencer faces $402 million profit hit after cyberattack
Coinbase says recent data breach impacts 69,461 customers
Coinbase says recent data breach impacts 69,461 customers
Coinbase, a cryptocurrency exchange with over 100 million customers, revealed that a recent data breach in which cybercriminals stole customer and corporate data affected 69,461 individuals
·bleepingcomputer.com·
Coinbase says recent data breach impacts 69,461 customers
Convoluted layers: An artificial intelligence primer | Cyber.gov.au
Convoluted layers: An artificial intelligence primer | Cyber.gov.au
Rapid advances in artificial intelligence (AI), along with public releases of AI products, have prompted governments, businesses and criminals to accelerate efforts to incorporate this new technology into their operations. This advice provides definitions for some of the most commonly encountered AI terms in cybersecurity and a brief typology of cyberthreats that will arise from AI.
·cyber.gov.au·
Convoluted layers: An artificial intelligence primer | Cyber.gov.au
PowerSchool hacker pleads guilty to student data extortion scheme
PowerSchool hacker pleads guilty to student data extortion scheme
A 19-year-old college student from Worcester, Massachusetts, has agreed to plead guilty to a massive cyberattack on PowerSchool that extorted millions of dollars in exchange for not leaking the personal data of millions of students and teachers.
·bleepingcomputer.com·
PowerSchool hacker pleads guilty to student data extortion scheme
Security Framework for Small Cloud Providers | CSA
Security Framework for Small Cloud Providers | CSA
CSA’s Enterprise Authority to Operate (EATO) framework and auditing guidelines are specifically designed to fulfill stringent regulatory compliance.
·cloudsecurityalliance.org·
Security Framework for Small Cloud Providers | CSA
KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS
KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS
KrebsOnSecurity last week was hit by a near record distributed denial-of-service (DDoS) attack that clocked in at more than 6.3 terabits of data per second (a terabit is one trillion bits of data). The brief attack appears to have been…
·krebsonsecurity.com·
KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS