Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29841 bookmarks
Custom sorting
GUEST ESSAY: Ponemon study warns: AI-enhanced deepfake attacks taking aim at senior execs
GUEST ESSAY: Ponemon study warns: AI-enhanced deepfake attacks taking aim at senior execs
A new study by the Ponemon Institute points to a concerning use of AI: deepfake attacks are on the rise and are taking a financial and reputational toll on companies and their executives. Related: Tools to fight deepfakes Deepfake Deception: How AI Harms the Fortunes and Reputations of Executives and Corporations details the results of a
·lastwatchdog.com·
GUEST ESSAY: Ponemon study warns: AI-enhanced deepfake attacks taking aim at senior execs
All Gmail users at risk from clever replay attack
All Gmail users at risk from clever replay attack
All Google accounts could end up compromised by a clever replay attack on Gmail users abusing Google infrastructure.
·malwarebytes.com·
All Gmail users at risk from clever replay attack
Prioritizing Care when Facing Cyber Risks | CSA
Prioritizing Care when Facing Cyber Risks | CSA
​Explore how healthcare organizations can safeguard patient care by addressing cyber risks through modernization and resilient security strategies.
·cloudsecurityalliance.org·
Prioritizing Care when Facing Cyber Risks | CSA
AI and Privacy: Shifting from 2024 to 2025 | CSA
AI and Privacy: Shifting from 2024 to 2025 | CSA
Explore how AI and data privacy are reshaping global business, driving innovation, and demanding agile, ethical governance across industries.
·cloudsecurityalliance.org·
AI and Privacy: Shifting from 2024 to 2025 | CSA
C’est quoi le Slopsquatting, la nouvelle menace sur Internet à cause des IA ?
C’est quoi le Slopsquatting, la nouvelle menace sur Internet à cause des IA ?
L'émergence de l'intelligence artificielle générative s'accompagne d'un nouveau type de risque informatique : le Slopsquatting. Il s'agit d'une manipulation construite grâce aux hallucinations d'une IA, qui permet à une personne malveillante d'injecter du code corrompu dans des logiciels. Ce n'est un secret pour
·numerama.com·
C’est quoi le Slopsquatting, la nouvelle menace sur Internet à cause des IA ?
Whistleblower: DOGE Siphoned NLRB Case Data
Whistleblower: DOGE Siphoned NLRB Case Data
A security architect with the National Labor Relations Board (NLRB) alleges that employees from Elon Musk's Department of Government Efficiency (DOGE) transferred gigabytes of sensitive data from agency case files in early March, using short-lived accounts configured to leave few…
·krebsonsecurity.com·
Whistleblower: DOGE Siphoned NLRB Case Data
Researchers warn of critical flaw found in Erlang OTP SSH
Researchers warn of critical flaw found in Erlang OTP SSH
The CVE could allow unauthenticated attackers to gain full access to a device. Many of these devices are widely used in IoT and telecom platforms.
·cybersecuritydive.com·
Researchers warn of critical flaw found in Erlang OTP SSH
Researchers warn of critical flaw found in Erlang OTP SSH
Researchers warn of critical flaw found in Erlang OTP SSH
The CVE could allow unauthenticated attackers to gain full access to a device. Many of these devices are widely used in IoT and telecom platforms.
·cybersecuritydive.com·
Researchers warn of critical flaw found in Erlang OTP SSH
Securing our future: April 2025 progress report on Microsoft’s Secure Future Initiative
Securing our future: April 2025 progress report on Microsoft’s Secure Future Initiative
The Microsoft Secure Future Initiative (SFI) stands as the largest cybersecurity engineering project in history and most extensive effort of its kind at Microsoft. Now, we are sharing the second SFI progress report, which highlights progress made in our multi-year journey to improve the security posture of Microsoft, our customers, and the industry at large.
·microsoft.com·
Securing our future: April 2025 progress report on Microsoft’s Secure Future Initiative
Microsoft Entra account lockouts caused by user token logging mishap
Microsoft Entra account lockouts caused by user token logging mishap
Microsoft confirms that the weekend Entra account lockouts were caused by the invalidation of short-lived user refresh tokens that were mistakenly logged into internal systems.
·bleepingcomputer.com·
Microsoft Entra account lockouts caused by user token logging mishap