Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31743 bookmarks
Custom sorting
The AI Trustworthy Pledge Matters Now More Than Ever | CSA
The AI Trustworthy Pledge Matters Now More Than Ever | CSA
CSA’s AI Trustworthy Pledge is a commitment that signals an organization's dedication to four foundational principles that should underpin every AI initiative.
·cloudsecurityalliance.org·
The AI Trustworthy Pledge Matters Now More Than Ever | CSA
GitLab patches high severity account takeover, missing auth issues
GitLab patches high severity account takeover, missing auth issues
GitLab has released security updates to address multiple vulnerabilities in the company's DevSecOps platform, including ones enabling attackers to take over accounts and inject malicious jobs in future pipelines.
·bleepingcomputer.com·
GitLab patches high severity account takeover, missing auth issues
DNS Posture Management: Close DNS Security Gaps | CSA
DNS Posture Management: Close DNS Security Gaps | CSA
Secure enterprise DNS with posture management: gain visibility, detect phishing domains, plus certificate and PQC monitoring.
·cloudsecurityalliance.org·
DNS Posture Management: Close DNS Security Gaps | CSA
SHARED INTEL Q&A: A sharper lens on rising API logic abuse — and a framework to fight back
SHARED INTEL Q&A: A sharper lens on rising API logic abuse — and a framework to fight back
In today’s digital enterprise, API-driven infrastructure is the connective tissue holding everything together. Related: The DocuSign API-abuse hack From mobile apps to backend workflows, APIs are what keep digital services talking—and scaling. But this essential layer of connectivity is also where attackers are gaining traction, often quietly and with alarming precision. Jamison Utter, a cybersecurity
·lastwatchdog.com·
SHARED INTEL Q&A: A sharper lens on rising API logic abuse — and a framework to fight back
NIST Publishes New Zero Trust Implementation Guidance
NIST Publishes New Zero Trust Implementation Guidance
The new NIST guidance sets out 19 example implementations of zero trust using commercial, off-the-shelf technologies
·infosecurity-magazine.com·
NIST Publishes New Zero Trust Implementation Guidance
Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
Microsoft has released an emergency Windows 11 24H2 update to address an incompatibility issue triggering restarts with blue screen of death (BSOD) errors on systems with Easy Anti-Cheat.
·bleepingcomputer.com·
Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
Montres connectées et ultrasons : le danger invisible qui menace même les ordinateurs les plus protégés
Montres connectées et ultrasons : le danger invisible qui menace même les ordinateurs les plus protégés
Des chercheurs israéliens ont prouvé que les montres connectées, objets du quotidien, peuvent servir à dérober des données sensibles depuis des ordinateurs pourtant totalement coupés d’Internet. Leur méthode, baptisée SmartAttack, repose sur la transmission de données par ultrasons et révèle une faille insoupçonnée
·numerama.com·
Montres connectées et ultrasons : le danger invisible qui menace même les ordinateurs les plus protégés
En passant par Amazon, il est possible d’acheter des VPN en promotion
En passant par Amazon, il est possible d’acheter des VPN en promotion
Vous ne le savez peut-être pas, mais Amazon vend des abonnements VPN, dont ceux du leader sur le marché. NordVPN ou Surfshark proposent plusieurs offres, avec parfois quelques promotions. Les VPN sont de plus en plus utilisés pour surfer sur Internet l'esprit tranquille, et ce, sur la plupart de vos appareils
·numerama.com·
En passant par Amazon, il est possible d’acheter des VPN en promotion
Digital rights groups sound alarm on Stop CSAM Act | CyberScoop
Digital rights groups sound alarm on Stop CSAM Act | CyberScoop
The organizations say a reintroduced version of the bill would “break” encryption for most Americans and make it impossible for end-to-end encrypted service providers to avoid lawsuits.
·cyberscoop.com·
Digital rights groups sound alarm on Stop CSAM Act | CyberScoop
Erie Insurance confirms cyberattack behind business disruptions
Erie Insurance confirms cyberattack behind business disruptions
Erie Insurance and Erie Indemnity Company have disclosed that a weekend cyberattack is behind the recent business disruptions and platform outages on its website.
·bleepingcomputer.com·
Erie Insurance confirms cyberattack behind business disruptions