Veza lève 108 millions de dollars pour sa plateforme de gestion des identités
Soutenue par Snowflake et Atlassian, Veza développe une plateforme d'analyse des applications d'une société afin de déterminer quel utilisateur...-Cybersécurité
Cisco mêle sécurité et intelligence artificielle au sein d'une entité baptisée Foundation AI
Le lancement de Foundation AI a pour volonté de démocratiser la sécurité autour de l’IA grâce à une panoplie d'outils open source. Un premier...-IA générative
House passes legislation to criminalize nonconsensual deepfakes | CyberScoop
The Take It Down Act received rare levels of bipartisan support in the House and Senate, but critics fear enforcement could threaten First Amendment protections and unduly burden smaller companies and encrypted applications.
Microsoft fixes Outlook paste, blank calendar rendering issues
Microsoft has confirmed several issues affecting Microsoft 365 customers using the "paste special' option and the calendar feature in the classic Outlook email client.
RSAC Fireside Chat: Shift left, think forward — why MDR is emerging as cyber’s silver bullet
With RSAC kicking off next week, the conversation is shifting—literally. Cybersecurity pros are rethinking how “shift left” applies not just to code, but to enterprise risk. Related: Making sense of threat detection In this Fireside Chat, I spoke with John DiLullo, CEO of Deepwatch, who makes a compelling case for how Managed Detection and Response
Google: 97 zero-days exploited in 2024, over 50% in spyware attacks
Google's Threat Intelligence Group (GTIG) says attackers exploited 75 zero-day vulnerabilities in the wild last year, over 50% of which were linked to spyware attacks.
CISA tags Broadcom Fabric OS, CommVault flaws as exploited in attacks
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning of Broadcom Brocade Fabric OS, Commvault web servers, and Qualitia Active! Mail clients vulnerabilities that are actively exploited in attacks.
Digital rampage saw ex-Disney employee remove nut allergy info from menus, dox co-workers, and more
A former Disney employee has been sentenced to three years in prison for computer fraud and identity theft. He must also pay nearly US$688,000 in restitution.
Avec 5629 notifications, les violations de données ont augmenté de 20% en 2024, selon la Cnil
En 2024, la Commission nationale de l'informatique et des libertés a reçu 5629 notifications de violation de données personnelles. Un chiffre...-Cybersécurité
Palo Alto Networks rachète Protect AI pour mieux sécuriser l'intelligence artificielle
La firme américaine met la main sur Protect AI, une start-up spécialisée dans la sécurisation des applications et modèles d'IA. Les solutions...-Cybersécurité
De l'enrôlement à l'usage, Thales lance une offre dédiée à l'identité numérique
Fournisseur d'un tiers des documents d'identité sécurisés dans le monde, Thales ambitionne devenir le partenaire privilégié pour la gestion de...-Cybersécurité
Nova Scotia energy provider takes some servers offline following cyber incident
On Friday, Nova Scotia Power — which provides serves 95% of the power for the region — discovered a cyber incident involving unauthorized access to its systems.
A New Era for Compliance | Compliance Automation | CSA
The Compliance Automation Revolution is a CSA initiative to develop methods to automatically gather compliance evidence, harmonize frameworks, & quantify risk.
Applying Security Engineering to Prompt Injection Security - Schneier on Security
This seems like an important advance in LLM security against prompt injection: Google DeepMind has unveiled CaMeL (CApabilities for MachinE Learning), a new approach to stopping prompt-injection attacks that abandons the failed strategy of having AI models police themselves. Instead, CaMeL treats language models as fundamentally untrusted components within a secure software framework, creating clear boundaries between user commands and potentially malicious content. […] To understand CaMeL, you need to understand that prompt injections happen when AI systems can’t distinguish between legitimate user commands and malicious instructions hidden in content they’re processing...
2024 wasn't the year that AI rewrote the cybercrime playbook — but it did turbocharge some of the old tricks. Read this summary of AI-based threats, from Talos' 2024 Year in Review.