Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31474 bookmarks
Custom sorting
Applying Security Engineering to Prompt Injection Security - Schneier on Security
Applying Security Engineering to Prompt Injection Security - Schneier on Security
This seems like an important advance in LLM security against prompt injection: Google DeepMind has unveiled CaMeL (CApabilities for MachinE Learning), a new approach to stopping prompt-injection attacks that abandons the failed strategy of having AI models police themselves. Instead, CaMeL treats language models as fundamentally untrusted components within a secure software framework, creating clear boundaries between user commands and potentially malicious content. […] To understand CaMeL, you need to understand that prompt injections happen when AI systems can’t distinguish between legitimate user commands and malicious instructions hidden in content they’re processing...
·schneier.com·
Applying Security Engineering to Prompt Injection Security - Schneier on Security
Year in Review: AI based threats
Year in Review: AI based threats
2024 wasn't the year that AI rewrote the cybercrime playbook — but it did turbocharge some of the old tricks. Read this summary of AI-based threats, from Talos' 2024 Year in Review.
·blog.talosintelligence.com·
Year in Review: AI based threats
When to Hire a GDPR Auditor | CSA
When to Hire a GDPR Auditor | CSA
Discover when to engage a GDPR auditor and how platforms streamline compliance with automated tools and expert support.
·cloudsecurityalliance.org·
When to Hire a GDPR Auditor | CSA
Europol Creates “Violence-as-a-Service” Taskforce
Europol Creates “Violence-as-a-Service” Taskforce
Europol has launched a new initiative designed to combat recruitment of youngsters into violent organized crime groups
·infosecurity-magazine.com·
Europol Creates “Violence-as-a-Service” Taskforce
News alert: Case dismissed against VPN executive, affirms no-logs policy as a valid legal defense
News alert: Case dismissed against VPN executive, affirms no-logs policy as a valid legal defense
Toronto, Canada, Apr. 28, 2025, CyberNewswire -- Windscribe, a globally used privacy-first VPN service, announced today that its founder, Yegor Sak, has been fully acquitted by a court in Athens, Greece, following a two-year legal battle in which Sak was personally charged in connection with an alleged internet offence by an unknown user of the
·lastwatchdog.com·
News alert: Case dismissed against VPN executive, affirms no-logs policy as a valid legal defense
Marks & Spencer breach linked to Scattered Spider ransomware attack
Marks & Spencer breach linked to Scattered Spider ransomware attack
Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted by a hacking collective known as "Scattered Spider" BleepingComputer has learned from multiple sources.
·bleepingcomputer.com·
Marks & Spencer breach linked to Scattered Spider ransomware attack
Hitachi Vantara takes servers offline after Akira ransomware attack
Hitachi Vantara takes servers offline after Akira ransomware attack
Hitachi Vantara, a subsidiary of Japanese multinational conglomerate Hitachi, was forced to take servers offline over the weekend to contain an Akira ransomware attack.
·bleepingcomputer.com·
Hitachi Vantara takes servers offline after Akira ransomware attack
Windscribe Acquitted on Charges of Not Collecting Users' Data - Schneier on Security
Windscribe Acquitted on Charges of Not Collecting Users' Data - Schneier on Security
The company doesn’t keep logs, so couldn’t turn over data: Windscribe, a globally used privacy-first VPN service, announced today that its founder, Yegor Sak, has been fully acquitted by a court in Athens, Greece, following a two-year legal battle in which Sak was personally charged in connection with an alleged internet offence by an unknown user of the service. The case centred around a Windscribe-owned server in Finland that was allegedly used to breach a system in Greece. Greek authorities, in cooperation with INTERPOL, traced the IP address to Windscribe’s infrastructure and, unlike standard international procedures, proceeded to initiate criminal proceedings against Sak himself, rather than pursuing information through standard corporate channels...
·schneier.com·
Windscribe Acquitted on Charges of Not Collecting Users' Data - Schneier on Security
Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw
Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw
Over 1,200 internet-exposed SAP NetWeaver instances are vulnerable to an actively exploited maximum severity unauthenticated file upload vulnerability that allows attackers to hijack servers.
·bleepingcomputer.com·
Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw