Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29738 bookmarks
Custom sorting
Privacy for Agentic AI - Schneier on Security
Privacy for Agentic AI - Schneier on Security
Sooner or later, it’s going to happen. AI systems will start acting as agents, doing things on our behalf with some degree of autonomy. I think it’s worth thinking about the security of that now, while its still a nascent idea. In 2019, I joined Inrupt, a company that is commercializing Tim Berners-Lee’s open protocol for distributed data ownership. We are working on a digital wallet that can make use of AI in this way. (We used to call it an “active wallet.” Now we’re calling it an “agentic wallet.”) I talked about this a bit at the RSA Conference...
·schneier.com·
Privacy for Agentic AI - Schneier on Security
Magento supply chain attack compromises hundreds of e-stores
Magento supply chain attack compromises hundreds of e-stores
A supply chain attack involving 21 backdoored Magento extensions has compromised between 500 and 1,000 e-commerce stores, including one belonging to a $40 billion multinational.
·bleepingcomputer.com·
Magento supply chain attack compromises hundreds of e-stores
Microsoft enterre les mots de passe pour les nouveaux comptes
Microsoft enterre les mots de passe pour les nouveaux comptes
Le premier jeudi du mois de mai est la journée mondiale du mot de passe. À cette occasion, Microsoft l'a célébrée d'une façon un peu particulière, avec une initiative visant à les tuer un peu plus. Chaque année, il y a la journée mondiale du mot de passe. Et tous les ans, elle tombe le premier jeudi du mois de mai --
·numerama.com·
Microsoft enterre les mots de passe pour les nouveaux comptes
Salesforce expands model lineup in support of agentic AI
Salesforce expands model lineup in support of agentic AI
The software vendor added variations to its family of large action models for on-device implementation, limited GPU resources and industrial applications.
·cybersecuritydive.com·
Salesforce expands model lineup in support of agentic AI
US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks
US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks
A 36-year-old Yemeni national, who is believed to be the developer and primary operator of 'Black Kingdom' ransomware, has been indicted by the United States for conducting 1,500 attacks on Microsoft Exchange servers.
·bleepingcomputer.com·
US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks
US wants to cut off key player in Southeast Asian cybercrime industry
US wants to cut off key player in Southeast Asian cybercrime industry
The Treasury Department issued the proposed rulemaking Thursday, stating that Huione Group has helped launder funds from North Korean state-backed cybercrime operations and investment scams originating in Southeast Asia.
·therecord.media·
US wants to cut off key player in Southeast Asian cybercrime industry
CISA Confirms Exploitation of SonicWall Vulnerabilities
CISA Confirms Exploitation of SonicWall Vulnerabilities
The US Cybersecurity and Infrastructure Security Agency has added two flaws affecting SonicWall products to its catalog of Known Exploited Vulnerabilities
·infosecurity-magazine.com·
CISA Confirms Exploitation of SonicWall Vulnerabilities
UK NCSC: Cyberattacks impacting UK retailers are a wake-up call
UK NCSC: Cyberattacks impacting UK retailers are a wake-up call
The United Kingdom's National Cyber Security Centre warned that ongoing cyberattacks impacting multiple UK retail chains should be taken as a "wake-up call."
·bleepingcomputer.com·
UK NCSC: Cyberattacks impacting UK retailers are a wake-up call
Using AI to Operationalize Zero Trust in Multi-Cloud | CSA
Using AI to Operationalize Zero Trust in Multi-Cloud | CSA
The ability of AI to handle enormous data volumes and identify irregularities in real-time enables it to fill the gap across disparate Zero Trust architectures.
·cloudsecurityalliance.org·
Using AI to Operationalize Zero Trust in Multi-Cloud | CSA
TikTok fined €530 million for sending European user data to China
TikTok fined €530 million for sending European user data to China
The Irish Data Protection Commission (DPC) has fined TikTok €530 million (over $601 million) for illegally transferring the personal data of users in the European Economic Area (EEA) to China, violating the European Union's GDPR data protection regulations.
·bleepingcomputer.com·
TikTok fined €530 million for sending European user data to China
Harrods becomes latest retailer to announce attempted cyberattack
Harrods becomes latest retailer to announce attempted cyberattack
London retailer Harrods said it had “recently experienced attempts to gain unauthorised access to some of our systems” but its security team "immediately took proactive steps to keep systems safe.”
·therecord.media·
Harrods becomes latest retailer to announce attempted cyberattack
NCSC Guidance on "Advanced Cryptography" - Schneier on Security
NCSC Guidance on "Advanced Cryptography" - Schneier on Security
The UK’s National Cyber Security Centre just released its white paper on “Advanced Cryptography,” which it defines as “cryptographic techniques for processing encrypted data, providing enhanced functionality over and above that provided by traditional cryptography.” It includes things like homomorphic encryption, attribute-based encryption, zero-knowledge proofs, and secure multiparty computation. It’s full of good advice. I especially appreciate this warning: When deciding whether to use Advanced Cryptography, start with a clear articulation of the problem, and use that to guide the development of an appropriate solution. That is, you should not start with an Advanced Cryptography technique, and then attempt to fit the functionality it provides to the problem. ...
·schneier.com·
NCSC Guidance on "Advanced Cryptography" - Schneier on Security
Balancing Ethics and AI in Business | CSA
Balancing Ethics and AI in Business | CSA
Explore how businesses can balance innovation with responsibility by adopting ethical AI practices that ensure fairness, transparency, and accountability.
·cloudsecurityalliance.org·
Balancing Ethics and AI in Business | CSA
Pour la journée des mots de passe, Microsoft leur fait un sale coup
Pour la journée des mots de passe, Microsoft leur fait un sale coup
Le premier jeudi du mois de mai est la journée mondiale du mot de passe. À cette occasion, Microsoft l'a célébrée d'une façon un peu particulière, avec une initiative visant à les tuer un peu plus. Chaque année, il y a la journée mondiale du mot de passe. Et tous les ans, elle tombe le premier jeudi du mois de mai --
·numerama.com·
Pour la journée des mots de passe, Microsoft leur fait un sale coup
Luxury department store Harrods suffered a cyberattack
Luxury department store Harrods suffered a cyberattack
Harrods confirmed a cyberattack, following similar incidents suffered by M&S and Co-op, making it the third major UK retailer hit in one week
·securityaffairs.com·
Luxury department store Harrods suffered a cyberattack