Mon.Aug 05, 2024

article thumbnail

Researchers warn of a new critical Apache OFBiz flaw

Security Affairs

Researchers urge organizations using Apache OFBiz to address a critical bug, following reports of active exploitation of another flaw. Experts urge organizations to address a new critical vulnerability, tracked as CVE-2024-38856, in Apache OFBiz. The vulnerability is an incorrect authorization issue in Apache OFBiz that impacts versions through 18.12.14, version 18.12.15 addressed the flaw. “Unauthenticated endpoints could allow execution of screen rendering code of screens if some precond

article thumbnail

CrowdStrike Rejects Delta's Negligence Claims Over IT Outage

Data Breach Today

Cybersecurity Firm Says Airline Rebuffed Help, Questions Its Incident Response CrowdStrike has dismissed claims of negligence leveled at it by Delta Air Lines, which is threatening to sue after a faulty security software update led to days of IT disruption. In response, the cybersecurity vendor is asking why Delta's competitors recovered so much more quickly.

IT 283
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

A flaw in Rockwell Automation ControlLogix 1756 could expose critical control systems to unauthorized access

Security Affairs

A security bypass bug in Rockwell Automation ControlLogix 1756 devices could allow unauthorized access to vulnerable devices. A high-severity security bypass vulnerability, tracked as CVE-2024-6242 (CVSS Base Score v4.0 of 7.3), impacts Rockwell Automation ControlLogix 1756 devices. An attacker can exploit the vulnerability to execute common industrial protocol (CIP) programming and configuration commands. “A vulnerability exists in the affected products that allows a threat actor to bypas

Access 314
article thumbnail

Low-Drama ‘Dark Angels’ Reap Record Ransoms

Krebs on Security

A ransomware group called Dark Angels made headlines this past week when it was revealed the crime group recently received a record $75 million data ransom payment from a Fortune 50 company. Security experts say the Dark Angels have been around since 2021, but the group doesn’t get much press because they work alone and maintain a low profile, picking one target at a time and favoring mass data theft over disrupting the victim’s operations.

article thumbnail

State of AI in Sales & Marketing 2025

AI adoption is reshaping sales and marketing. But is it delivering real results? We surveyed 1,000+ GTM professionals to find out. The data is clear: AI users report 47% higher productivity and an average of 12 hours saved per week. But leaders say mainstream AI tools still fall short on accuracy and business impact. Download the full report today to see how AI is being used — and where go-to-market professionals think there are gaps and opportunities.

article thumbnail

Apple finally starts paying off qualifying MacBook owners as part of a class action settlement

Collaboration 2.0

If you bought a MacBook with a faulty butterfly keyboard between 2015 and 2019 and filed a claim, the check should be in the mail.

244
244

More Trending

article thumbnail

The best fitness trackers you can buy: Expert tested and reviewed

Collaboration 2.0

We tested the best fitness trackers from Apple, Garmin, Fitbit, and others to help you track your health, sleep, and more.

190
190
article thumbnail

Zero-Day Vulnerability in Apache OFBiz Enables RCE

Data Breach Today

Flaws in Apache OFBiz Putting Critical Business Functions at Risk A zero-day pre-authentication vulnerability in Apache OFBiz is putting critical business functions at risk by enabling unauthorized remote code execution. The vulnerability's root cause lies in a flaw in OFBiz's authentication mechanism.

article thumbnail

Schools will remove app from students' Chromebooks and iPads following security breach

Collaboration 2.0

Device management app Mobile Guardian will be pulled from Chrome and iOS devices after 13,000 Singapore users had their data remotely wiped by a cyber attacker.

Security 190
article thumbnail

Chinese APT Group Using DNS Poisoning for Espionage

Data Breach Today

StormBamboo Targeting Automatic Software Update Systems to Deploy Malware A state hacking group that's been linked to Chinese cyberespionage infected an internet service provider to redirect software update connections to an attacker server that downloaded Macma malware, says Volexity. Google first spotted Macma in 2021.

162
162
article thumbnail

How to Achieve High-Accuracy Results When Using LLMs

Speaker: Ben Epstein, Stealth Founder & CTO | Tony Karrer, Founder & CTO, Aggregage

When tasked with building a fundamentally new product line with deeper insights than previously achievable for a high-value client, Ben Epstein and his team faced a significant challenge: how to harness LLMs to produce consistent, high-accuracy outputs at scale. In this new session, Ben will share how he and his team engineered a system (based on proven software engineering approaches) that employs reproducible test variations (via temperature 0 and fixed seeds), and enables non-LLM evaluation m

article thumbnail

The best VPN for Windows: Expert tested and reviewed

Collaboration 2.0

We tested the best VPNs for your Windows PC on everything from speed to server count to security. Here are some of the top VPNs for the Microsoft Windows operating system.

Security 190
article thumbnail

Stock Sell-Off: CISO Global, Trend Micro, Okta Hardest Hit

Data Breach Today

12 Security Stocks Fared Worse Than the Nasdaq Monday, While Just 10 Did Better Cybersecurity companies took Monday's sell-off on the chin, with CISO Global, Trend Micro and Okta experiencing significant stock price drops in Wall Street's worst day since 2022. The Nasdaq Composite Index fell nearly 3.5% Monday amid concerns about Friday's dismal jobs report.

article thumbnail

You can search Google Lens with your voice now. Here's how - and why it's so useful

Collaboration 2.0

Expanding your Google Lens searches just got a lot easier thanks to this new feature.

IT 189
article thumbnail

Rockwell Controller Flaw Exposes Industrial Control Systems

Data Breach Today

Claroty Says Attackers Could Use Security Flaw to Bypass Trusted Slot Feature A vulnerability in Rockwell Automation's ControlLogix 1756 devices allows attackers to bypass a critical security feature, turning the trusted slot mechanism into a hacker's secret passageway to jump between slots and gain access to industrial control systems.

Access 130
article thumbnail

The GTM Intelligence Era: ZoomInfo 2025 Customer Impact Report

ZoomInfo customers aren’t just selling — they’re winning. Revenue teams using our Go-To-Market Intelligence platform grew pipeline by 32%, increased deal sizes by 40%, and booked 55% more meetings. Download this report to see what 11,000+ customers say about our Go-To-Market Intelligence platform and how it impacts their bottom line. The data speaks for itself!

article thumbnail

Can AI even be open source? It's complicated

Collaboration 2.0

AI can't exist without open source, but the top AI vendors are unwilling to commit to open-sourcing their programs and data sets. To complicate matters further, defining open-source AI is a messy issue that has yet to be settled.

IT 189
article thumbnail

Attacks on Blood Suppliers Trigger Supply Chain Warning

Data Breach Today

Blood Shortage After Ransomware Attack Underscores Rising Threats to Patient Safety The American Hospital Association and Health Information Sharing and Analysis Center are urging the healthcare sector to step up its supply chain security and resilience as disruptive cyberattacks target critical suppliers, including last week's attack on a Florida-based blood donation center.

article thumbnail

This Samsung phone is the one most people should buy in 2024 (and it's not a flagship)

Collaboration 2.0

The Galaxy A35 5G has its flaws, but with a two-day battery life and gorgeous display, it's hard to ignore how good it is for the price.

IT 189
article thumbnail

How BlueVoyant's Cyber Defense Platform Reduces Cyber Risk

Data Breach Today

CEO Jim Rosenthal on the Perks of Combining Internal and External Security Measures BlueVoyant's Cyber Defense Platform combines proactive and reactive security measures with internal and external capabilities. CEO Jim Rosenthal explains how this comprehensive approach allows clients to manage cyber risks effectively and achieve a desired state of cyber defense readiness.

Risk 130
article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

The best portable power stations for camping in 2024: Expert tested and reviewed

Collaboration 2.0

We tested the best portable power stations for camping to power your most essential devices, whether you're tent camping or staying in an RV.

189
189
article thumbnail

New Patent Application for Car-to-Car Surveillance

Schneier on Security

Ford has a new patent application for a system where cars monitor each other’s speeds, and then report then to some central authority. Slashdot thread.

129
129
article thumbnail

The best VPN for gaming in 2024: Expert tested and reviewed

Collaboration 2.0

We tested the best gaming VPNs that offer easy-to-use apps, stable connectivity, and the speeds required to render games without lag.

189
189
article thumbnail

Brand Impersonation of Microsoft Increases 50% in One Quarter

KnowBe4

The use of the Microsoft brand in phishing attacks demonstrates both its widespread credibility as well as the continued success of attacks leveraging it.

Phishing 119
article thumbnail

5 Ways You Can Win Faster with Gen AI in Sales

Incorporating generative AI (gen AI) into your sales process can speed up your wins through improved efficiency, personalized customer interactions, and better informed decision- making. Gen AI is a game changer for busy salespeople and can reduce time-consuming tasks, such as customer research, note-taking, and writing emails, and provide insightful data analysis and recommendations.

article thumbnail

The best outdoor TVs of 2024: Expert recommended

Collaboration 2.0

The best outdoor TVs can upgrade your deck or backyard with great picture and streaming features while protecting your electronics from the elements.

189
189
article thumbnail

Creating a Big Security Culture With a Tiny Button

KnowBe4

When it comes to creating a strong cybersecurity culture, one of the most powerful tools we have at our disposal is the Phish Alert Button (PAB).

Phishing 115
article thumbnail

Will OpenAI's new AI detection tool put an end to student cheating?

Collaboration 2.0

OpenAI claims its new method can identify - with 99.9% accuracy - when someone uses ChatGPT to write an essay or research paper. Here's why I'm skeptical.

Paper 189
article thumbnail

4 steps to grow a data governance program

Collibra

As more organizations are dealing with higher volumes and varieties of data, they are encountering more data-related problems. Whether it’s managing data quality, installing cybersecurity measures, or simply budgeting for the high cost of processing and storing enormous amounts of information, enterprises face growing challenges to enable data access and usage.

article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

iPad Air (2024) review: Apple's M2 tablet is the iPad most people should buy

Collaboration 2.0

The new iPad Air may be an iterative upgrade on paper, but several features make it still the tablet most people should buy.

Paper 189
article thumbnail

CILIP statement on the fire damage at Spellow Hub Library in Liverpool

CILIP

CILIP statement on the fire damage at Spellow Hub Library in Liverpool Spellow Hub library is located in Liverpool, and was transformed into a 'library of the future' in 2023. CILIP expresses solidarity with the library staff and users of Spellow Hub Library that was severely damaged during scenes of violent disorder on Saturday 3 August 2024. This public library opened in Spring 2023 as a fully accessible 'library of the future', offering a free “education to employment” service for people of a

article thumbnail

The Arlo Pro 5S is so close to being my perfect security camera. Here's why

Collaboration 2.0

The Arlo Pro 5S 2K captures outdoor movement almost instantly, but brand-exclusive features make it hard to recommend to everyone.

Security 189