Tue.Jun 11, 2024

article thumbnail

Patch Tuesday, June 2024 “Recall” Edition

Krebs on Security

Microsoft today released updates to fix more than 50 security vulnerabilities in Windows and related software, a relatively light Patch Tuesday this month for Windows users. The software giant also responded to a torrent of negative feedback on a new feature of Redmond’s flagship operating system that constantly takes screenshots of whatever users are doing on their computers, saying the feature would no longer be enabled by default.

Mining 238
article thumbnail

AI Will Soon Exhaust the Internet. What's Next?

Data Breach Today

Researchers Expect an AI Training Data Drought in the Next 2 to 8 Years Artificial intelligence models consume training data faster than humans can produce it, and large language model researchers warn that the stocks of public text data are set to be exhausted as early as two years from now. They also say that bottlenecks aren't inevitable.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

RSAC Fireside Chat: Ontinue ups the ‘MXDR’ ante — by emphasizing wider automation, collaboration

The Last Watchdog

Companies that need to protect assets spread across hybrid cloud infrastructure face a huge challenge trying to mix and match disparate security tools. Related: Cyber help for hire Why not seek help from a specialist? At RSAC 2024 , I visited with Geoff Haydon , CEO, and Alex Berger , Head of Product Marketing, at Ontinue , a new player in the nascent Managed Extended Detection and Response ( MXDR ) space.

Marketing 130
article thumbnail

UK Sides With APP Fraud Victims - Despite Industry Pressure

Data Breach Today

Payments Regulator Says Banks Should Prioritize Customer Protection Over Losses The U.K. Payments Systems Regulator has denied The Payment Association's request to delay the contentious APP fraud reimbursement plan by a year. The association, the largest community in payments, had warned that failing to delay the plan would permanently damage the payments industry.

261
261
article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

Arm zero-day in Mali GPU Drivers actively exploited in the wild

Security Affairs

Semiconductor and software design company Arm warns of an actively exploited zero-day vulnerability in Mali GPU Kernel Driver. Arm is warning of an actively exploited zero-day vulnerability, tracked as CVE-2024-4610, in Mali GPU Kernel Driver. The vulnerability is a use-after-free issue issue that impacts Bifrost GPU Kernel Driver (all versions from r34p0 to r40p0) and Valhall GPU Kernel Driver (all versions from r34p0 to r40p0). “A local non-privileged user can make improper GPU memory pr

Access 134

More Trending

article thumbnail

LLMs Acting Deceptively

Schneier on Security

New research: “ Deception abilities emerged in large language models “: Abstract: Large language models (LLMs) are currently at the forefront of intertwining AI systems with human communication and everyday life. Thus, aligning them with human values is of great importance. However, given the steady increase in reasoning abilities, future LLMs are under suspicion of becoming able to deceive human operators and utilizing this ability to bypass monitoring efforts.

article thumbnail

Dutch Agency Renews Warning of Chinese Fortigate Campaign

Data Breach Today

Chinese Cyber Espionage Campiagn Is 'Much Larger Than Previously Known' Chinese hackers breached thousands of vulnerable Fortigate network security appliances in a cyber-espionage campaign "much larger than previously known," a Dutch cybersecurity agency warned Tuesday. Even fully patched FortiGate devices may still be infected.

article thumbnail

Sinister "More_eggs" Malware Cracks Into Companies by Targeting Hiring Managers

KnowBe4

Job seekers, beware - cybercriminals have a nasty new way to slide their malicious code on corporate networks. Researchers have uncovered a devious phishing campaign that's distributing the powerful More_eggs backdoor by disguising it as resume submissions for open roles.

Phishing 117
article thumbnail

Protecting the data of our commercial and public sector customers in the AI era

Data Breach Today

Empowering Industries with Secure AI Solutions for Enhanced Growth and Productivity How are multiple industries leveraging Microsoft Azure OpenAI and Copilot to drive growth and ensure robust data security?

Security 182
article thumbnail

15 Modern Use Cases for Enterprise Business Intelligence

Large enterprises face unique challenges in optimizing their Business Intelligence (BI) output due to the sheer scale and complexity of their operations. Unlike smaller organizations, where basic BI features and simple dashboards might suffice, enterprises must manage vast amounts of data from diverse sources. What are the top modern BI use cases for enterprise businesses to help you get a leg up on the competition?

article thumbnail

Microsoft Patch Tuesday security updates for June 2024 fixed only one critical issue

Security Affairs

Microsoft Patch Tuesday security updates for June 2024 addressed 49 vulnerabilities, only one of them is a publicly disclosed zero-day flaw. Microsoft Patch Tuesday security updates for June 2024 addressed 49 vulnerabilities in Windows and Windows Components; Office and Office Components; Azure; Dynamics Business Central; and Visual Studio. Eight of these bugs were reported through the ZDI program.

Security 124
article thumbnail

Cyberhaven Secures $88M to Strengthen Data Security Platform

Data Breach Today

Adams Street Partners, Khosla Ventures Lead Series C Funding for Data Security Firm Cyberhaven secured $88 million in a Series C round led by Adams Street Partners and Khosla Ventures. The company wants to bolster product development, expand AI detection capabilities and increase market reach in hope of becoming a leader in the fragmented data security market.

Security 173
article thumbnail

Expert released PoC exploit code for Veeam Backup Enterprise Manager flaw CVE-2024-29849. Patch it now!

Security Affairs

A proof-of-concept (PoC) exploit code for a Veeam Backup Enterprise Manager authentication bypass flaw CVE-2024-29849 is publicly available. Researcher Sina Kheirkha analyzed the Veeam Backup Enterprise Manager authentication bypass flaw CVE-2024-29849 and a proof of concept exploit for this issue. The flaw CVE-2024-29849 is a critical vulnerability (CVSS score: 9.8) in Veeam Backup Enterprise Manager that could allow attackers to bypass authentication.

article thumbnail

Cleveland Cyber Incident Prompts Shutdown of City IT Systems

Data Breach Today

Cleveland Investigating Cyber Incident that Forced City to Shutdown IT Systems The city of Cleveland, Ohio is launching an investigation into an apparent cyber event that forced a shutdown of its information technology systems throughout the start of the week, officials said Tuesday, though additional details surrounding the incident remain unclear.

IT 173
article thumbnail

The Cloud Development Environment Adoption Report

Cloud Development Environments (CDEs) are changing how software teams work by moving development to the cloud. Our Cloud Development Environment Adoption Report gathers insights from 223 developers and business leaders, uncovering key trends in CDE adoption. With 66% of large organizations already using CDEs, these platforms are quickly becoming essential to modern development practices.

article thumbnail

Beware: Major AI Chatbots Now Intentionally Spreading Election Disinformation

KnowBe4

Just when you thought the disinformation landscape couldn't get any worse, an alarming new report from Democracy Reporting International reveals that popular AI chatbots have started intentionally spreading false information related to elections and the voting process.

article thumbnail

Chinese-Made Biometric Access System Has 24 Vulnerabilities

Data Breach Today

Kaspersky Unveils 24 Flaws in ZKTeco Terminals A promise of better security through biometrics fell short after security researchers dismantled an access system manufactured by a Chinese manufacture, only to discover 24 vulnerabilities contained inside. ZKTeco specializes in hybrid biometric verification technology.

Access 173
article thumbnail

Bruce Schneier: "AI Will Increase the Quantity—and Quality—of Phishing Scams"

KnowBe4

Wow. It does not happen often that the godfather of infosec comes out this strong about phishing risks. He co-published new research in the Harvard Business Review May 30, 2024, which in turn links back to the actual study that was published at the IEEE. This is the best budget ammo I have seen in the last few years.

article thumbnail

Nationwide Building Society gives member communications the personal touch 

OpenText Information Management

Nationwide isn’t like most other financial services organisations. Because we’re owned by our millions of members across the UK, we can invest everything back into the business. Our mission is to provide outstanding services that make life better for our members—and our product offering includes personal banking, credit cards, mortgages, and more. As the CIO for customer experience platforms, I’m responsible for everything relating to customer communications—from account statements to the latest

article thumbnail

The Tumultuous IT Landscape Is Making Hiring More Difficult

After a year of sporadic hiring and uncertain investment areas, tech leaders are scrambling to figure out what’s next. This whitepaper reveals how tech leaders are hiring and investing for the future. Download today to learn more!

article thumbnail

New HR-Themed Credential Harvesting Phishing Attack Uses Legitimate Signature Platform Yousign

KnowBe4

Analysis of this latest phishing campaign exposes exactly how the digital signature platform is misused to create a simple and easily avoidable.

article thumbnail

Approaches to migrating your VMware workloads to AWS   

IBM Big Data Hub

The VMware® acquisition by Broadcom has changed VMware’s product and partner strategies. In November 2023, Broadcom finalized its acquisition (link resides outside ibm.com) of VMware for USD 69 billion, with an aim to enhance its multicloud strategy. Further to the acquisition, Broadcom decided to discontinue (link resides outside ibm.com) its AWS authorization to resell VMware Cloud on AWS as of 30 April 2024.

Cloud 66
article thumbnail

DarkGate Malware Being Spread Via Excel Docs Attached To Phishing Emails

KnowBe4

A phishing campaign is spreading the DarkGate malware using new techniques to evade security filters, according to researchers at Cisco Talos.

article thumbnail

The best AirTag wallets of 2024: Expert tested

Collaboration 2.0

Lose your wallet often? ZDNET went hands-on with the best Apple AirTag wallets and accessories to help you keep track of your cards and cash.

75
article thumbnail

Introducing CDEs to Your Enterprise

Explore how enterprises can enhance developer productivity and onboarding by adopting self-hosted Cloud Development Environments (CDEs). This whitepaper highlights the simplicity and flexibility of cloud-based development over traditional setups, demonstrating how large teams can leverage economies of scale to boost efficiency and developer satisfaction.

article thumbnail

Unlocking AI/ML Success with Trusted, Unified Data

Reltio

Imagine a skilled chef trying to cook a gourmet meal with rotten ingredients; the dish won’t turn out great. Similarly, for businesses using any AI, including machine learning and gen AI, to make decisions or automate processes, data quality is as crucial as the technology itself. Like a meal prepared with subpar ingredients, AI solutions won’t deliver the desired results when fueled with bad data, and those investments won’t pay off.

article thumbnail

The best security keys of 2024: Expert tested

Collaboration 2.0

We tested the best security keys that combine safety and convenience to keep your online accounts safe from hackers and phishing attacks.

article thumbnail

Celebrating Collibra: 2024 Databricks Governance Partner of the Year

Collibra

We’re thrilled to announce that Collibra has been recognized as the 2024 Databricks Data Governance Partner of the Year. This prestigious award is a testament to our unwavering commitment to excellence in data and AI governance. Join us as we celebrate this achievement and explore the transformative power of our partnership with Databricks. The time is now to do more with trusted data There has never been a more critical moment to invest your time into understanding how to do more with data, and

article thumbnail

CyberheistNews Vol 14 #24 [NEW 2024 RESEARCH] Reveals that 34% of Green Users Will Fail a Phishing Test

KnowBe4

[NEW 2024 RESEARCH] Reveals that 34% of Green Users Will Fail a Phishing Test

article thumbnail

Improving the Accuracy of Generative AI Systems: A Structured Approach

Speaker: Anindo Banerjea, CTO at Civio & Tony Karrer, CTO at Aggregage

When developing a Gen AI application, one of the most significant challenges is improving accuracy. This can be especially difficult when working with a large data corpus, and as the complexity of the task increases. The number of use cases/corner cases that the system is expected to handle essentially explodes. 💥 Anindo Banerjea is here to showcase his significant experience building AI/ML SaaS applications as he walks us through the current problems his company, Civio, is solving.

article thumbnail

Tech partner spotlight: Jamf + 1GLOBAL

Jamf

Learn how integrating Jamf with 1GLOBAL mitigates security risks while automating eSIM deployment.

Risk 40
article thumbnail

Privacy Regulators Probe Impact of 23andMe's Mega-Breach

Data Breach Today

6.9 Million Individuals' Genetic Details Stolen via 2023 Credential-Stuffing Attack Privacy regulators in the U.K. and Canada have launched a joint investigation into 23andMe following the direct-to-consumer genetic testing service suffering a massive data breach in October 2023 that led to the theft of 6.9 million individuals' ancestry details.

Privacy 189
article thumbnail

Genetic testing company 23andMe investigated over hack that hit 7m users

The Guardian Data Protection

Data watchdogs in UK and Canada to look at whether there were enough safeguards on personal information Business live – latest updates The California genetic testing company 23andMe faces investigations by the data watchdogs of the UK and Canada over a security breach affecting nearly 7 million people last October. Hackers who broke into the site gained access to personal information by using customers’ old passwords.