Fri.Aug 23, 2024

article thumbnail

Qilin ransomware steals credentials stored in Google Chrome

Security Affairs

Sophos researchers investigated a Qilin ransomware breach attack that led to the theft of credentials stored in Google Chrome browsers. Sophos researchers investigated a Qilin ransomware attack where operators stole credentials stored in Google Chrome browsers of a limited number of compromised endpoints. The experts pointed out that the credential harvesting activity is usually not associated with ransomware infections.

article thumbnail

Local Networks Go Global When Domain Names Collide

Krebs on Security

The proliferation of new top-level domains (TLDs) has exacerbated a well-known security weakness: Many organizations set up their internal Microsoft authentication systems years ago using domain names in TLDs that didn’t exist at the time. Meaning, they are continuously sending their Windows usernames and passwords to domain names they do not control and which are freely available for anyone to register.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Phishing attacks target mobile users via progressive web applications (PWA)

Security Affairs

Cybercriminals use progressive web applications (PWA) to impersonate banking apps and steal credentials from mobile users. ESET researchers detailed a phishing campaign against mobile users that uses Progressive Web Applications (PWAs). The threat actors used fake apps almost indistinguishable from real banking apps on both iOS and Android. The technique was first disclosed in Poland in July 2023 and later observed in Czechia and other countries like Hungary and Georgia.

Phishing 328
article thumbnail

Is AI Making Banking Safer or Just More Complicated?

Data Breach Today

As Banks Combat Fraud, Customers Feel the Strain of Overly Cautious Measures In today’s AI-driven world, banks are becoming increasingly vigilant, often freezing accounts or demanding extensive documentation at the slightest hint of suspicious activity. Sending money, once a straightforward task, is now fraught with complexity.

296
296
article thumbnail

State of AI in Sales & Marketing 2025

AI adoption is reshaping sales and marketing. But is it delivering real results? We surveyed 1,000+ GTM professionals to find out. The data is clear: AI users report 47% higher productivity and an average of 12 hours saved per week. But leaders say mainstream AI tools still fall short on accuracy and business impact. Download the full report today to see how AI is being used — and where go-to-market professionals think there are gaps and opportunities.

article thumbnail

New malware Cthulhu Stealer targets Apple macOS users

Security Affairs

Cato Security found a new info stealer, called Cthulhu Stealer, that targets Apple macOS and steals a wide range of information. Cado Security researchers have discovered a malware-as-a-service (MaaS) targeting macOS users dubbed Cthulhu Stealer. Cthulhu Stealer targets macOS users via an Apple disk image (DMG) that disguises itself as legitimate software.

Passwords 320

More Trending

article thumbnail

China-linked APT Velvet Ant exploited zero-day to compromise Cisco switches

Security Affairs

China-linked APT group Velvet Ant exploited a recently disclosed zero-day in Cisco switches to take over the network appliance. Researchers at cybersecurity firm Sygnia reported that the China-linked APT group Velvet Ant has exploited the recently disclosed zero-day CVE-2024-20399 in Cisco switches to take over the network devices. In July 2024, Cisco addressed the NX-OS zero-day CVE-2024-20399 (CVSS score of 6.0) that China-linked group Velvet Ant exploited to deploy previously unknown malw

article thumbnail

OnDemand | The Business Value of Prisma Cloud for Google Cloud

Data Breach Today

The Business Value of Prisma Cloud for Google Cloud.

Cloud 278
article thumbnail

Member of cybercrime group Karakurt charged in the US

Security Affairs

The Russian national Deniss Zolotarjovs has been charged in a U.S. court for his role in the Karakurt cybercrime gang. Deniss Zolotarjovs (33), a Russian cybercriminal, has been charged in a U.S. court for his role in the Russian Karakurt cybercrime gang. The man has been charged with money laundering, wire fraud, and extortion. The man was arrested in Georgia in December 2023 and recently extradited to the U.S. “According to court documents, Zolotarjovs is a member of a known cybercrimina

article thumbnail

DOJ Lawsuit Accuses Georgia Tech of Cybersecurity Failures

Data Breach Today

New Lawsuit Alleges Georgia Tech Submitted 'False' Cybersecurity Score to DOD The Justice Department intervened in a whistleblower lawsuit against the Georgia Institute of Technology and the Georgia Tech Research Corp. for allegedly failing to implement federally required cybersecurity protections while overseeing sensitive government data.

article thumbnail

How to Achieve High-Accuracy Results When Using LLMs

Speaker: Ben Epstein, Stealth Founder & CTO | Tony Karrer, Founder & CTO, Aggregage

When tasked with building a fundamentally new product line with deeper insights than previously achievable for a high-value client, Ben Epstein and his team faced a significant challenge: how to harness LLMs to produce consistent, high-accuracy outputs at scale. In this new session, Ben will share how he and his team engineered a system (based on proven software engineering approaches) that employs reproducible test variations (via temperature 0 and fixed seeds), and enables non-LLM evaluation m

article thumbnail

How much can a 2GB Raspberry Pi handle? I put it to the ultimate test

Collaboration 2.0

Trying to save a few bucks can make or break your next Raspberry Pi project.

IT 246
article thumbnail

Banking Lobby Asks Ginnie Mae to Modify Cyber Reporting Rule

Data Breach Today

Banking and Housing Policy Groups Call New Cyber Reporting Measures 'Impractical' A group of banking and housing lobbyists are urging Ginnie Mae to redo its latest set of cybersecurity incident reporting requirements for custodians of mortgage-backed securities, calling the new measures "impractical" and potentially burdensome for many organizations.

article thumbnail

Microsoft says its killing Windows Control Panel - here's why I'm not holding my breath

Collaboration 2.0

Finally, the 40-year-old tool will be deprecated in favor of the Settings app? Raise your hand if you still use Control Panel.

IT 190
article thumbnail

Feds to Health Sector: Don't Skimp on Physical Security

Data Breach Today

Cyberattacks Soar, But Guarding PHI From Break-Ins, Natural Disasters Is Critical Despite the endless barrage of cyberattacks hitting the healthcare sector, HIPAA-regulated entities must not neglect their duty to protect electronic patient information against physical threats, including burglaries and natural disasters, U.S. regulators said.

Security 173
article thumbnail

The GTM Intelligence Era: ZoomInfo 2025 Customer Impact Report

ZoomInfo customers aren’t just selling — they’re winning. Revenue teams using our Go-To-Market Intelligence platform grew pipeline by 32%, increased deal sizes by 40%, and booked 55% more meetings. Download this report to see what 11,000+ customers say about our Go-To-Market Intelligence platform and how it impacts their bottom line. The data speaks for itself!

article thumbnail

ChatGPT is (obviously) the most popular AI app - but the runners up may surprise you

Collaboration 2.0

ChatGPT still leads the way in generative AI apps, but the runners-up give some interesting insight into which tools are most popular - and how people are using them.

190
190
article thumbnail

Slack Patches Prompt Injection Flaw in AI Tool Set

Data Breach Today

Hackers Could Exploit Bug to Manipulate Slack AI's LLM to Steal Data Chat app Slack patched a vulnerability in its artificial intelligence tool set that hackers could have exploited to manipulate an underlying large language model to phish employees and steal sensitive data. Slack said it was a low-severity bug.

article thumbnail

Want a programming job? Make sure you learn these three languages

Collaboration 2.0

The 2024 IEEE Spectrum Top Programming Languages report is out. We've seen some movement at the top of the jobs list that you should know about. A few fell off the list, too.

190
190
article thumbnail

When War Came to Their Country, They Built a Map

WIRED Threat Level

The Telegram channel and website Deep State uses public data and insider intelligence to power its live tracker of Ukraine’s ever-shifting front line.

IT 169
article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

If you want a programming job, be sure to learn these three languages

Collaboration 2.0

The 2024 IEEE Spectrum Top Programming Languages report is out. We've seen some movement at the top of the jobs list that you should know about. A few fell off the list, too.

190
190
article thumbnail

A Tangled Web We Weave: When Reported M&A Never Materializes

Data Breach Today

Why Acquisition Reports Emerge in the Media, and What It Means for Those Mentioned Companies historically responded to M&A reports with milquetoast statements about "not commenting on rumors or speculation," but aggressive clapbacks have become much more common. Increasingly, executives are willing to attract more publicity by publicly - and vocally - denying acquisition reports.

IT 162
article thumbnail

Linus Torvalds talks AI, Rust adoption, and why the Linux kernel is 'the only thing that matters'

Collaboration 2.0

In a wide-ranging conversation with Verizon open-source officer Dirk Hondhel, 'plodding engineer' Linus Torvalds discussed where Linux is today and where it may go tomorrow.

IT 190
article thumbnail

Medibank to Spend AU$126M on Post-Breach Security Upgrade

Data Breach Today

Australian Insurer Expects Years of Litigation Related to 2022 Hack Australia's largest provider of private health insurance says it expects to spend a total of AU$126 million, or $84.78 million, over a three-year period to upgrade its IT security. A Russia-based cybercriminal group hacked Medibank in October 2022.

Insurance 162
article thumbnail

5 Ways You Can Win Faster with Gen AI in Sales

Incorporating generative AI (gen AI) into your sales process can speed up your wins through improved efficiency, personalized customer interactions, and better informed decision- making. Gen AI is a game changer for busy salespeople and can reduce time-consuming tasks, such as customer research, note-taking, and writing emails, and provide insightful data analysis and recommendations.

article thumbnail

How I used ChatGPT to scan 170k lines of code in seconds and save me hours of detective work

Collaboration 2.0

Writing this article about the problem I solved took me a few hours. The actual AI analysis process, from start to finish, took me less than 10 minutes. That's some serious productivity right there.

190
190
article thumbnail

Take a Selfie Using a NY Surveillance Camera

Schneier on Security

This site will let you take a selfie with a New York City traffic surveillance camera.

Privacy 128
article thumbnail

5 free AI tools for school that students, teachers, and parents can use, too

Collaboration 2.0

These AI tools can summarize PDFs, tutor you, help with essay writing and math problems, and much more.

189
189
article thumbnail

The Trouble with Procurement Departments, Resellers and Stripe

Troy Hunt

It should be so simple: you're a customer who wants to purchase something so you whip out the credit card and buy it. I must have done this thousands of times, and it's easy! I've bought stuff with plastic credit cards, stuff with Apple Pay on my phone and watch and, like all of us, loads of stuff simply by entering credit card details into a website.

IT 127
article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

1 in 5 top companies mention generative AI in their financial reports, but not in a good way

Collaboration 2.0

Generative AI is on everyone's radar. But more often than not, emerging technology is seen as a risk factor.

Risk 189
article thumbnail

Business Email Compromise Scams Rise 20%, Making up Nearly Half of all Spam Emails

KnowBe4

New research on email threats points to AI-based tools to assist in generating BEC content. And the overwhelming targeted role may or may not surprise you.

article thumbnail

How I test an AI chatbot's coding ability - and you can, too

Collaboration 2.0

This article provides detailed prompts and tests you can repeat on your favorite AI chatbot to see if it can help you program reliably.

IT 189