B+ Security Rating Masks Healthcare Supply Chain Risks

The healthcare sector received a “B+” security rating for the first half of 2024, indicating a decent level of security. However, it faces a significant vulnerability in the form of supply chain cyber risk.

Cyware News – Latest Cyber News – ​Read More

Russian APT Reportedly Behind New TeamViewer Hack

TeamViewer’s corporate network was hacked and some reports say the Russian group APT29 is behind the attack.

The post Russian APT Reportedly Behind New TeamViewer Hack appeared first on SecurityWeek.

SecurityWeek – ​Read More

This Viral AI Chatbot Will Lie and Say It’s Human

Bland AI’s customer services and sales bot is the latest example of “human-washing” in AI. Experts warn against the consequences of blurred reality.

Wired – ​Read More

Cyber Insurance Terms Drive Companies To Invest More in Security, Report Finds

Approximately three-quarters of companies have made investments in cyber defense in order to qualify for cyber insurance, according to a report by Sophos and Vanson Bourne.

Cyware News – Latest Cyber News – ​Read More

Polyfill Domain Shut Down as Owner Disputes Accusations of Malicious Activity

Namecheap shut down polyfill.io amid reports of malicious activity, but the Chinese owner claims it has good intentions.

The post Polyfill Domain Shut Down as Owner Disputes Accusations of Malicious Activity appeared first on SecurityWeek.

SecurityWeek – ​Read More

CISA Adds GeoServer, Linux Kernel, and Roundcube Webmail Bugs to its Known Exploited Vulnerabilities Catalog

The US cybersecurity agency CISA has issued a warning about cyber threat actors exploiting vulnerabilities in GeoServer (CVE-2022-24816), the Linux kernel (CVE-2022-2586), and Roundcube Webmail (CVE-2020-13965).

Cyware News – Latest Cyber News – ​Read More

Mitigating Skeleton Key, a New Type of Generative AI Jailbreak Technique

Microsoft has discovered a new type of jailbreak attack called Skeleton Key. This technique uses a multi-turn strategy to make the model ignore its guardrails, allowing it to generate forbidden content or override its decision-making rules.

Cyware News – Latest Cyber News – ​Read More

Researchers Warn of Flaws in Widely Used Industrial Gas Analysis Equipment

Multiple security flaws have been disclosed in Emerson Rosemount gas chromatographs that could be exploited by malicious actors to obtain sensitive information, induce a denial-of-service (DoS) condition, and even execute arbitrary commands.
The flaws impact GC370XA, GC700XA, and GC1500XA and reside in versions 4.1.5 and prior.
According to operational technology (OT) security firm Claroty, the

The Hacker News – ​Read More

Xeno RAT Spread via .gg Domains and GitHub

XenoRAT is being used by North Korean hackers and other actors targeting the gaming community. It is being spread through .gg domains and a GitHub repository disguised as Roblox scripting tools.

Cyware News – Latest Cyber News – ​Read More

California Privacy Regulator to Partner With French Data Authority

The California Privacy Protection Agency (CPPA) has signed a partnership agreement with France’s Commission Nationale de l’Informatique et des Libertés (CNIL) to conduct joint research and share investigative findings on data privacy issues.

Cyware News – Latest Cyber News – ​Read More