MIT Brothers Charged With Exploiting Ethereum to Steal $25 Million

The two MIT graduates discovered a flaw in a common trading tool for the Ethereum blockchain. Does it presage problems ahead for cryptocurrency?

darkreading – ​Read More

Stalkerware App With Security Bug Discovered on Hotel Systems

The spyware is able to capture screenshots of a user’s device every few seconds from any location globally.

darkreading – ​Read More

Courtroom Recording Platform JAVS Hijacked in Supply Chain Attack

With more than 10,000 installations across prisons, courts, and governments, impacted Justice AV Solutions users are urged to re-image affected endpoints and reset credentials.

darkreading – ​Read More

Anthropic’s Generative AI Research Reveals More About How LLMs Affect Security and Bias

Anthropic opened a window into the ‘black box’ where ‘features’ steer a large language model’s output.

Security | TechRepublic – ​Read More

The SEC slaps NYSE’s parent company with a $10M fine for not immediately reporting a hack

Intercontinental Exchange failed to notify nine of its subsidiaries about a VPN breach, sitting on the information for days.

Latest stories for ZDNET in Security – ​Read More

New Gift Card Scam Targets Retailers, Not Buyers, to Print Endless $$$

Microsoft researchers discover an old-timey scam with a facelift for the cloud era: hacking retailers’ portals to make it rain gift cards.

darkreading – ​Read More

IBM X-Force Report: Grandoreiro Malware Targets More Than 1,500 Banks in 60 Countries

Find out how Grandoreiro banking trojan campaigns work and the countries targeted, as well as how to mitigate this malware threat.

Security | TechRepublic – ​Read More

CISA Warns of Actively Exploited Apache Flink Security Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a security flaw impacting Apache Flink, the open-source, unified stream-processing and batch-processing framework, to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Tracked as CVE-2020-17519, the issue relates to a case of improper access control that

The Hacker News – ​Read More