Bug affecting PHP scripts demands ‘immediate action from defenders globally’

A vulnerability initially exploited mostly in cyberattacks against Japanese organizations is now a potential problem worldwide, researchers said Friday.

The Record from Recorded Future News – ​Read More

MITRE EMB3D for OT & ICS Threat Modeling Takes Flight

Manufacturers and infrastructure providers are gaining options to satisfy regulations and boost cyber safety for embedded and industrial control systems, as EMB3D, STRIDE, and ATT&CK for ICS gain traction.

darkreading – ​Read More

Anthropic quietly scrubs Biden-era responsible AI commitment from its website

AI companies continue to reduce evidence of Biden-era AI safety policy from their communications as attitudes shift under Trump.

Latest stories for ZDNET in Security – ​Read More

‘Spearwing’ RaaS Group Ruffles Feathers in Cyber Threat Scene

The group is using the Medusa malware and taking up space once held by other notable ransomware groups like LockBot, increasing its victim list to 400 and demanding astoundingly high ransoms.

darkreading – ​Read More

Malicious use of Cobalt Strike down 80% after crackdown, Fortra says

An effort launched in 2023 to curb the longstanding issue of pirated Cobalt Strike software being used by cybercriminals appears to have borne fruit.

The Record from Recorded Future News – ​Read More

Static Scans, Red Teams and Frameworks Aim to Find Bad AI Models

With hundreds of AI models found to harbor malicious code, cybersecurity firms are releasing technology to help companies manage their AI development and deployment efforts.

darkreading – ​Read More

Women in Cyber Security on the Rise, But Facing More Layoffs and Budget Cuts Than Men

In 2024, women accounted for 22% of global security teams on average, compared to 17% in 2023, according to ISC2.

Security | TechRepublic – ​Read More

Zero-Days Put Tens of 1,000s of Orgs at Risk for VM Escape Attacks

More than 41,000 ESXi instances remain vulnerable to a critical VMware vulnerability, one of three that Broadcom disclosed earlier this week.

darkreading – ​Read More

Cybercrime’s Cobalt Strike Use Plummets 80% Worldwide

Fortra, Microsoft, and Health-ISAC have combined forces to claw back one of hackers’ most prized attack tools, with massive takedowns.

darkreading – ​Read More

Taylor Swift Ticket Thieves Charged in Court for Resale Operation

The pair found a loophole through StubHub’s services, allowing them to steal tickets and resell them for personal profit, amassing hundreds of thousands of dollars.

darkreading – ​Read More