Purple Teaming and the Role of Threat Categorization

Purple team assessments, where red and blue teams collaborate, can provide a more comprehensive approach to security assessments, but they need to evolve to account for the multitude of attack technique variants.

Cyware News – Latest Cyber News – ​Read More

New Financial Fraud APK Campaign Discovered

A new family of malicious Android Package Kit (APK) files has been discovered targeting Chinese users. The attackers pose as law enforcement officials and claim the victim’s phone number or bank account is involved in financial fraud.

Cyware News – Latest Cyber News – ​Read More

SEC X Account Hack Draws Senate Outrage

Senators from both parties called the Securities and Exchange Commission’s lack of MFA “inexcusable” and demand investigation into the regulator’s cybersecurity lapse.

darkreading – ​Read More

CISA Adds 9.8 ‘Critical’ Microsoft SharePoint Bug to its KEV Catalog

It’s a tale as old as time: an old, long-since patched vulnerability that remains actively exploited.

darkreading – ​Read More

GitLab Releases Updates to Address Critical Vulnerabilities

Two vulnerabilities are critical, and three others are determined to be of high, medium, and low severity.

darkreading – ​Read More

How enterprises are using gen AI to protect against ChatGPT leaks

There’s growing interest in generative AI Isolation and comparable technologies to keep confidential data out of ChatGPT, Bard and other gen AI sitesRead More

Security News | VentureBeat – ​Read More

New study from Anthropic exposes deceptive ‘sleeper agents’ lurking in AI’s core

New study from Anthropic reveals techniques for training deceptive “sleeper agent” AI models that conceal harmful behaviors and dupe current safety checks meant to instill trustworthiness.Read More

Security News | VentureBeat – ​Read More

Newly Discovered Ivanti Secure VPN Zero-Day Vulnerabilities Allow Chinese Threat Actor to Compromise Systems

Most of the exposed VPN appliances are in the U.S., followed by Japan and Germany. Read the technical details about these zero-day vulnerabilities, along with detection and mitigation tips.

Security | TechRepublic – ​Read More

Hyundai MEA X Account Hacked, Followed by Crypto Promotion

Attackers hit more X accounts to promote Overworld Bitcoin registration.

darkreading – ​Read More