Security News > 2023 > February

How to Use AI in Cybersecurity and Avoid Being Trapped
2023-02-24 13:22

Our systems have detected unusual traffic from your computer network. This page appears when Google automatically detects requests coming from your computer network which appear to be in violation of the Terms of Service.

CISA Sounds Alarm on Cybersecurity Threats Amid Russia's Invasion Anniversary
2023-02-24 13:10

The U.S. Cybersecurity and Infrastructure Security Agency is urging organizations and individuals to increase their cyber vigilance, as Russia's military invasion of Ukraine officially enters one year. "CISA assesses that the United States and European nations may experience disruptive and defacement attacks against websites in an attempt to sow chaos and societal discord on February 24, 2023, the anniversary of Russia's 2022 invasion of Ukraine," the agency said.

Microsoft announces automatic BEC, ransomware attack disruption capabilities
2023-02-24 13:09

Last year, Microsoft announced automatic attack disruption capabilities in Microsoft 365 Defender, its enterprise defense suite. On Wednesday, it announced that these capabilities will now help organizations disrupt two common attack scenarios: BEC and human-operated ransomware attacks.

Putting Undetectable Backdoors in Machine Learning Models
2023-02-24 12:34

Abstract: Given the computational cost and technical expertise required to train machine learning models, users may delegate the task of learning to a service provider. We show how a malicious learner can plant an undetectable backdoor into a classifier.

Brave browser to block “open in app” prompts, pool-party attacks
2023-02-24 09:38

The next major version of the privacy-focused Brave browser will start blocking annoyances like "Open in app" prompts and will feature better protections against pool-party attacks. Brave will now block this annoyance starting version 1.49 for Windows and Android, allowing users to browse the web without unexpected interruptions.

Even Top-Ranked Android Apps in Google Play Store Provide Misleading Data Safety Labels
2023-02-24 09:00

An investigation into data safety labels for Android apps available on the Google Play Store has uncovered "Serious loopholes" that allow apps to provide misleading or outright false information. The study, conducted by the Mozilla Foundation as part of its *Privacy Not Included initiative, compared the privacy policies and labels of the 20 most popular paid apps and the 20 most popular free apps on the app marketplace.

Dutch Police arrest three ransomware actors extorting €2.5 million
2023-02-24 08:32

The Amsterdam cybercrime police team has arrested three men for ransomware activity that generated €2.5 million from extorting small and large organizations in multiple countries. The extortion involved threats of leaking the data or destroying the company's digital infrastructure.

European Commission bans TikTok from staff gadgets
2023-02-24 07:27

The European Commission on Thursday banned the use of the TikTok short video app on corporate devices and on the personal devices of employees enrolled in the commission's mobile device management service. The commission's statement cites the need to protect staff from a rising number of cyber threats but fails to explain while TikTok was singled out.

Microsoft grows automated assault disruption to cover BEC, ransomware campaigns
2023-02-24 06:30

The automatic attack disruption functionality aimed at corporate security operation centers uses millions of data points and signals to identify active malware campaigns - including ransomware - and take steps to automatically isolate the device under attack from the network and to suspended accounts compromised by the attackers. The software and cloud services giant has now expanded the public preview of the automatic attack disruption capability to cover business email compromise and human-operated ransomware attacks.

Defenders on high alert as backdoor attacks become more common
2023-02-24 05:30

Although ransomware's share of incidents declined only slightly from 2021 to 2022, defenders were more successful detecting and preventing ransomware, according to IBM. Despite this, attackers continued to innovate with the report showing the average time to complete a ransomware attack dropped from 2 months down to less than 4 days. "The shift towards detection and response has allowed defenders to disrupt adversaries earlier in the attack chain - tempering ransomware's progression in the short term," said Charles Henderson, Head of IBM Security X-Force.