Security News > 2023 > October

Google expands bug bounty program to cover AI-related threats
2023-10-30 09:12

Google has expanded its bug bounty program, aka Vulnerability Rewards Program, to cover threats that could arise from Google's generative AI systems. Following the voluntary commitment to the Biden-⁠Harris Administration to develop responsible AI and manage its risks, Google has added AI-related risks to its bug bounty program, which gives recognition and compensation to ethical hackers who successfully find and disclose vulnerabilities in Google's systems.

Urgent: New Security Flaws Discovered in NGINX Ingress Controller for Kubernetes
2023-10-30 06:46

Three unpatched high-severity security flaws have been disclosed in the NGINX Ingress controller for Kubernetes that could be weaponized by a threat actor to steal secret credentials from the...

The dangers of dual ransomware attacks
2023-10-30 06:30

The FBI has recently warned about dual ransomware attacks, a new trend that involves criminals carrying out two or more attacks in close proximity to each other. The time between attacks ranges from 48 hours to a maximum of ten days.

Finding the right approach to security awareness
2023-10-30 06:00

As artificial intelligence amplifies the sophistication and reach of phishing, vishing, and smishing attacks, understanding and managing human cyber risks has become increasingly vital. Security awareness training is essential and must be a live, evolving process.

AI threat landscape: Model theft and inference attacks emerge as top concerns
2023-10-30 05:30

Enterprises will invest nearly $16 billion worldwide on GenAI solutions in 2023, according to IDC. In this Help Net Security interview, Guy Guzner, CEO at Savvy, discusses the challenges and opportunities presented by in-house AI models, the security landscape surrounding them, and the future of AI cybersecurity. Organizations developing in-house AI models have a distinct advantage when it comes to critical security concerns.

Companies scramble to integrate immediate recovery into ransomware plans
2023-10-30 05:00

More than one-third of companies still do not have a well-rounded, holistic ransomware strategy in place, according to Zerto. In all, just over half of the companies surveyed focus on both recovery and prevention.

Cyber attacks cause revenue losses in 42% of small businesses
2023-10-30 04:30

The financial impacts of cyber breaches continued to drop compared to previous years, with more small businesses reporting losses under $250,000 and fewer reporting higher dollar-value events. Focus on data security grows among small business leaders.

Hackers Using MSIX App Packages to Infect Windows PCs with GHOSTPULSE Malware
2023-10-30 04:21

A new cyber attack campaign has been observed using spurious MSIX Windows app package files for popular software such as Google Chrome, Microsoft Edge, Brave, Grammarly, and Cisco Webex to...

IoT’s convenience comes with cybersecurity challenges
2023-10-30 04:00

The rapid proliferation of Internet of Things devices has ushered in a new era of connectivity and convenience, transforming the way we live and work. This interconnectivity has also given rise to a host of cybersecurity challenges and vulnerabilities.

LockBit alleges it boarded Boeing, stole 'sensitive data'
2023-10-30 02:30

"Security In Brief Notorious ransomware gang LockBit has reportedly exfiltrated"a tremendous amount of sensitive data from aerospace outfit Boeing. VX underground published a screenshot of Lockbit's announcement, and threat to expose data if Boeing does not engage with it by November 2nd. Boeing has told US media it is investigating Lockbit's claims.