Security News > 2024 > February

New Silver SAML Attack Evades Golden SAML Defenses in Identity Systems
2024-02-29 15:21

Cybersecurity researchers have disclosed a new attack technique called Silver SAML that can be successful even in cases where mitigations have been applied against Golden SAML attacks. Silver SAML...

Airbnb scammers pose as hosts, redirect users to fake Tripadvisor site
2024-02-29 14:18

Scammers on Airbnb are faking technical issues and citing higher fees to get users to a spoofed Tripadvisor website and steal their money. Malwarebytes researchers came across the Airbnb scam when trying to book an apartment through the platform.

Meta's pay-or-consent model hides 'massive illegal data processing ops': lawsuit
2024-02-29 13:00

Consumer groups are filing legal complaints in the EU in a coordinated attempt to use data protection law to stop Meta from giving local users a "Fake choice" between paying up and consenting to data collection. Privacy rights folks weren't happy about it from the get-go, with privacy advocacy group noyb, for example, sarcastically noting Meta was basically proposing you pay it in order to enjoy your fundamental rights under EU law.

ALPHV/BlackCat threatens to leak data stolen in Change Healthcare cyberattack
2024-02-29 12:41

The ALPHV/BlackCat ransomware group has claimed responsibility for the cyberattack that targeted Optum, a subsidiary of UnitedHealth Group, causing disruption to the Change Healthcare platform and affecting pharmacy transactions across the US. ALPHV/BlackCat is back. 3000+ source code files for Change Healthcare solutions.

How the “Frontier” Became the Slogan of Uncontrolled AI
2024-02-29 12:00

As early as 2018, the powerful foundation models powering cutting-edge applications like chatbots have been called "Frontier AI." In previous decades, the internet itself was considered an electronic frontier. Turner grappled with some of the negative consequences and contradictions of the frontier ethic and how it shaped American democracy.

#AI
GTPDOOR Linux Malware Targets Telecoms, Exploiting GPRS Roaming Networks
2024-02-29 11:33

Threat hunters have discovered a new Linux malware called GTPDOOR that’s designed to be deployed in telecom networks that are adjacent to GPRS roaming exchanges (GRX) The malware is novel in the...

Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks
2024-02-29 11:19

The notorious Lazarus Group actors exploited a recently patched privilege escalation flaw in the Windows Kernel as a zero-day to obtain kernel-level access and disable security software on...

How to Prioritize Cybersecurity Spending: A Risk-Based Strategy for the Highest ROI
2024-02-29 11:19

As an IT leader, staying on top of the latest cybersecurity developments is essential to keeping your organization safe. But with threats coming from all around — and hackers dreaming up new...

Kali Linux 2024.1 released: New tools, new look, new Kali Nethunter kernels
2024-02-29 10:20

OffSec has released Kali Linux 2024.1, the latest version of its popular penetration testing and digital forensics platform.The new version comes with new tools, a fresh look, a new image viewer for the Gnome desktop and a usability enhancement to the Xfce desktop, and updates for the Kali NetHunter mobile pentesting platform.

New Backdoor Targeting European Officials Linked to Indian Diplomatic Events
2024-02-29 08:19

A previously undocumented threat actor dubbed SPIKEDWINE has been observed targeting officials in European countries with Indian diplomatic missions using a new backdoor called WINELOADER. The...