Security News > 2024 > April

The Tech Needed to Survive This Decade’s ‘Seismic’ APAC B2B Trends
2024-04-05 18:31

APAC regional B2B enterprises will need to consider their levels of investment in a number of technologies and integrating new tools now to prepare for and adapt to the coming changes. The B2B Futures: The View From 2030 report argues four key "Seismic" trends are coming to B2B:. Jake Hird, vice president of strategy, Merkle B2B - APAC, told TechRepublic B2B enterprises in the region will need to respond with investment in technologies including IoT, AI, data analytics and blockchain to ensure they adapt to these shifts hitting their businesses and markets.

New Ivanti RCE flaw may impact 16,000 exposed VPN gateways
2024-04-05 17:40

Approximately 16,500 Ivanti Connect Secure and Poly Secure gateways exposed on the internet are likely vulnerable to a remote code execution flaw the vendor addressed earlier this week. The flaw is tracked as CVE-2024-21894 and is a high-severity heap overflow in the IPSec component of Ivanti Connect Secure 9.x and 22.x, potentially allowing unauthenticated users to cause denial of service or achieve RCE by sending specially crafted requests.

Microsoft fixes Windows Sysprep issue behind 0x80073cf2 errors
2024-04-05 17:38

Microsoft has fixed a known issue causing 0x80073cf2 errors when using the System Preparation tool after installing November Windows 10 updates. It also helps manage multiple computers on a network or fine-tune a single Windows image for a specific PC. The known issue only impacts Windows 10, version 22H2 systems where Sysprep is used by admins in audit mode to test or add drivers or apps to new Windows installations.

Fake Facebook MidJourney AI page promoted malware to 1.2 million people
2024-04-05 16:47

Hackers are using Facebook advertisements and hijacked pages to promote fake Artificial Intelligence services, such as MidJourney, OpenAI's SORA and ChatGPT-5, and DALL-E, to infect unsuspecting users with password-stealing malware. In one of the cases seen by researchers at Bitdefender, a malicious Facebook page impersonating Midjourney amassed 1.2 million followers and remained active for nearly a year before it was eventually taken down.

Acuity confirms hackers stole non-sensitive govt data from GitHub repos
2024-04-05 15:32

Acuity, a federal contractor that works with U.S. government agencies, has confirmed that hackers breached its GitHub repositories and stole documents containing old and non-sensitive data. Acuity is a tech consulting firm with almost 400 employees and a $100+ million annual revenue that provides DevSecOps, cyber security, data analytics, and operations support services to federal civilian national security customers.

US government excoriates Microsoft for 'avoidable errors' but keeps paying for its products
2024-04-05 14:30

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

AI-as-a-Service Providers Vulnerable to PrivEsc and Cross-Tenant Attacks
2024-04-05 14:08

New research has found that artificial intelligence (AI)-as-a-service providers such as Hugging Face are susceptible to two critical risks that could allow threat actors to escalate privileges,...

Panera Bread week-long IT outage caused by ransomware attack
2024-04-05 13:52

Panera Bread's recent week-long outage was caused by a ransomware attack, according to people familiar with the matter and emails seen by BleepingComputer. Panera has not responded to multiple requests for comments about the outage and the attack.

Hotel check-in terminal bug spews out access codes for guest rooms
2024-04-05 12:30

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Get an Extra 20% Off a Lifetime of Powerful VPN Protection Through 4/7
2024-04-05 11:47

Use coupon SECURE20 at checkout through 4/7 to unlock an additional 20% off this deal! TL;DR: Protect your business's data and privacy with a lifetime subscription to OysterVPN. It's currently available to new users for the best-on-web price of just $32 with coupon code SECURE20 through April 7.