Security News > 2024 > July

Indian Software Firm's Products Hacked to Spread Data-Stealing Malware
2024-07-01 12:44

Installers for three different software products developed by an Indian company named Conceptworld have been trojanized to distribute information-stealing malware. The installers correspond to...

Juniper Networks flings out emergency patches for perfect 10 router vuln
2024-07-01 11:32

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Model Extraction from Neural Networks
2024-07-01 11:05

A new paper, "Polynomial Time Cryptanalytic Extraction of Neural Network Models," by Adi Shamir and others, uses ideas from differential cryptanalysis to extract the weights inside a neural network using specific queries and their results. Billions of dollars and countless GPU hours are currently spent on training Deep Neural Networks for a variety of tasks.

End-to-End Secrets Security: Making a Plan to Secure Your Machine Identities
2024-07-01 10:51

At the heart of every application are secrets. Credentials that allow human-to-machine and machine-to-machine communication. Machine identities outnumber human identities by a factor of 45-to-1...

New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems
2024-07-01 10:50

OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root privileges in glibc-based Linux systems....

Polyfill.io claims reveal new cracks in supply chain, but how deep do they go?
2024-07-01 10:32

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Poyfill.io claims reveal new cracks in supply chain, but how deep do they go?
2024-07-01 10:32

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

AVG Secure VPN vs Surfshark (2024): Which VPN Is Better?
2024-07-01 10:15

Surfshark offers three levels of plans for individuals, and the yearly subscriptions for all of them are pretty affordable, especially compared to AVG. Surfshark Starter, the entry-level plan, includes the VPN plus ad and cookie pop-up blockers. To test the speed of AVG and Surfshark, I first used Ookla's Speed Test without any VPN running and got baseline results of 737.88 download Mbps and 605.14 upload Mbps. Then, I connected each VPN to the nearest server in Atlanta and ran the exact same test again.

CISA director: US is 'not afraid' to shout about Big Tech's security failings
2024-07-01 09:35

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Router maker's support portal hacked, replies with MetaMask phishing
2024-07-01 07:58

BleepingComputer has verified that the helpdesk portal of a router maker is currently sending MetaMask phishing emails in response to newly filed support tickets, in what appears to be a compromise. Support tickets acknowledged with MetaMask phishing.