Security News

Prompt Injection Defenses Against LLM Cyberattacks
2024-11-07 16:13

Interesting research: “Hacking Back the AI-Hacker: Prompt Injection as a Defense Against LLM-driven Cyberattacks“: Large language models (LLMs) are increasingly being harnessed to automate...

Infostealer malware bypasses Chrome’s new cookie-theft defenses
2024-09-24 17:31

Infostealer malware developers released updates claiming to bypass Google Chrome's recently introduced feature App-Bound Encryption to protect sensitive data such as cookies. [...]

Google Chrome Switches to ML-KEM for Post-Quantum Cryptography Defense
2024-09-17 12:22

Google has announced that it will be switching from KYBER to ML-KEM in its Chrome web browser as part of its ongoing efforts to defend against the risk posed by cryptographically relevant quantum...

Top priorities for federal cybersecurity: Infrastructure, zero trust, and AI-driven defense
2024-09-12 04:00

In this Help Net Security, Erica Banks, VP and a leader in Booz Allen’s civilian services business, discusses the Federal Cybersecurity Strategy’s role in safeguarding national assets. Banks...

New Tickler malware used to backdoor US govt, defense orgs
2024-08-28 18:36

The APT33 Iranian hacking group has used new Tickler malware to backdoor the networks of organizations in the government, defense, satellite, oil and gas sectors in the United States and the...

New Tickler malware used to backdoor US govt, defense orgs
2024-08-28 18:36

The APT33 Iranian hacking group has used new Tickler malware to backdoor the networks of organizations in the government, defense, satellite, oil and gas sectors in the United States and the...

UK plans to revamp national cyber defense tools are already in motion
2024-08-02 10:34

The UK's National Cyber Security Centre says it's in the planning stages of bringing a new suite of services to its existing Active Cyber Defence program. Existing services under ACD 1.0 such as Logging Made Easy and Protective DNS are already run by external partners - CISA and Cloudflare respectively - but some, such as Early Warning, can only ever be run by the NCSC due to their very nature.

'Error' in Microsoft's DDoS defenses amplified 8-hour Azure outage
2024-07-31 12:58

Do you have problems configuring Microsoft's Defender? You might not be alone: Microsoft admitted that whatever it's using for its defensive implementation exacerbated yesterday's Azure instability. Microsoft has published its strategy to defend against network-based DDoS attacks, noting it was unique due to the global footprint of the company.

Microsoft: DDoS defense error amplified attack on Azure, leading to outage
2024-07-31 10:42

A DDoS attack that started on Tuesday has made a number of Microsoft Azure and Microsoft 365 services temporarily inaccessible, the company has confirmed. Microsoft's mitigation statement on the Azure status history page.

CISOs must shift from tactical defense to strategic leadership
2024-07-19 03:30

Fully 95% of IT and security professionals believe security threats will be more dangerous due to AI - yet, despite that elevated risk, nearly one in three security and IT professionals have no documented strategy in place to address generative AI risks. When leaders don't understand vulnerability management, they may not realize how changing leadership priorities can impact the security of their organization.