Security News

Microsoft: Copilot ‘app’ on Windows Server mistakenly added by Edge
2024-04-17 12:16

Microsoft says the new Copilot app, mistakenly added to the list of installed Windows apps by recent Edge updates, doesn't collect or relay data to its servers. For this reason, they were surprised to see a new 8KB Microsoft Copilot app added to the list of installed programs on live production builds of Windows Server 2022.

Microsoft: New Copilot app added by Edge doesn’t collect data
2024-04-17 12:16

Microsoft says the new Copilot app, added by recent Edge updates to the list of installed Windows apps, doesn't collect or relay data to its servers. "Updates to Edge browser version 123.0.2420.65, released on March 28, 2024 and later, might incorrectly install a new package called 'Microsoft chat provider for Copilot in Windows' on Windows devices. Resulting from this, the Microsoft Copilot app might appear in the Installed apps in Settings menu," Redmond said.

Using AI-Generated Legislative Amendments as a Delaying Technique
2024-04-17 11:08

Canadian legislators proposed 19,600 amendments-almost certainly AI-generated-to a bill in an attempt to delay its adoption. I wrote about many different legislative delaying tactics in , but this is a new one.

#AI
GenAI: A New Headache for SaaS Security Teams
2024-04-17 11:07

The introduction of Open AI’s ChatGPT was a defining moment for the software industry, touching off a GenAI race with its November 2022 release. SaaS vendors are now rushing to upgrade tools with...

Critical Atlassian Flaw Exploited to Deploy Linux Variant of Cerber Ransomware
2024-04-17 10:57

Threat actors are exploiting unpatched Atlassian servers to deploy a Linux variant of Cerber (aka C3RB3R) ransomware. The attacks leverage CVE-2023-22518 (CVSS score: 9.1), a critical security...

Hackers Exploit Fortinet Flaw, Deploy ScreenConnect, Metasploit in New Campaign
2024-04-17 10:23

Cybersecurity researchers have discovered a new campaign that's exploiting a recently disclosed security flaw in Fortinet FortiClient EMS devices to deliver ScreenConnect and Metasploit Powerfun...

OpenAI's GPT-4 can exploit real vulnerabilities by reading security advisories
2024-04-17 10:15

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Palo Alto firewalls: Public exploits, rising attacks, ineffective mitigation
2024-04-17 09:29

While it initially seemed that protecting Palo Alto Network firewalls from attacks leveraging CVE-2024-3400 would be possible by disabling the devices' telemetry, it has now been comfirmed that this mitigation is ineffectual."Device telemetry does not need to be enabled for PAN-OS firewalls to be exposed to attacks related to this vulnerability," Palo Alto Networks noted on Tuesday, and said they are aware of an "Increasing number of attacks that leverage the exploitation of this vulnerability."

Cisco Warns of Global Surge in Brute-Force Attacks Targeting VPN and SSH Services
2024-04-17 08:38

Cisco is warning about a global surge in brute-force attacks targeting various devices, including Virtual Private Network (VPN) services, web application authentication interfaces, and SSH...

UK e-visa rollout starts today for millions: no more physical immigration cards
2024-04-17 05:48

The Home Office has started rolling out e-visas for existing holders of physical immigration documents like Biometric Residence Permits and Biometric Residence Cards. Millions of such residents will start receiving email invites from today, in batches, prompting them to create a UK Visas and Immigration account that will serve as digital proof of their legal immigration status.