Security News

GoFetch security exploit can't be disabled on M1 and M2 Apple chips
2024-03-25 14:30

The GoFetch vulnerability found on Apple M-series and Intel Raptor Lake CPUs has been further unpacked by the researchers who first disclosed it. DMPs are present on all Apple M-series CPUs and Intel's Raptor Lake processors, and the dedicated website for GoFetch now shows how exactly the exploit is carried out.

Scammers steal millions from FTX, BlockFi claimants
2024-03-25 12:46

Customers of bankrupt crypto platform BlockFi have been targeted with a very convincing phishing email impersonating the platform, asking them to connect their wallet to complete the withdrawal of remaining funds. BlockFi was a digital asset lender that filed for Chapter 11 bankruptcy protection after it lost access to funds in the wake of the bankruptcy of the FTX cryptocurrency exchange and the Silicon Valley Bank shutdown.

Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others
2024-03-25 11:58

Unidentified adversaries orchestrated a sophisticated attack campaign that has impacted several individual developers as well as the GitHub organization account associated with Top.gg, a Discord...

Key Lesson from Microsoft’s Password Spray Hack: Secure Every Account
2024-03-25 11:37

In January 2024, Microsoft discovered they’d been the victim of a hack orchestrated by Russian-state hackers Midnight Blizzard (sometimes known as Nobelium). The concerning detail about this case...

Google's new AI search results promotes sites pushing malware, scams
2024-03-25 11:32

Google's new AI-powered 'Search Generative Experience' algorithms recommend scam sites that redirect visitors to unwanted Chrome extensions, fake iPhone giveaways, browser spam subscriptions, and tech support scams. Earlier this month, Google began rolling out a new feature called Google Search Generative Experience in its search results, which provides AI-generated quick summaries for search queries, including recommendations for other sites to visit related to the query.

Licensing AI Engineers
2024-03-25 11:04

Stephen March 25, 2024 8:02 AM. Physician and attorney self governance are both organized at the state level. There are advantages to operation at this scale - chiefly that smaller communities will tend to know their members better.

#AI
APT29 hit German political parties with bogus invites and malware
2024-03-25 09:41

APT29 has been spotted targeting German political parties for the first time, Mandiant researchers have shared. The attack started in late February 2024, with phishing emails containing bogus invitations to a dinner reception, ostensibly sent by the Christian Democratic Union, a major political party in Germany.

Time to examine the anatomy of the British Library ransomware nightmare
2024-03-25 09:30

Opinion Quiz time: name one thing you know about the Library of Alexandria. The Rhysida ransomware attack on the British Library last October didn't have the visceral physical aspect that creates a folk memory, but it should for anyone who makes enterprise IT. Five months on, not only are significant systems not restored, they've gone forever.

New "GoFetch" Vulnerability in Apple M-Series Chips Leaks Secret Encryption Keys
2024-03-25 09:02

A new security shortcoming discovered in Apple M-series chips could be exploited to extract secret keys used during cryptographic operations. Dubbed GoFetch, the vulnerability relates to a...

Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks
2024-03-25 07:37

The Iran-affiliated threat actor tracked as MuddyWater (aka Mango Sandstorm or TA450) has been linked to a new phishing campaign in March 2024 that aims to deliver a legitimate Remote Monitoring...