Security News

Researchers Uncover Vulnerabilities in Open-Source AI and ML Models
2024-10-29 13:00

A little over three dozen security vulnerabilities have been disclosed in various open-source artificial intelligence (AI) and machine learning (ML) models, some of which could lead to remote code...

Researchers Uncover OS Downgrade Vulnerability Targeting Microsoft Windows Kernel
2024-10-28 05:29

A new attack technique could be used to bypass Microsoft's Driver Signature Enforcement (DSE) on fully patched Windows systems, leading to operating system (OS) downgrade attacks. "This bypass...

Researchers Discover Command Injection Flaw in Wi-Fi Alliance's Test Suite
2024-10-25 13:41

A security flaw impacting the Wi-Fi Test Suite could enable unauthenticated local attackers to execute arbitrary code with elevated privileges. The CERT Coordination Center (CERT/CC) said the...

Apple Opens PCC Source Code for Researchers to Identify Bugs in Cloud AI Security
2024-10-25 12:25

Apple has publicly made available its Private Cloud Compute (PCC) Virtual Research Environment (VRE), allowing the research community to inspect and verify the privacy and security guarantees of...

Apple creates Private Cloud Compute VM to let researchers find bugs
2024-10-24 22:48

Apple created a Virtual Research Environment to allow public access to testing the security of its Private Cloud Compute system, and released the source code for some "key components" to help...

Researchers Reveal 'Deceptive Delight' Method to Jailbreak AI Models
2024-10-23 09:54

Cybersecurity researchers have shed light on a new adversarial technique that could be used to jailbreak large language models (LLMs) during the course of an interactive conversation by sneaking...

Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers
2024-10-21 06:59

Cybersecurity researchers have discovered severe cryptographic issues in various end-to-end encrypted (E2EE) cloud storage platforms that could be exploited to leak sensitive data. "The...

Researchers Uncover Cicada3301 Ransomware Operations and Its Affiliate Program
2024-10-17 13:54

Cybersecurity researchers have gleaned additional insights into a nascent ransomware-as-a-service (RaaS) called Cicada3301 after successfully gaining access to the group's affiliate panel on the...

WeChat devs introduced security flaws when they modded TLS, say researchers
2024-10-17 08:31

No attacks possible, but enough issues to cause concern Messaging giant WeChat uses a network protocol that the app's developers modified – and by doing so introduced security weaknesses,...

Researchers Uncover Hijack Loader Malware Using Stolen Code-Signing Certificates
2024-10-15 06:43

Cybersecurity researchers have disclosed a new malware campaign that delivers Hijack Loader artifacts that are signed with legitimate code-signing certificates. French cybersecurity company...