Security News

Microsoft says Russian hackers breached its systems, accessed source code
2024-03-08 15:31

Microsoft says the Russian 'Midnight Blizzard' hacking group recently accessed some of its internal systems and source code repositories using authentication secrets stolen during a January...

PyRIT: Open-source framework to find risks in generative AI systems
2024-03-04 06:00

Python Risk Identification Tool is Microsoft's open-source automation framework that enables security professionals and machine learning engineers to find risks in generative AI systems. It started as a collection of individual scripts used during the team's initial foray into red teaming generative AI systems in 2022.

New Silver SAML Attack Evades Golden SAML Defenses in Identity Systems
2024-02-29 15:21

Cybersecurity researchers have disclosed a new attack technique called Silver SAML that can be successful even in cases where mitigations have been applied against Golden SAML attacks. Silver SAML...

Lazarus Exploits Typos to Sneak PyPI Malware into Dev Systems
2024-02-29 08:17

The notorious North Korean state-backed hacking group Lazarus uploaded four packages to the Python Package Index (PyPI) repository with the goal of infecting developer systems with malware. The...

Hessen Consumer Center says systems encrypted by ransomware
2024-02-27 16:27

The story has been updated to clarify that the Hessen Consumer Center is not part of the government. The Hessen Consumer Center in Germany has been hit with a ransomware attack, causing IT systems to shut down and temporarily disrupting its availability.

German state of Hessen says systems encrypted by ransomware
2024-02-27 16:27

The German state of Hessen has been hit with a ransomware attack, causing the government to shut down IT systems and disrupting the availability of its consumer advice center. Hessen is a state in central Germany with over six million people that encompasses Frankfurt, the country's second-largest metropolitan area and a major financial center.

Checklist: Network and Systems Security
2024-02-22 16:00

While every organization's specific security needs form a unique and complex blend of interconnected requirements, numerous security fundamentals almost always apply to each of these groups. It stands to reason that cybersecurity pros who effectively identify network and systems risks and who standardize methods of mitigating those vulnerabilities are likely to experience less stress and volatility.

Safeguarding cyber-physical systems for a smart future
2024-02-19 08:58

Taking these systems offline to upgrade them with better security can be difficult and very expensive, if it can be done at all. "Ideally this process would start with an accurate inventory of the infrastructure and systems you have, which sounds simple enough," adds Grant Bailey, Solutions Engineer with Claroty.

Prudential Financial finds cybercrims lurking inside its IT systems
2024-02-14 17:24

Prudential Financial, the second largest life insurance company in the US and eight largest worldwide, is dealing with a digital break-in that exposed some internal company and customer records to a criminal group. "Confirmation of the"material cybersecurity incident" was made in an 8K filing [PDF] the corporation deposited with the SEC. "On February 5, 2024, Prudential Financial detected that, beginning February 4, 2024, a threat actor had gained unauthorized access to certain of our systems.

Hacking the flow: The consequences of compromised water systems
2024-02-12 05:30

In this Help Net Security video, Andy Thompson, Offensive Cybersecurity Research Evangelist at CyberArk, discusses the dire consequences of hacking water systems and why their cybersecurity must be prioritized. From contaminating water supplies to disrupting essential services, the impact of such attacks can present a direct danger to public health and safety.