Security News

Poking holes in Google tech bagged bug hunters $10M
2024-03-13 18:00

Google awarded $10 million to 632 bug hunters last year through its vulnerability reward programs. Google's 2023 highlights include newer reward categories, including finding flaws in its AI products and Android phone apps, plus a brand-new Bonus Awards program that periodically pays out time-limited, extra rewards for specific vulnerability targets.

Advanced AI, analytics, and automation are vital to tackle tech stack complexity
2024-03-11 04:30

97% of technology leaders find traditional AIOps models are unable to tackle the data overload, according to Dynatrace. 88% of organizations say the complexity of their technology stack has increased in the past 12 months, and 51% say it will continue to increase.

Google engineer caught stealing AI tech secrets for Chinese firms
2024-03-07 14:56

The U.S. Department of Justice has announced the unsealing of an indictment against Linwei Ding, 38, a former software engineer at Google, suspected of stealing Google AI trade secrets for Chinese companies. The allegedly stolen trade secrets involve crucial technology underpinning Google's advanced supercomputing data centers, which are essential for training and hosting large AI models capable of processing nuanced language and generating intelligent responses.

Japan orders local giants LINE and NAVER to disentangle their tech stacks
2024-03-06 03:29

Japan's government has ordered local tech giants LINE and NAVER to disentangle their tech stacks, after a data breach saw over 510,000 users' data exposed. LINE is a messaging app created by an offshoot of South Korea's NAVER - a Google-like web giant.

Sandvine put on America's export no-fly list after Egypt used network tech for spying
2024-02-27 20:22

The US Commerce Department has blacklisted Sandvine for selling its networking monitoring technology to Egypt, where the Feds say the gear was used to spy on political and human-rights activists. Chengdu made the naughty list for apparently acquiring and attempting to acquire US goods on behalf of China's University of Electronic Science and Technology, which was already on the Entity List.

Miscreants turn to ad tech to measure malware metrics
2024-02-15 08:27

Cyber baddies have turned to ad networks to measure malware deployment and to avoid detection, according to HP Wolf Security. The security group's Q4 2024 Threat Insights Report finds criminals have adopted ad tech tools to make their social engineering attacks more effective.

As-a-Service tools empower criminals with limited tech skills
2024-02-08 04:00

As-a-service attacks continue to dominate the threat landscape, with Malware-as-a-Service and Ransomware-as-a-Service tools making up the majority of malicious tools in use by attackers, according to Darktrace. As-a-Service tools can provide attackers with everything from pre-made malware to templates for phishing emails, payment processing systems and even helplines to enable criminals to mount attacks with limited technical knowledge.

Global Coalition and Tech Giants Unite Against Commercial Spyware Abuse
2024-02-07 09:45

A coalition of dozens of countries, including France, the U.K., and the U.S., along with tech companies such as Google, MDSec, Meta, and Microsoft, have signed a joint agreement to curb the abuse...

Researchers discover exposed API secrets, impacting major tech tokens
2024-02-05 05:30

The exposed secrets include hundreds of Stripe, GitHub/GitLab tokens, RSA private keys, OpenAI keys, AWS tokens, Twitch secret keys, cryptocurrency exchange keys, X tokens, and Slack and Discord webhooks. This approach shows how and where API secret keys and tokens are exposed in real-world settings, not only in code repositories.

Crowdsourced security is not just for tech companies anymore
2024-02-02 05:00

There is a misconception that only software and technology companies leverage crowdsourced security. Companies across various sectors are increasingly adopting crowdsourced security, as reported by Bugcrowd.