Security News

AIs Discovering Vulnerabilities
2024-11-05 12:08

I’ve been writing about the possibility of AIs automatically discovering code vulnerabilities since at least 2018. This is an ongoing area of research: AIs doing source code scanning, AIs finding...

Researchers Uncover Vulnerabilities in Open-Source AI and ML Models
2024-10-29 13:00

A little over three dozen security vulnerabilities have been disclosed in various open-source artificial intelligence (AI) and machine learning (ML) models, some of which could lead to remote code...

Exploited: Cisco, SharePoint, Chrome vulnerabilities
2024-10-25 10:25

Threat actors have been leveraging zero and n-day vulnerabilities in Cisco security appliances (CVE-2024-20481), Microsoft Sharepoint (CVE-2024-38094), and Google’s Chrome browser (CVE-2024-4947)....

Threat Actors Are Exploiting Vulnerabilities Faster Than Ever
2024-10-23 16:15

It only takes five days on average for attackers to exploit a vulnerability, according to a new report.

The Rise of Zero-Day Vulnerabilities: Why Traditional Security Solutions Fall Short
2024-10-15 11:00

In recent years, the number and sophistication of zero-day vulnerabilities have surged, posing a critical threat to organizations of all sizes. A zero-day vulnerability is a security flaw in...

US and UK govts warn: Russia scanning for your unpatched vulnerabilities
2024-10-12 03:05

Also, phishing's easier over the phone, and your F5 cookies might be unencrypted, and more in brief If you need an excuse to improve your patching habits, a joint advisory from the US and UK...

Patch Tuesday: Internet Explorer Vulnerabilities Still Pose a Problem
2024-10-10 10:10

Patch Tuesday brings patches for hundreds of vulnerabilities. Plus, Apple makes sure Sequoia plays nice with third-party security tools.

Researchers Uncover Major Security Vulnerabilities in Industrial MMS Protocol Libraries
2024-10-09 15:33

Details have emerged about multiple security vulnerabilities in two implementations of the Manufacturing Message Specification (MMS) protocol that, if successfully exploited, could have severe...

Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited
2024-10-08 16:38

Ivanti has warned that three new security vulnerabilities impacting its Cloud Service Appliance (CSA) have come under active exploitation in the wild. The zero-day flaws are being weaponized in...

CUPS vulnerabilities could be abused for DDoS attacks
2024-10-03 13:10

While the Common UNIX Printing System (CUPS) vulnerabilities recently disclosed by researcher Simone “evilsocket” Margaritelli are not easily exploited for remote command execution on vulnerable...