generalnews.media
All World Business Technology Science Health Sports Entertainment Security
333 stories
Exclusive

Cybersecurity Roundup: AI Hacking, Chrome Flaws, SonicWall Attacks, DNS Hijacking

A weekly digest covers over 25 major cybersecurity stories, including AI-powered hacking techniques, 370 new Chrome vulnerabilities, active SonicWall attacks, and DNS hijacking incidents. The compilation highlights the escalating breadth and sophistication of current cyber threats, urging enhanced defenses across industries.

Exclusive

CISA Guide Aids Federal Agencies in Secure Open Source Software Use

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a guide to help federal agencies securely and effectively use open source software. The guide outlines best practices for risk management, compliance, and integration into federal systems. This matters because open source software is increasingly critical to government operations, and its use requires robust security measures.

Exclusive

Network Emerges as Control Plane for AI Security

Security experts identify a shift where network infrastructure is taking on the role of a control plane for securing AI systems. This change centralizes policy enforcement and threat response for AI workloads. It matters because it introduces new architectural considerations and potential single points of failure for AI security.

Exclusive

Hackers Exploit AnySign4PC Via Compromised Korean Sites to Install Backdoors

Hackers are exploiting a vulnerability in the South Korean authentication software AnySign4PC through compromised Korean websites. The attacks silently install backdoors on users' systems without any prompts, bypassing typical security warnings. This matters because AnySign4PC is widely used in South Korea for banking and government services, putting millions at risk.

Exclusive

SilverFox Hits Japanese Manufacturer via BYOVD Chain and ValleyRAT Malware

The SilverFox threat actor group has targeted a Japanese manufacturer using a three-driver Bring Your Own Vulnerable Driver (BYOVD) chain to deploy ValleyRAT malware. This attack demonstrates advanced techniques to bypass security controls and infiltrate industrial networks. It highlights the growing risk of sophisticated cyberattacks on manufacturing supply chains.

Exclusive

FCC Blocks Foreign Robots, Power Inverters Over Cybersecurity Risks

The U.S. Federal Communications Commission (FCC) has banned the import and sale of new foreign-made robots and power inverters due to cybersecurity risks. The move targets devices that could be used for espionage or to disrupt critical infrastructure. This decision impacts supply chains and highlights growing concerns over foreign technology vulnerabilities.

Exclusive

Amazon links npm package hijack targeting debug and chalk to North Korean group

Amazon’s security team has attributed the hijacking of the popular npm packages 'debug' and 'chalk' to the North Korean threat actor Sapphire Sleet. The attackers compromised these widely used JavaScript libraries to inject malicious code, potentially affecting numerous applications. This incident highlights ongoing supply chain risks from state-sponsored hackers targeting open-source ecosystems.

security technology

Microsoft Plans Copilot Super App for This Year

Microsoft has confirmed that its Copilot AI assistant will evolve into a "super app" within this year. The integration aims to combine various capabilities into a single platform, potentially competing with other all-in-one apps. This matters because it signals Microsoft's strategy to embed AI deeply into its ecosystem.

Exclusive

Measuring AI Agents' Propensity to Act Against Their Goals

A new study examines methods to quantify the likelihood that AI agents will behave in ways contrary to their intended objectives, known as "going rogue." Researchers propose metrics to assess this risk before deployment. The work is important for developing safer autonomous systems and anticipating potential failures.