generalnews.media
All World Business Technology Science Health Sports Entertainment Security
311 stories
Exclusive

CrashStealer macOS Malware Bypasses Gatekeeper with Notarized Dropper

CrashStealer, a new macOS malware, uses a notarized dropper to evade Apple's Gatekeeper security checks. The malware targets macOS users by exploiting the trust granted to notarized applications. This discovery underscores a critical vulnerability in Apple's verification process, potentially allowing malicious software to run undetected.

Exclusive

Lessons from CISA's GitHub Leak on Sensitive Data Exposure

CISA inadvertently exposed sensitive information on a public GitHub repository, highlighting risks in code management. The leak included system details and credentials, prompting a review of security protocols. This incident underscores the need for rigorous oversight to prevent data breaches in government agencies.

Exclusive

MemGhost Attack Plants False Memories in AI Agents with One Email

Researchers have identified the MemGhost attack, which can implant persistent false memories into AI agents through a single malicious email. This manipulation allows attackers to control an agent's future behavior without detection, posing serious risks for trust and security in AI-assisted systems.

Exclusive

Forg365 PhaaS Targets Microsoft 365 via Device Code and AitM Session Theft

A new phishing-as-a-service platform called Forg365 is targeting Microsoft 365 users by abusing the device code authentication flow and performing adversary-in-the-middle session theft. This technique bypasses multi-factor authentication and steals session tokens, enabling persistent access to accounts. The emergence of such a tool heightens risks for organizations reliant on Microsoft 365, requiring enhanced monitoring and user training.

Exclusive

Meta Files Patent for AI That Listens All Day and Tracks Emotions

Meta has filed a patent for an AI system that can continuously listen to audio and monitor a user's emotional state throughout the day. The technology aims to detect sentiment through voice analysis, potentially for targeted advertising or personalized recommendations. This raises significant privacy concerns about constant surveillance and data collection.

Exclusive

Combining Autonomous AI with Analyst Copilots in the SOC

This article discusses applying the "thinking fast and slow" concept to security operations, advocating for combining autonomous AI for rapid threat detection with analyst copilots for deeper investigation. It argues this hybrid approach improves SOC efficiency and decision-making by balancing speed with human oversight.

Exclusive

Misconfigured Server Exposes Three Phishing Operations Targeting Microsoft 365

Researchers discovered a misconfigured server that revealed three separate phishing operations using the Evilginx framework, targeting Microsoft 365 credentials. The attackers employed reverse proxy techniques to bypass multi-factor authentication. The exposure highlights the persistent threat of advanced phishing campaigns against enterprise cloud services.

Exclusive

Joomla iCagenda and Balbooa Forms Zero-Day Flaws Exploited

Security researchers report that two Joomla extensions, iCagenda and Balbooa Forms, contain critical flaws that are being actively exploited as zero-days. The vulnerabilities allow attackers to compromise websites running these components before patches are available. Joomla site administrators should urgently review their installed extensions and apply any available fixes.

Exclusive

Squid Proxy Vulnerability Called "Squidbleed" Discovered

Security researchers have identified a new vulnerability in the Squid web proxy cache, dubbed "Squidbleed". This flaw could potentially allow attackers to leak sensitive data or disrupt proxy services. The finding highlights ongoing security challenges in widely used network infrastructure software.