Fri.Dec 27, 2024

article thumbnail

The Top 25 Security Predictions for 2025 (Part 2)

Lohrman on Security

Welcome to the second installment of this comprehensive annual look at global cybersecurity industry predictions, forecasts, trends and outlook reports from the top security industry vendors, technology magazines, expert thought leaders and more.

article thumbnail

Palo Alto Networks fixed a high-severity PAN-OS flaw

Security Affairs

Palo Alto Networks addressed a high-severity PAN-OS flaw that could trigger denial-of-service (DoS) on vulnerable devices. Palo Alto Networks addressed a high-severity flaw, tracked as CVE-2024-3393 (CVSS score: 8.7), in PAN-OS software that could cause a denial-of-service (DoS) condition. An unauthenticated attacker can exploit this vulnerability to reboot the firewall by sending a malicious packet through its data plane.

DNS 112
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Best of 2024: AT&T Says 110M Customers’ Data Leaked — Yep, it’s Snowflake Again

Security Boulevard

Shouldve used MFA: $T loses yet more customer datathis time, from almost all of them. The post Best of 2024: AT&T Says 110M Customers Data Leaked Yep, its Snowflake Again appeared first on Security Boulevard.

article thumbnail

2024 in AI: It’s changed the world, but it’s not all good

Malwarebytes

A popular saying is: To err is human, but to really foul things up you need a computer. Even though the saying is older than you might think, it did not come about earlier than the concept of artificial intelligence (AI). And as long as we have been waiting for AI technology to become commonplace, if AI has taught us one thing this year, then its that when humans and AI cooperate, amazing things can happen.

Scams 114
article thumbnail

Why Giant Content Libraries Do Nothing for Your Employees’ Cyber Resilience

Many cybersecurity awareness platforms offer massive content libraries, yet they fail to enhance employees’ cyber resilience. Without structured, engaging, and personalized training, employees struggle to retain and apply key cybersecurity principles. Phished.io explains why organizations should focus on interactive, scenario-based learning rather than overwhelming employees with excessive content.

article thumbnail

Casino Players Using Hidden Cameras for Cheating

Schneier on Security

The basic strategy is to place a device with a hidden camera in a position to capture normally hidden card values, which are interpreted by an accomplice off-site and fed back to the player via a hidden microphone. Miniaturization is making these devices harder to detect. Presumably AI will soon obviate the need for an accomplice.

276
276
article thumbnail

North Korea actors use OtterCookie malware in Contagious Interview campaign

Security Affairs

North Korea-linked threat actors are using the OtterCookie backdoor to target software developers with fake job offers. North Korea-linked threat actors were spotted using new malware called OtterCookie as part of the Contagious Interview campaign that targets software developer community with fake job offers. The Contagious Interview campaign was first detailed by Palo Alto Networks researchers in November 2023, however it has been active since at least December 2022.

Malware 87

LifeWorks

More Trending

article thumbnail

Experts warn of a surge in activity associated FICORA and Kaiten botnets

Security Affairs

FortiGuard Labs observed increased activity from two botnets, the Mirai variant “FICORA” and the Kaiten variant “CAPSAICIN” FortiGuard Labs researchers observed a surge in activity associated with two botnets, the Mirai variant “ FICORA ” and the Kaiten variant “CAPSAICIN,” in late 2024. Both botnets target vulnerabilities in D-Link devices, particularly through the HNAP interface, allowing remote command execution.

article thumbnail

Choosing the Right Cyber Risk Management Solution: RFI vs. RFP and Beyond

Security Boulevard

Selecting a cyber risk management solution is a critical decision for any organization. The process requires careful consideration of your needs, how a platform can meet them, and how the solution supports legacy GRC functions. This post will delve into the key elements for a successful selection process, including evaluating product capabilities, service levels, and the overall vendor relationship.

article thumbnail

Brazilian citizen charged for threatening to release data stolen from a company in 2020

Security Affairs

A Brazilian citizen faces U.S. charges for allegedly threatening to release data stolen from a company in a March 2020 security breach. The U.S. government has charged the Brazilian citizen Junior Barros De Oliveira, 29, with allegedly threatening to release data stolen from a company during a March 2020 security breach. De Oliveira was charged with four counts of extortionate threats involving information obtained from protected computers in violation of Title 18, United States Code, Section 10

article thumbnail

15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials

The Hacker News

A high-severity flaw impacting select Four-Faith routers has come under active exploitation in the wild, according to new findings from VulnCheck. The vulnerability, tracked as CVE-2024-12856 (CVSS score: 7.2), has been described as an operating system (OS) command injection bug affecting router models F3x24 and F3x36.

136
136
article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

15 ways AI saved me time at work in 2024 - and how I plan to use it in 2025

Zero Day

In 2024, AI became truly helpful. Here are 15 clever ways I integrated it into my workflow for quicker, better results - and how you can too.

130
130
article thumbnail

North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign

The Hacker News

North Korean threat actors behind the ongoing Contagious Interview campaign have been observed dropping a new JavaScript malware called OtterCookie.

article thumbnail

What is the Process of ISO 27001 Certification?

Security Boulevard

In 2025, the cost of cyberattacks will reach $10.5 trillion globally. The projected growth rate is 15% every year. While the cost of attack keeps increasing, a breach is now identified in 194 days on average. It takes 64 days to contain a breach and 88 days on average to resolve an attack facilitated through [] The post What is the Process of ISO 27001 Certification?

Risk 52
article thumbnail

Cloud Atlas Deploys VBCloud Malware: Over 80% of Targets Found in Russia

The Hacker News

The threat actor known as Cloud Atlas has been observed using a previously undocumented malware called VBCloud as part of its cyber attack campaigns targeting "several dozen users" in 2024.

Malware 116
article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

Why ethics is becoming AI's biggest challenge

Zero Day

Teams designing AI should include linguistics and philosophy experts, parents, young people, everyday people with different life experiences from different socio-economic backgrounds.

111
111
article thumbnail

DEF CON 32 – Using AI Computer Vision In Your OSINT Data Analysis

Security Boulevard

Authors/Presenters: Mike Raggo Our sincere appreciation to DEF CON , and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conferences events located at the Las Vegas Convention Center ; and via the organizations YouTube channel. Permalink The post DEF CON 32 – Using AI Computer Vision In Your OSINT Data Analysis appeared first on Security Boulevard.

article thumbnail

AI isn't the next big thing - here's what is

Zero Day

Here's what you should be focusing on instead.

111
111
article thumbnail

The Paper Passport Is Dying

WIRED Threat Level

Smartphones and face recognition are being combined to create new digital travel documents. The paper passports days are numbereddespite new privacy risks.

Risk 89
article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

AI data centers are becoming 'mind-blowingly large'

Zero Day

Clusters of GPU chips in coming years will have to connect over distances longer than a mile, says the CEO of this fiber-optics firm.

110
110
article thumbnail

Xiaomi Limits HyperOS Bootloader Unlocking to One Device Per Account

Penetration Testing

Xiaomi is redefining its Bootloader unlocking policy with the introduction of new rules effective January 1, 2025, coinciding with the rollout of its HyperOS. These updates aim to enhance security... The post Xiaomi Limits HyperOS Bootloader Unlocking to One Device Per Account appeared first on Cybersecurity News.

article thumbnail

OpenAI's o3 isn't AGI yet but it just did something no other AI has done

Zero Day

The new AI model 'is doing something completely different from the GPT series.

108
108
article thumbnail

eSIMs: The Future of Connectivity, But Are Consumers Ready?

Penetration Testing

A recent research report by Counterpoint Research reveals that, despite the long-standing promotion of eSIM technology and the availability of eSIM services from numerous telecom providers, a significant portion of... The post eSIMs: The Future of Connectivity, But Are Consumers Ready? appeared first on Cybersecurity News.

article thumbnail

The Tumultuous IT Landscape Is Making Hiring More Difficult

After a year of sporadic hiring and uncertain investment areas, tech leaders are scrambling to figure out what’s next. This whitepaper reveals how tech leaders are hiring and investing for the future. Download today to learn more!

article thumbnail

Is free Apple TV+ on the way? The streaming service is teasing something for next weekend

Zero Day

You might have the chance to test-drive Apple's streaming service for free soon.

105
105
article thumbnail

Microsoft Announces Critical Change to.NET Installer Distribution Domains

Penetration Testing

Microsofts.NET team, led by Product Manager Richard Lander, has announced a major change in how.NET installers and archives are distributed. This unexpected update, necessitated by the imminent shutdown... The post Microsoft Announces Critical Change to.NET Installer Distribution Domains appeared first on Cybersecurity News.

article thumbnail

Why I recommend this Windows tablet for work travel over the iPad and Lenovo Yoga

Zero Day

Microsoft's 11th-edition Surface Pro delivers with a brilliant OLED display and a snappy processor.

105
105
article thumbnail

This month in security with Tony Anscombe – December 2024 edition

We Live Security

From attacks leveraging new new zero-day exploits to a major law enforcement crackdown, December 2024 was packed with impactful cybersecurity news

article thumbnail

The Cloud Development Environment Adoption Report

Cloud Development Environments (CDEs) are changing how software teams work by moving development to the cloud. Our Cloud Development Environment Adoption Report gathers insights from 223 developers and business leaders, uncovering key trends in CDE adoption. With 66% of large organizations already using CDEs, these platforms are quickly becoming essential to modern development practices.

article thumbnail

Does your old PC need a speed boost? This thumb-sized accessory did the trick for me

Zero Day

If you're dealing with a laggy PC, the PNY 1TB storage drive can speed up your system with added storage.

105
105
article thumbnail

Detection Engineering: A Case Study

Security Boulevard

In this blog post, we will explore the intricate world of detection engineering. Well start by examining the inputs and outputs of detection engineering, and then well illustrate the detection engineering lifecycle. The post Detection Engineering: A Case Study appeared first on Security Boulevard.

article thumbnail

How to buy Casio's tiny digital watch for your finger in the US

Zero Day

If you like your watches extra little and not-so-smart, Casio might have something for you.

104
104
article thumbnail

Cybersecurity Snapshot: What Looms on Cyberland’s Horizon? Here’s What Tenable Experts Predict for 2025

Security Boulevard

Wondering what cybersecurity trends will have the most impact in 2025? Check out six predictions from Tenable experts about cyber issues that should be on your radar screen in the new year including AI security, data protection, cloud security and much more! 1 - Data protection will become even more critical as AI usage surges Because AI tools rely on vast amounts of data, widespread AI adoption will lead to the exponential growth of data volumes.

article thumbnail

Bringing the Cybersecurity Imperative Into Focus

Tech leaders today are facing shrinking budgets and investment concerns. This whitepaper provides insights from over 1,000 tech leaders on how to stay secure and attract top cybersecurity talent, all while doing more with less. Download today to learn more!