Hackers are using Middle East phone and internet networks more often to run big command-and-control systems. The results show a change from temporary signs to tracking at the infrastructure level, helping defenders find ongoing patterns in cyber attacks instead of just responding to changing signs of trouble. The data shows …
Read More »Microsoft’s MDASH VS Anthropic’s Mythos VS OpenAI’s Daybreak
The newly launched of Microsoft MDASH, OpenAI Daybreak, and Anthropic Mythos shows a big change in cybersecurity. These tools go beyond basic chat functions by using groups of special models to find, discuss, and fix serious problems in important systems. MDASH and Daybreak aim to make security stronger during development, …
Read More »Google Identifies First AI-Generated Zero-Day Exploit
Google detects for the first time a zero-day exploit which is thought to be developed using artificial intelligence. The company shared a new report on Monday. It gives a summary of its findings on how AI is used in cyber threats. This information comes from recent data collected by Gemini, …
Read More »AWS says data center overheating in North Virginia disrupts services
Amazon’s cloud unit said on Thursday (May 7) it was actively working to restore temperatures to normal levels at a data center in North Virginia after overheating disrupted some services, though progress has been slower than anticipated. Amazon Web Services said it had made “incremental progress” in restoring cooling systems, …
Read More »
KidsProtect
From $60 to Full Control: The Spyware Anyone Can Buy and Rebrand
A new Android spyware tool is for sale on the internet. It has more risks than just its tracking features. For a price, anyone can buy it, add their name and logo, and sell it as their own. The tool is named KidsProtect. It looks like a parent monitoring app, …
Read More »FBI and CISA outline Zero Trust Principles Implementation Guide for OT networks
FBI and CISA, along with the Department of Energy and defense partners, released a joint report. Called “Adapting Zero Trust Principles to Operational Technology,” this guide helps critical infrastructure operators protect industrial systems from today’s cyber threats. The new federal guidance strongly urges organizations to adopt an “assume breach” philosophy. This …
Read More »OpenAI unveils 5-Point Action Plan For Strengthening Cyber Defense
OpenAI has released a detailed plan for cybersecurity called “Cybersecurity in the Intelligence Age: An Action Plan for Democratizing AI-Powered Cyber Defense.” It describes a five-part strategy to give trusted defenders better AI tools and stop bad use. Artificial intelligence is changing the way we protect against cyber threats. It’s …
Read More »TP-Link Routers Affected by CVE-2023-33538 Mirai
Hackers are looking for weak TP-Link home routers to spread Mirai-like malware, taking advantage of CVE-2023-33538 in a new round of automated attacks. Current exploit attempts have some technical problems, but researchers say the bug is real and can be dangerous when used with default passwords and outdated firmware. Network …
Read More »Recently leaked Windows 0-Day flaw exploited in attacks
Threat actors are exploiting 3 new Windows security flaws in their attacks to get SYSTEM or higher administrator access. Since the beginning of the month, a security expert called “Chaotic Eclipse” or “Nightmare-Eclipse” has shared proof-of-concept exploit code for all three security problems. Two of the flaws, called BlueHammer and RedSun, …
Read More »US alerts banks on cyber risks from Anthropic’s new AI model
Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell called for an important meeting with bank CEOs this week to talk about the cyber dangers from Anthropic’s new AI model. Bessent and Powell met with the group on Tuesday to talk about the risks linked to Anthropic’s Mythos and …
Read More »
InfoSecBulletin Cybersecurity for mankind