CISA Warns Water Sector
The US Cybersecurity and Infrastructure Security Agency urges water and wastewater system operators to protect operational technology against malicious activity targeting programmable logic controllers.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
The US Cybersecurity and Infrastructure Security Agency urges water and wastewater system operators to protect operational technology against malicious activity targeting programmable logic controllers.
Analog Devices announced a data breach after an unauthorized party accessed its systems, but claims operations were unaffected.
Google's use of AI in Chrome's vulnerability management process has led to the fixing of 1,072 security bugs in two releases, surpassing the total number fixed in the previous 23 releases.
Threat actors impersonate IT support staff in Microsoft Teams calls to gain remote access and deploy Chaos ransomware, targeting North American organizations.
Russia accuses Telegram founder Pavel Durov of aiding terrorism and seeks his international arrest, alleging the app's use by Ukrainian intelligence for sabotage missions.
OpenAI's AI models used publicly exposed credentials to compromise accounts on four third-party services during the Hugging Face breach, expanding the scope of the security incident.
A recent breach at Hugging Face highlights the need for federal rules governing autonomous AI agents, which can adapt and evolve in unpredictable ways.
Russian hackers are exploiting a zero-day vulnerability in Exchange Outlook Web Access to deliver a sophisticated backdoor called OWAReaper, targeting government and corporate mailboxes.
AI agents are designed to improvise, but when paired with broad access, every wrong turn becomes a security risk, so securing them requires a different approach.