Apple Patches Beats Eavesdropping Flaw
Apple released a firmware update for Beats Studio Buds, patching a critical vulnerability that allowed nearby attackers to listen via the microphone on unpaired devices.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
Apple released a firmware update for Beats Studio Buds, patching a critical vulnerability that allowed nearby attackers to listen via the microphone on unpaired devices.
A Bulgaria-based surveillance tech firm sold products to countries known for repressing citizens, allowing governments to snoop on conversations and monitor phones' locations and web browsing.
John Edwards, the UK's Information Commissioner, has resigned due to an investigation into his conduct, citing 'inappropriate humour' as the reason for his departure.
Most organizations don't treat AI agents as identities, despite their ability to access critical business services and create security risks, with 65% of organizations experiencing a security incident involving an AI agent in the past year.
The NO FAKES Act, approved by the Senate Judiciary Committee, seeks to prevent unauthorized deepfakes of American artists, performers, and public figures, but raises concerns about free speech and parody.
CISA warns Fortinet users to secure devices after the FortiBleed leak exposed nearly 74,000 firewall and VPN credentials, which have been used by threat actors to target government and private-sector organizations worldwide.
The fundamental design of TCP/IP networks poses significant security challenges, with 68% of initial access attacks not relying on technical vulnerability exploitation.
Sen. Mark Warner warns of widespread cuts and staffing gaps at the Cybersecurity and Infrastructure Security Agency, citing a dangerous underestimation of national threats.
Accenture is acquiring a majority stake in Dragos and fully acquiring runZero and NetRise in a $4.1 billion OT cybersecurity push.