Huawei Zero-Day Attack Causes Nationwide Telecom Outage
A previously unknown vulnerability in Huawei enterprise router software was exploited in a zero-day attack, causing a nationwide telecoms outage in Luxembourg last year.
The Cybersecurity and Infrastructure Security Agency's new ANCHOR-CI framework aims to improve collaboration between the government and private companies to protect critical infrastructure from cyber threats and natural disasters.
A previously unknown vulnerability in Huawei enterprise router software was exploited in a zero-day attack, causing a nationwide telecoms outage in Luxembourg last year.
Microsoft has disrupted a malware-signing-as-a-service operation that abused its Artifact Signing platform to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals.
UK regulator Ofcom will require tech firms to remove non-consensual intimate images and curb deepfakes, with new rules taking effect this autumn.
Mini Shai-Hulud malware has compromised hundreds of npm packages, with the threat actor TeamPCP embedding a self-replicating worm that installs persistent backdoors and steals sensitive data.
Cyber resilience is crucial for business continuity, as it helps organizations manage risk and ensure operations continue uninterrupted despite disruptions.
Experts warn that connecting financial accounts to AI chatbots like ChatGPT poses significant privacy risks, despite promises of secure data handling.
Security teams can manage shadow AI tools by building a full picture of what's running, writing a policy that works with employees, and creating a fast lane for new tool requests.
New AI models like Anthropic's Mythos and OpenAI's Daybreak are generating a flood of vulnerability reports, but many are low-quality submissions without proof of concept.
A CISA contractor leaked credentials to highly privileged AWS GovCloud accounts and internal CISA systems on a public GitHub repository.