G7 Agencies Release AI SBOM Guidance
A group of international government agencies has released guidance on what an artificial intelligence 'ingredients list' tool should include to make AI more secure.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
A group of international government agencies has released guidance on what an artificial intelligence 'ingredients list' tool should include to make AI more secure.
The 'mini Shai-Hulud' malware campaign has infected hundreds of open-source software packages, embedding credential-stealing code into development tools downloaded millions of times a week.
A House Energy and Commerce Committee lawmaker is investigating whether 25 food retailers use surveillance pricing to charge customers based on their personal data.
A test of Anthropic's Claude Mythos model found only one low-severity vulnerability in the open source data transfer tool curl, casting doubt on the AI company's claims.
Hundreds of npm and PyPI packages have been compromised in a Shai-Hulud supply-chain campaign, delivering credential-stealing malware to developers.
Google has identified a zero-day exploit believed to have been developed using artificial intelligence, designed to bypass two-factor authentication on an open source web-based system administration tool.
Google researchers found a zero-day exploit likely generated using AI, targeting a popular open-source web administration tool to bypass two-factor authentication protection.
South Staffordshire Water was fined £963,900 for failing to discover hackers hidden inside its computer network for nearly two years, resulting in the personal data of 633,887 customers and employees being published.
Changing passwords doesn't immediately invalidate old credentials across every authentication path in Active Directory and hybrid Entra ID environments, leaving a window for attackers to maintain access.