Eve's dropping in on Alice and Bob
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices.
The post The AI hacking apocalypse is not inevitable appeared first on CyberScoop.
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]
Two reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.
Several vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service or cache poisoning. For the stable distribution (trixie), these problems have been fixed in version 1:9.20.29-1~deb13u1. We recommend that you upgrade your bind9 packages.
Des pirates ont compromis le dépôt itorrents.org pour diffuser MovieReaper, un malware déguisé en films comme The Odyssey. Kaspersky présente cette menace.
Le post iTorrents.org compromis pour distribuer un malware Windows à la place des films a été publié sur IT-Connect.
It was discovered that incorrect state cookie parsing in mod_auth_openidc, an OpenID Certified authentication and authorisation module for the Apache HTTP server that implements the OpenID Connect Relying Party functionality, could result in denial of service. For the stable distribution (trixie), t...
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.
The Security Management Server is the system that controls firewall policy and administrator access. Check Point has...
Cyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.S. Coast Guard personnel and FBI agents boarded two Texas‑bound energy tankers last month after cyberattacks hit the vessels while they were underway, accord...
In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.
Beware the SparroWocky, my son! The backdoor that bites…
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.
This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying...
L'autorité sud-coréenne de protection des données, la Commission de protection des informations personnelles (PIPC), a organisé une réunion du "Forum sur l'avenir des informations personnelles 2026" pour discuter de l'évolution du régime des transferts de données personnelles hors du pays.La quatriè...
Le président de l'Autorité polonaise de protection des données personnelles (UODO) a affirmé, lors d'une conférence sur les technologies de rupture, que les réglementations en matière de protection des données ne doivent pas être perçues comme un obstacle mais comme un levier de compétitivité.En rép...
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
L'autorité portugaise de protection des données, la Commission Nationale de Protection des Données (CNPD), a lancé un canal prioritaire pour le traitement des plaintes relatives aux données personnelles des enfants et des jeunes.Disponible depuis le 15 septembre 2026, ce canal permet de traiter en u...
Les représentants des autorités de protection des données d'Europe centrale ont été reçus par la présidente de la Slovénie pour discuter des enjeux actuels en matière de protection des données.Lors de la réunion des autorités de protection des données d'Europe centrale, tenue à Ljubljana du 14 au 16...
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.
The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek.
Le Contrôleur européen de la protection des données (CEPD) a publié une analyse technologique sur le calcul multipartite sécurisé (CMS), une technique cryptographique permettant la collaboration sur des données sans en révéler le contenu.Cette méthode, considérée comme une technologie de renforcemen...
Le président de l'Autorité polonaise de protection des données personnelles (UODO) a indiqué au ministère des Affaires étrangères que l'exécution d'un arrêt du Tribunal de justice de l'Union européenne (TJUE) concernant les règles antidopage nécessite une modification du droit polonais.Dans sa corre...