ZDI shames Microsoft for – yet another – coordinated vulnerability disclosure snafu

July 15, 2024 at 11:10AM Microsoft released a patch to fix a zero-day exploit, CVE-2024-38112, in its proprietary browser engine for Internet Explorer, without crediting Trend Micro’s Zero Day Initiative (ZDI) which had reported the vulnerability to Redmond in May. ZDI contends that the flaw is a critical remote code execution issue, while Microsoft deems … Read more

UK cyber-boss slams China’s bug-hoarding laws

July 14, 2024 at 08:12PM The interim CEO of the UK’s National Cyber Security Centre (NCSC) criticizes China’s cyber activities, highlighting concerns about the Beijing-backed Volt Typhoon gang’s attacks and China’s approach to vulnerability reporting. AWS China denies rumors of business trouble and declares good growth momentum. Japanese scientists believe they’ve spotted remnants of a … Read more

Big Tech’s eventual response to my LLM-crasher bug report was dire

July 10, 2024 at 03:29AM Columnist discovered a bug after reporting it in The Register, receiving an influx of emails requesting the bug’s details. Despite brushing off these requests, they engaged with genuine inquiries. After Microsoft initially dismissed the bug, they reopened their investigation. The bug’s impact on AI chatbots remains unclear, highlighting the lack … Read more