Inside Baseball: The Red Sox Cloud Security Game

June 6, 2024 at 09:32AM The Boston Red Sox are making comprehensive cybersecurity efforts by adopting a software-as-a-service model and embracing IoT at Fenway Park. Despite limited resources, support from Major League Baseball helps the team punch above its weight in cyber defense. Their security apparatus is dynamic and constantly evolving to protect IP, ensure … Read more

Trend Micro, Nvidia Partner to Secure AI Data Centers

June 6, 2024 at 08:39AM Trend Micro and Nvidia are teaming up to provide cybersecurity tools for private AI clouds, leveraging Nvidia’s GPUs to enhance data privacy, real-time analysis, and threat mitigation. By using GPUs, Trend Micro’s AI-powered security tools will offer faster threat detection and protection, appealing to companies with a strong focus on … Read more

Microsoft Research chief scientist has no issue with Windows Recall

June 6, 2024 at 03:30AM Jaime Teevan, chief scientist at Microsoft Research, discussed the data privacy implications of Microsoft’s Recall tool at the Institute for Human-Centered Artificial Intelligence’s conference. She emphasized the importance of rethinking data usage in the context of generative AI. Teevan reassured that Recall stores data locally and prioritizes data protection, despite … Read more

Hypr Raises $30 Million for Passwordless Authentication

June 5, 2024 at 09:30AM Hypr, a passwordless authentication provider, received $30 million from Silver Lake Waterman, bringing the total funding to over $127 million. The New York-based company offers a passwordless authentication solution supporting secure logins on mobile and web. The recent investment will be used to develop technologies to combat generative AI-driven credential-based … Read more

Celebrity TikTok Accounts Compromised Using Zero-Click Attack via DMs

June 5, 2024 at 03:09AM TikTok acknowledged a zero-click account takeover campaign by threat actors, impacting high-profile accounts on the platform. The company has taken preventive measures and is working with affected users. Previous security issues were also highlighted, including a flaw enabling data extraction and a one-click exploit. Concerns about TikTok’s Chinese roots further … Read more

Ockam and Redpanda Partner to Launch Zero-Trust Streaming Data Platform

June 3, 2024 at 05:17PM Ockam and Redpanda have collaborated to launch Redpanda Connect with Ockam, the first zero-trust streaming data platform. This partnership aims to simplify secure streaming data connections, empowering developers to build and scale distributed systems effortlessly. The platform provides end-to-end encrypted streaming pipelines, ensuring secure data transmission and unlocking new high-value … Read more

Cox fixed an API auth bypass exposing millions of modems to attacks

June 3, 2024 at 05:12PM Cox Communications fixed an authorization bypass vulnerability discovered by bug bounty hunter Sam Curry, preventing remote attackers from resetting modem settings and stealing sensitive customer information. The largest private broadband company in the U.S., Cox provides services to nearly seven million homes and businesses across over 30 states. The company … Read more

Data Privacy in the Age of GenAI

May 31, 2024 at 10:07AM The American Privacy Rights Act of 2024 (APRA) is a comprehensive national legislation aiming to hold organizations accountable for privacy. It includes requirements like CEO-signed compliance certification, biennial audits, and publishing privacy policies. However, concerns remain about transparency, ethics, and the impact of GenAI models, indicating the need for further … Read more

In Other News: Apple WPS Surveillance, Canadian Gov Wants Backdoors, NIST AI Program

May 31, 2024 at 09:36AM SecurityWeek compiles important cybersecurity news, highlighting impactful stories. Recent articles cover threats like abusing BitLocker for ransomware, critical data exposure in India, AI-as-a-service vulnerability, and surveillance using Wi-Fi-based positioning systems. Additionally, a memorandum of understanding aims to boost electric sector cybersecurity, while cyberspying targets political entities in multiple regions. Based … Read more

BBC Data Breach Impacts 25,000 Employees

May 31, 2024 at 04:49AM The BBC has informed current and former employees about a data breach involving files storing information on BBC Pension Scheme members. Information including names, National Insurance numbers, addresses, and dates of birth was accessed, impacting over 25,000 individuals. The BBC stated there is no misuse evidence and no impact on … Read more