What to do with a cloud intrusion toolkit in 2023? Slap a chat assistant on it, duh

November 9, 2023 at 02:08AM A cybersecurity tool called Predator AI has been discovered by infosec researchers. It can be used to compromise poorly secured cloud services and web apps, and also includes a partially functional chat-bot assistant. While it is supposedly intended for educational purposes, it has the potential to be used maliciously. The … Read more

Okta breach affected 134 orgs, ‘or less than 1%’ of customers, company admits

November 6, 2023 at 09:11AM Okta has confirmed that its October breach resulted in the compromise of files belonging to 134 customers, which is less than 1 percent of their customer base. Among the affected customers are 1Password, BeyondTrust, and Cloudflare. The breach involved an employee signing into their personal Google account on a company-managed … Read more

Microsoft opens early access to AI assistant for infosec, Security Copilot

October 23, 2023 at 09:08AM Microsoft is launching the early access program for Security Copilot, an AI cybersecurity tool embedded in the Microsoft 365 Defender XDR platform. The tool aims to save time for security teams by providing step-by-step instructions on managing incidents and offering insights to upskill existing staff. It can generate natural language … Read more

Regulator, insurers and customers all coming for Progress after MOVEit breach

October 15, 2023 at 11:00PM The US Securities and Exchange Commission (SEC) is investigating Progress Software’s MOVEit file transfer software following a data breach. Progress admitted to receiving a subpoena from the SEC and stated that it is facing multiple class-action lawsuits and other litigation over the breach. Progress also disclosed that it has received … Read more