News Desk 2024: Hacking Microsoft Copilot Is Scary Easy

August 29, 2024 at 08:16AM Microsoft Copilot is gaining popularity as an artificial intelligence productivity assistant for large enterprises. However, Zenity’s CTO Michael Bargury warns about cybersecurity risks due to Copilot’s deep access into enterprise systems, making it vulnerable to malicious attacks. Bargury demonstrated how a single email can take over Copilot, despite acknowledging its … Read more

Microsoft removes FAT32 partition size limit in Windows 11

August 15, 2024 at 05:54PM Microsoft removed the 32GB size limit for FAT32 partitions in the latest Windows 11 Canary build, enabling a maximum size of 2TB. It looks like you’ve provided a snippet of meeting notes about Microsoft removing the 32GB size limit for FAT32 partitions in the latest Windows 11 Canary build. The … Read more

Cybersecurity’s Real Challenge Is Communication, Not Just Technology

August 14, 2024 at 10:06AM In business, strong relationships across teams are crucial, especially in cybersecurity. Communication remains a challenge for security teams, with automation emerging as a key enabler to facilitate cross-departmental collaboration. Building a shared culture of vigilance and open communication is essential for effective incident management and to strengthen the security posture … Read more

Progress Announces Conclusion of SEC Investigation into MOVEit

August 9, 2024 at 01:34PM Progress (Nasdaq: PRGS) announced that the Securities and Exchange Commission’s fact-finding investigation into the MOVEit vulnerability has concluded without enforcement action recommended at this time. Progress received a subpoena on Oct. 2, 2023, from the SEC. The company empowers organizations with AI-powered infrastructure software to achieve transformational success in a … Read more

Under-Resourced Maintainers Pose Risk to Africa’s Open Source Push

July 22, 2024 at 02:07AM The UN Open-Source Program Officers for Good 2024 conference discussed the benefits of open source software (OSS) in delivering affordable technology to underserved nations. Emphasizing the need for security in OSS, speakers highlighted the risk of under-resourced projects and ways to secure the open source ecosystem, including software bills of … Read more

Microsoft bigwig says the Feds catching Chinese spies in Exchange Online is the cloud working as intended

June 13, 2024 at 08:47PM During a US House committee hearing, Microsoft president Brad Smith faced scrutiny over security breaches involving China-backed spies. Smith admitted to the company’s errors and defended its operations in China, prompting further questioning from lawmakers about compliance with Beijing’s national security laws. Other topics included the role of Microsoft in … Read more

GitHub Paid Out Over $4 Million via Bug Bounty Program

June 12, 2024 at 08:06AM GitHub’s bug bounty program, established 10 years ago, has paid out over $4 million. In 2023, the program reached this milestone and saw its largest single reward of $75,000 for a vulnerability. The total payout exceeded $850,000 in 2023, with GitHub aiming to enhance payout processes and public disclosures in … Read more

Arm Warns of Actively Exploited Zero-Day Vulnerability in Mali GPU Drivers

June 11, 2024 at 03:21AM Arm has warned of a security vulnerability in Mali GPU Kernel Driver, CVE-2024-4610, actively exploited in the wild. The issue affects certain products, allowing improper GPU memory processing operations for unauthorized access. The vulnerability has been addressed in Bifrost and Valhall GPU Kernel Driver r41p0, with reports of exploitation in … Read more

CISA’s Secure by Design Initiative at 1: A Report Card

June 3, 2024 at 10:05AM The initiative has been successful, but further work is still required to fully achieve its goals. Based on the meeting notes, the key takeaway is that the initiative is currently successful, but there is a recognition that there is still more work to be done in order to achieve its … Read more

OpenAI Disrupts 5 AI-Powered, State-Backed Influence Ops

May 31, 2024 at 02:42PM OpenAI has flagged five influence operations from China, Iran, Israel, and Russia, all employing AI tools to spread political messaging, but with insignificant impact. Notable activities include Spamouflage from China, Bad Grammar targeting Eastern Europe and the United States, Doppelganger engaging on various platforms, and IUVM from Iran. OpenAI is … Read more