California Advances Unique Safety Regulations for AI Companies Despite Tech Firm opposition

July 4, 2024 at 12:33PM California lawmakers advanced legislation requiring AI companies to test their systems to prevent potential harm, such as disrupting the electric grid or building chemical weapons. The bill, fiercely opposed by tech companies, aims to regulate AI safety standards and oversight. It also addresses concerns about AI discrimination and data privacy, … Read more

Ethereum mailing list breach exposes 35,000 to crypto draining attack

July 4, 2024 at 12:18PM A threat actor compromised Ethereum’s mailing list provider and sent a phishing email to over 35,000 addresses, luring recipients to a malicious site offering investment returns. Ethereum disclosed the incident, stating it had no material impact. The internal security team launched an investigation, blocked the attacker, and warned the community. … Read more

Software Productivity Tools Hijacked to Deliver Infostealers

July 4, 2024 at 09:10AM Conceptworld Corporation, an India-based software company, was found to be distributing information-stealing malware with its software products. Researchers from Rapid7 discovered that the installation packages of their tools, Notezilla, RecentX, and Copywhiz, had been Trojanized. Despite replacing the malicious installers, users were unknowingly exposed to the dllFake malware, capable of … Read more

Hackers attack HFS servers to drop malware and Monero miners

July 4, 2024 at 08:33AM Hackers are targeting older versions of Rejetto’s HTTP File Server (HFS) with malware and cryptocurrency mining. They exploit CVE-2024-23692 to execute commands without authentication. Vulnerable versions include up to 2.3m, categorized as “dangerous” by Rejetto. Attackers gather system information, install backdoors, and deploy various malware, including XMRig for cryptocurrency mining. … Read more

Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView Plus

July 4, 2024 at 06:37AM Microsoft has disclosed two security vulnerabilities in Rockwell Automation PanelView Plus, which could be exploited by remote attackers for remote code execution and denial-of-service (DoS) attacks. These flaws are tracked as CVE-2023-2071 and CVE-2023-29464, impacting FactoryTalk View Machine Edition and FactoryTalk Linx. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) … Read more

Mekotio Banking Trojan Threatens Financial Systems in Latin America

July 4, 2024 at 05:14AM The Mekotio banking trojan is a significant threat to financial systems in Latin America, targeting countries such as Brazil, Chile, Mexico, Spain, and Peru. It infiltrates systems through phishing emails, aiming to steal sensitive information, particularly banking credentials. Users can protect themselves by being cautious with emails, avoiding clicking on … Read more

Europol nukes nearly 600 IP addresses in Cobalt Strike crackdown

July 4, 2024 at 04:36AM Europol led Operation Morpheus to tackle nearly 600 illegal IP addresses associated with Cobalt Strike. The disruptive action targeted criminal activity, involving partners in 27 countries. Notable support was provided by private sector partners and Europol’s Malware Information Sharing Platform. The operation sent a strong message to cybercriminals globally. However, … Read more

Twilio Confirms Data Breach After Hackers Leak 33M Authy User Phone Numbers

July 4, 2024 at 03:37AM Twilio confirmed a data breach where hackers leaked 33 million phone numbers and account IDs associated with Authy. However, Twilio found no evidence of access to its systems and advised users to update security measures. The breach could lead to phishing and smishing attacks, urging heightened awareness among Authy users. … Read more

Brazil Halts Meta’s AI Data Processing Amid Privacy Concerns

July 4, 2024 at 03:11AM Brazil’s data protection authority, ANPD, has temporarily banned Meta from using users’ personal data to train AI algorithms due to inadequate legal basis, lack of transparency, and risks to children. Meta must comply within five days or face fines. This mirrors pushback in the EU over AI training data. The … Read more

Ransomware scum who hit Indonesian government apologizes, hands over encryption key

July 4, 2024 at 02:01AM Brain Cipher, the group behind the hacking of Indonesia’s Temporary National Data Center, has apologized and released an encryption key to the government. The key was a 54 kb ESXi file, with its effectiveness yet to be confirmed. The group shared its motive, claiming to act as penetration testers and … Read more