720-891-1663

Security News Update for the Week Ending May 10, 2024

TikTok Sues US Government; Vows to Prevail No surprise here and without taking a side pro or con; ByteDance and TikTok have filed suit in federal court arguing the law violates the US Constitution. TikTok’s CEO Shou Zi Chew says the company expects to win a legal challenge to block the new law. He says […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Supply Chain Breaches Up 68% From Last Year

If you have been reading this blog then any conversation about supply chain risk is not news to you. Verizon, which publishes the well respected annual data breach investigations report says that supply chain breaches are up 68 percent from 2022. The number is still suspiciously low to me, however. Most people think of Verizon […]

Continue reading → [DISPLAY_ACURAX_ICONS]

US Says Russia Exploiting Weak Security at Water, Wastewater Plants

Shoddy security practices. Short of cash. Lack of personnel to deal with threats. Outdated equipment connected to the Internet. Weak passwords. CISA and the FBI say these are just some of the issues that critical infrastructure operators are facing. Anti U.S. (pro-Russian) hackers are intensifying attacks on critical infrastructure such as water, wastewater, dams, energy […]

Continue reading → [DISPLAY_ACURAX_ICONS]

You Can’t Trust Cyber Crooks – DUH!

It was always difficult to separate fact from fiction when it came to breach information. Too many players had their own agendas to know what was real. Now there is another player in the room and it is FEAR, UNCERTAINTY AND DOUBT. Over the past four months alone, the press, social media accounts, and some […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Cloud Vendors Say “Know Your Customer” Rule is “Hard”

A Presidential Executive Order (EO) is making its way though the approval process which, if approved, would require cloud vendors like Google and Amazon to identify who is buying server time from them. This is very similar to what banks and other financial institutions have been doing for decades. But Google’s and Amazon’s trade group […]

Continue reading → [DISPLAY_ACURAX_ICONS]

SURPRISE: GPT-4 Can Exploit Unpatched Vulnerabilities

Who would have guessed? Researchers at the University of Illinois Urbana-Champaign (UIUC) fed AI agents vague descriptions of more than a dozen unpatched vulnerabilities. The agent they created with GPT-4 exploited 87 percent of those vulnerabilities. Fourteen other agents made with lesser tools like GPT 3.5 and Metasploit failed. The researchers said that GPT-4 was […]

Continue reading → [DISPLAY_ACURAX_ICONS]