Malware ships with bugs that defenders could use against it

Static analysis tools have spent years scanning legitimate software for security bugs before it goes out the door. The same scanners work on malware, and malware carries a steady supply of its own bugs. Researchers ran four of these tools across 658 le… Continue reading Malware ships with bugs that defenders could use against it

The security questions around Chinese AI coding models in U.S. software

Software developers across the United States are using AI models built in China to write, debug, and review code, drawn by prices below those of American alternatives. These models carry risks for the security of American software, according to a repor… Continue reading The security questions around Chinese AI coding models in U.S. software

Samsung just made Galaxy phones more secure in One UI 9 beta

Samsung’s One UI 9 beta integrates Lockdown mode into the power menu. This is the screen that contains Power off, Restart, and emergency options. Opening it initiates Lockdown mode, disabling biometric authentication. “We tried it out on the Gala… Continue reading Samsung just made Galaxy phones more secure in One UI 9 beta

OpenAI is locking down parts of ChatGPT to reduce data theft risks

OpenAI has started rolling out Lockdown Mode for ChatGPT, an optional security setting that restricts access to external resources and several product capabilities. It is available for personal accounts, including Free, Go, Plus, and Pro plans, as well… Continue reading OpenAI is locking down parts of ChatGPT to reduce data theft risks

52% of direct-to-IP threats are missing from intelligence feeds

Security tools are good at inspecting websites, domains, URLs, and files, so attackers are moving lower in the stack and communicating directly with IP addresses, where visibility is limited. According to Palo Alto Networks’ report, this creates … Continue reading 52% of direct-to-IP threats are missing from intelligence feeds

Let’s Encrypt works toward post-quantum certificates at web scale

Let’s Encrypt plans to pursue a post-quantum-safe Web PKI through Merkle Tree Certificates (MTCs), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. The project i… Continue reading Let’s Encrypt works toward post-quantum certificates at web scale