Zero-Day Breach at Rackspace Sparks Vendor Blame Game

A breach at Rackspace exposes the fragility of the software supply chain, triggering a blame game among vendors over an exploited zero-day.
The post Zero-Day Breach at Rackspace Sparks Vendor Blame Game appeared first on SecurityWeek.
Continue reading Zero-Day Breach at Rackspace Sparks Vendor Blame Game

Harmonic Raises $17.5M to Defend Against AI Data Harvesting

Harmonic has raised a total of $26 million to develop a new approach to data protection using pre-trained, specialized language models. 
The post Harmonic Raises $17.5M to Defend Against AI Data Harvesting appeared first on SecurityWeek.
Continue reading Harmonic Raises $17.5M to Defend Against AI Data Harvesting

North Korea Hackers Linked to Breach of German Missile Manufacturer

The targeting of Diehl Defence is significant because the company specializes in the production of missiles and ammunition.
The post North Korea Hackers Linked to Breach of German Missile Manufacturer appeared first on SecurityWeek.
Continue reading North Korea Hackers Linked to Breach of German Missile Manufacturer

Controversial Windows Recall AI Search Tool Returns With Proof-of-Presence Encryption, Data Isolation

Microsoft reboots controversial Windows Recall with proof-of-presence encryption, anti-tampering checks, and secure enclave data management.
The post Controversial Windows Recall AI Search Tool Returns With Proof-of-Presence Encryption, Data Isolation … Continue reading Controversial Windows Recall AI Search Tool Returns With Proof-of-Presence Encryption, Data Isolation

Critical Nvidia Container Flaw Exposes Cloud AI Systems to Host Takeover

Nvidia confirms risk of code execution, denial of service, escalation of privileges, information disclosure, and data tampering. CVSS 9/10.
The post Critical Nvidia Container Flaw Exposes Cloud AI Systems to Host Takeover appeared first on SecurityWeek.
Continue reading Critical Nvidia Container Flaw Exposes Cloud AI Systems to Host Takeover

CrowdStrike Overhauls Testing and Rollout Procedures to Avoid System Crashes

CrowdStrike says it has revamped several testing, validation, and update rollout processes to prevent a repeat of the July BSOD incident.
The post CrowdStrike Overhauls Testing and Rollout Procedures to Avoid System Crashes appeared first on SecurityWe… Continue reading CrowdStrike Overhauls Testing and Rollout Procedures to Avoid System Crashes

Microsoft Names Deputy CISOs, Governance Council to Manage Security Push 

Microsoft says each Deputy CISO will oversee specific domains, ranging from gaming and cloud security to AI and government systems.
The post Microsoft Names Deputy CISOs, Governance Council to Manage Security Push  appeared first on SecurityWeek.
Continue reading Microsoft Names Deputy CISOs, Governance Council to Manage Security Push 

Mandiant Offers Clues to Spotting and Stopping North Korean Fake IT Workers

Mandiant shines the spotlight on the growing infiltration of US and Western companies by North Korean fake IT workers.
The post Mandiant Offers Clues to Spotting and Stopping North Korean Fake IT Workers appeared first on SecurityWeek.
Continue reading Mandiant Offers Clues to Spotting and Stopping North Korean Fake IT Workers

Opnova Banks Seed Capital to Tackle Security, IT Automation

Serial entrepreneur Sinan Eren is back with Opnova, a startup working on automating security workflows with limited human supervision.
The post Opnova Banks Seed Capital to Tackle Security, IT Automation appeared first on SecurityWeek.
Continue reading Opnova Banks Seed Capital to Tackle Security, IT Automation

Chinese Spies Built Massive Botnet of IoT Devices to Target US, Taiwan Military

Black Lotus Labs estimates that more than 200,000 routers, network-attached storage servers, and IP cameras have been ensnared in the botnet.
The post Chinese Spies Built Massive Botnet of IoT Devices to Target US, Taiwan Military appeared first on Sec… Continue reading Chinese Spies Built Massive Botnet of IoT Devices to Target US, Taiwan Military