Judge Dismisses Major SEC Charges Against SolarWinds and CISO 

Judge dismissed SEC lawsuit charging SolarWinds and CISO Timothy Brown with hiding security problems before and after the SUNBURST supply chain compromise.
The post Judge Dismisses Major SEC Charges Against SolarWinds and CISO  appeared first on Securi… Continue reading Judge Dismisses Major SEC Charges Against SolarWinds and CISO 

OpenAI Rolls Out Compliance API and Integrations for ChatGPT Enterprise

The tools are being positioned as crucial to help business customers meet requirements for regulations like FINRA, HIPAA, and GDPR.
The post OpenAI Rolls Out Compliance API and Integrations for ChatGPT Enterprise appeared first on SecurityWeek.
Continue reading OpenAI Rolls Out Compliance API and Integrations for ChatGPT Enterprise

Chinese Hacking Group APT41 Infiltrates Global Shipping and Tech Sectors, Mandiant Warns

Chinese government-backed hacking team caught breaking into organizations in shipping, logistics and automotive sectors in Europe and Asia.
The post Chinese Hacking Group APT41 Infiltrates Global Shipping and Tech Sectors, Mandiant Warns appeared first… Continue reading Chinese Hacking Group APT41 Infiltrates Global Shipping and Tech Sectors, Mandiant Warns

Ex-GitHub Engineers Raise $20M to Enhance Pen-Testing with AI-Powered XBOW

A team of former GitHub engineers has secured $20 million in venture capital funding from Sequoia to build AI-powered security tools.
The post Ex-GitHub Engineers Raise $20M to Enhance Pen-Testing with AI-Powered XBOW appeared first on SecurityWeek.
Continue reading Ex-GitHub Engineers Raise $20M to Enhance Pen-Testing with AI-Powered XBOW

VMware Patches Critical SQL-Injection Flaw in Aria Automation

VMware warns that authenticated malicious users could enter specially crafted SQL queries and perform unauthorized read/write operations in the database.
The post VMware Patches Critical SQL-Injection Flaw in Aria Automation appeared first on SecurityW… Continue reading VMware Patches Critical SQL-Injection Flaw in Aria Automation

Microsoft Warns of Windows Hyper-V Zero-Day Being Exploited

Patch Tuesday: Microsoft patches more than 140 security vulnerabilities in the Windows ecosystem, including a pair of exploited zero-days.
The post Microsoft Warns of Windows Hyper-V Zero-Day Being Exploited appeared first on SecurityWeek.
Continue reading Microsoft Warns of Windows Hyper-V Zero-Day Being Exploited

Adobe Issues Critical Patches for Multiple Products, Warns of Code Execution Risks

Adobe documents at least seven code execution bugs affecting Adobe Premiere Pro, Adobe InDesign and Adobe Bridge on Windows and macOS.
The post Adobe Issues Critical Patches for Multiple Products, Warns of Code Execution Risks appeared first on Securit… Continue reading Adobe Issues Critical Patches for Multiple Products, Warns of Code Execution Risks

BlastRADIUS Attack Exposes Critical Flaw in 30-Year-Old RADIUS Protocol

Security vendor InkBridge Networks calls urgent attention to the discovery of a decades-old design flaw (CVE-2024-3596) in the popular RADIUS protocol.
The post BlastRADIUS Attack Exposes Critical Flaw in 30-Year-Old RADIUS Protocol appeared first on S… Continue reading BlastRADIUS Attack Exposes Critical Flaw in 30-Year-Old RADIUS Protocol

Europol Announces Crackdown on Cobalt Strike Servers Used by Cybercriminals

European law enforcement agency announces the takedown of nearly 600 Cobalt Strike servers linked to criminal activity.
The post Europol Announces Crackdown on Cobalt Strike Servers Used by Cybercriminals appeared first on SecurityWeek.
Continue reading Europol Announces Crackdown on Cobalt Strike Servers Used by Cybercriminals