OpenAI Adds Controls That Should’ve Been There Already

**OpenAI Takes Major Step Towards AI Security with New Controls** In a move that comes after last month’s high-profile breach of Hugging Face, OpenAI has implemented a slew of security controls to prevent similar incidents in the future. While these new measures are certainly welcome, some experts argue that they should have been put in … Read more

Calling on Cyber Pros to Help Defend City Hall

**City Halls Under Siege: How Cybersecurity Experts Can Help** Imagine a city’s housing authority losing nearly $1 million without even realizing it. No ransom demands, no locked servers – just a quietly orchestrated heist that went undetected until it was too late. This isn’t a federal agency or a Fortune 500 company; it’s a local … Read more

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

A sophisticated malware campaign has compromised 14 popular npm packages, injecting a Linux backdoor known as RedC2 4.0 into unsuspecting users’ systems. This attack leverages artificial intelligence-assisted command and control (C2) capabilities to evade detection, making it a particularly insidious threat. The affected packages, used by millions of developers worldwide, were quietly modified to include … Read more

Former NSA Director Paul Nakasone Launches National Security Advisory Firm

Former NSA Director Paul Nakasone Launches National Security Advisory Firm, Bringing Elite-Level Counsel to Private Clients Retired US Army General Paul M. Nakasone, a highly decorated and experienced national security expert, has launched a boutique advisory firm to help individuals, families, and organizations navigate the increasingly complex landscape of cybersecurity threats, geopolitics, and personal security … Read more

OpenAI Adds Controls That Should’ve Been There Already

Cybersecurity Giant OpenAI Fails to Catch Red Flags, Now Playing Catch-Up In a stark reminder that even the most advanced organizations can fall short of their own standards, OpenAI has announced sweeping changes in response to a recent incident where its cutting-edge models inadvertently breached an AI application store. The company’s new security controls are … Read more

Calling on Cyber Pros to Help Defend City Hall

Local Governments Vulnerable to Cyberattacks, But Experts Say There’s Hope for Improvement A recent cybersecurity breach at a small local government agency has highlighted the alarming vulnerability of these institutions to cyber threats. The incident, which resulted in the loss of nearly $1 million, was a wake-up call for the agency, but also an opportunity … Read more

OWASP Flags Top AI Skill Risks in New Security Blueprint

Cybersecurity experts have sounded the alarm on a growing threat to artificial intelligence (AI) systems, and the Open Worldwide Application Security Project (OWASP) has responded with a new security blueprint. In a recent high-profile attack, cyber attackers exploited vulnerabilities in AI skills – essentially scripts that add features and capabilities to these platforms – to … Read more

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

A Sneaky Linux Backdoor Spreads Through Popular npm Packages, Exploiting AI-Powered Command and Control Features Malicious actors have been secretly slipping a sophisticated backdoor into 14 popular Node.js packages on the npm registry, leaving thousands of users vulnerable to a powerful Linux exploit. The compromised packages, which were downloaded over 1.5 million times in recent … Read more

OWASP Flags Top AI Skill Risks in New Security Blueprint

As AI-powered agents become increasingly ubiquitous in modern businesses, a new threat landscape is emerging that targets their “skills” – essentially scripts written in natural language or code that enable these agents to perform specific tasks. A recent cyberattack on an agentic AI work platform, Paperclip, highlights the risks posed by skills and has prompted … Read more

CISA orders feds to patch actively exploited TrueConf Server flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert to all federal agencies, instructing them to patch two critical vulnerabilities in the TrueConf Server self-hosted communications platform as soon as possible. These flaws, which allow attackers to remotely execute arbitrary scripts and gain code execution on vulnerable servers, have already been … Read more