White House taps security firms for offensive hack-back operations

A landmark shift in US cybersecurity policy has been announced, with the White House instructing private security companies to participate in offensive hack-back operations against foreign cybercrime organizations. A national security presidential memorandum (NSPM) signed by President Donald Trump enables the National Coordination Center (NCC) to tap into the expertise of these firms, allowing them … Read more

White House taps security firms for offensive hack-back operations

The White House has taken a significant step in its fight against foreign cybercrime organizations by signing a memo that enables private security companies to participate in offensive hack-back operations. The national security presidential memorandum (NSPM) instructs the National Coordination Center (NCC) to establish a program that would allow these firms to apply for approval … Read more

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

As AI coding assistants become increasingly prevalent in software development, a growing concern has emerged about who is responsible for vetting the code generated by these tools. The issue is particularly pressing when it comes to open-source ingestion, where the sheer scale of code generation has outpaced traditional review processes. In other words, developers are … Read more

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

As AI coding tools continue to revolutionize software development, a pressing concern has emerged in the cybersecurity community: who is responsible for vetting the code generated by these machines? The answer lies in the scale of open source ingestion, where developer adoption of AI assistants has outpaced traditional security measures. This has created a perfect … Read more

Trezor discloses data breach affecting nearly 14,000 customers

Trezor, a leading manufacturer of hardware cryptocurrency wallets, has disclosed a data breach that affects nearly 14,000 customers. The breach was caused by ShipMonk, Trezor’s shipping and logistics provider, being hacked by attackers who gained access to customer order data. The compromised information includes full names, shipping addresses, email addresses, and phone numbers of customers … Read more

Trezor discloses data breach affecting nearly 14,000 customers

Cybersecurity firm Trezor has disclosed a data breach that affects nearly 14,000 of its customers. The incident occurred when ShipMonk, Trezor’s shipping and logistics provider, was hacked by attackers who exploited a vulnerability in the third-party analytics platform Metabase. As a result, customers’ order data, including their full names, shipping addresses, email addresses, and phone … Read more

White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs

A new era in US cybersecurity has begun with a presidential memorandum that allows vetted private companies to conduct cyber operations under federal control against foreign cybercrime gangs. The initiative, managed by the National Coordination Center (NCC), marks a significant shift towards a more collaborative approach between the government and the private sector. The program … Read more

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

Fortinet, a leading cybersecurity company, has issued patches for eight vulnerabilities across its products, including two high-severity authentication flaws in FortiWeb and FortiManager. The patches address weaknesses that could allow attackers to bypass security controls or gain unauthorized access to sensitive systems. The most critical issue affects FortiWeb, where an attacker can exploit a flaw … Read more

Venture Firm Team8 Secures Additional $365 Million

Team8, a prominent Israeli venture capital firm, has secured an additional $365 million in funding, bringing its assets under management to nearly $2 billion since its inception in 2014. This new influx of capital will be used to support promising startups across various sectors, with a particular focus on AI and cybersecurity. The company’s venture-creation … Read more

‘Jewelbug’ APT Balances State Espionage & Cryptocurrency Theft

A Notorious APT Group Juggles State Espionage and Cryptocurrency Theft from the Same Web Panel Researchers have uncovered a sophisticated mercenary group operating out of China that seamlessly switches between conducting high-stakes cyber espionage on behalf of nation-states and engaging in lucrative cryptocurrency theft. Dubbed “Jewelbug” by Symantec, this advanced persistent threat (APT) group has … Read more