OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

OpenAI’s Astra Model Sparks Concerns Over Autonomous Cyberattacks A new AI model developed by OpenAI, called Astra, has been flagged as a potential cybersecurity risk due to its advanced capabilities in creating autonomous cyberattacks. The company has taken steps to mitigate this threat, but the incident highlights the growing concern of AI-powered attacks on real-world … Read more

Mozilla Issues New Firefox GPG Key Following Exposure

Mozilla has taken swift action to address a potential security vulnerability after accidentally exposing its GPG signing subkey in a GitHub repository. The exposed key could have allowed an attacker to create malicious versions of Firefox and Thunderbird software that appeared authentic, but several factors mitigate the impact. The GPG (GNU Privacy Guard) private signing … Read more

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

A devastating cyberattack on a Polish power plant has left experts scrambling to understand the scale of the damage. Hackers breached the facility’s control systems via its private cellular network, shutting down a critical turbine and potentially putting the entire grid at risk. The attack is believed to have been carried out through a vulnerability … Read more

OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

As OpenAI’s highly anticipated Astra model edges closer to release, the company has hit the brakes on internal development due to concerns over its potential for autonomous cyberattacks. According to recent evaluations, Astra has made significant strides in agentic coding and cybersecurity capabilities, putting it squarely in the crosshairs of a “critical” risk threshold. Under … Read more

Mozilla Issues New Firefox GPG Key Following Exposure

Mozilla has issued a new GPG signing subkey used for some Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a GitHub repository. This is a significant development in the world of cybersecurity, where the exposure of a private signing key can create a supply chain attack risk. When a private signing … Read more

Sherlock Holmes was the “OG” Social Engineer

The Age-Old Art of Social Engineering: Lessons from Sherlock Holmes’ Playbook Sherlock Holmes, the iconic detective created by Sir Arthur Conan Doyle, was long before his time. But what if we told you that this fictional character’s techniques are still being used today? In a fascinating session at DEF CON 34, University of West Florida’s … Read more

Outdated Cybercrime Laws Put Security Researchers at Risk

A growing number of cybersecurity researchers are being put at risk by outdated cybercrime laws that fail to distinguish between malicious hackers and those working in good faith. A recent study has highlighted this issue, revealing that many countries have yet to update their policies and laws to reflect the evolving nature of security research. … Read more

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

A Sneaky Supply Chain Attack Hits WordPress Sites, Leaving a Trail of Rogue Admins in Its Wake A sophisticated cyber attack has been discovered targeting BdThemes, a popular WordPress theme provider. The malicious scheme involves injecting poisoned JSON files into the supply chain, which ultimately creates rogue administrators on compromised sites. This brazen attack not … Read more

Sherlock Holmes was the “OG” Social Engineer

Sherlock Holmes: The Original Social Engineer In a fascinating display of how timeless social engineering techniques remain, Professor Elizabeth Rasnick has drawn parallels between the fictional detective Sherlock Holmes and modern-day tactics used by threat actors. Her session at DEF CON 34 highlighted the importance of prioritizing human element security awareness training in organizations. Holmes’s … Read more