NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA’s groundbreaking move to open-source its NOOA framework and form the 37-member Open Secure AI Alliance has sent shockwaves through the tech industry, sparking both excitement and trepidation among security professionals. At the heart of this initiative is a bold effort to harness artificial intelligence (AI) for cybersecurity, leveraging AI models to uncover previously unknown … Read more

Shadow AI agents are multiplying. Here’s how to find and secure them.

Shadow AI agents are proliferating across organizations at an alarming rate. These hidden entities have been created in popular platforms such as Salesforce Agentforce, Microsoft Copilot Studio, and Zapier, often without IT or security teams being aware of their existence. With capabilities to connect to sensitive systems and take action on their own, shadow AI … Read more

Ernst & Young data breach claimed by ShinyHunters extortion gang

A major accounting firm’s sensitive client data has been compromised in a recent data breach, with the notorious ShinyHunters extortion gang claiming responsibility for the attack. Ernst & Young (EY), one of the world’s largest professional services firms, disclosed the breach earlier this month, revealing that an attacker had accessed its third-party support ticket system … Read more

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

A highly sophisticated and resilient botnet, known as Dysphoria, has evolved its command-and-control (C2) infrastructure by incorporating blockchain technology, allowing it to remain operational even after attempts to disrupt it. The botnet, which targets Internet of Things (IoT) devices, has also introduced a new feature called victim relays, enabling it to amplify attacks and evade … Read more

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

A major milestone in the fight against software vulnerabilities was reached yesterday with the formation of the Open Secure AI Alliance, a 37-member consortium comprising some of the biggest names in tech, including NVIDIA, Microsoft, and Google. At the heart of this initiative is the NOOA (NVIDIA Open-Source Omniscient Analysis) framework, an open-sourced tool designed … Read more

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

Apple is facing a lawsuit over its handling of cryptocurrency wallet apps on the App Store, with three individuals claiming that approximately $1.8 million in Bitcoin was stolen after they downloaded and used a fake Sparrow Wallet application. The plaintiffs allege that Apple failed to adequately review and monitor applications distributed through the App Store, … Read more

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybercrime Groups Exploit Remote Access Tools to Gain Unfettered Access to Networks A sophisticated cyberattack campaign, dubbed Operation BlueDash, has been uncovered, with hackers leveraging fake Microsoft Teams updates to deploy malicious remote management tools on unsuspecting organizations’ networks. The operation’s goal is to gain unfettered access to sensitive systems, underscoring the increasing threat posed … Read more

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

Cybersecurity researchers have uncovered a critical vulnerability in n8n, an open-source workflow automation platform widely used by businesses and developers. The bug, dubbed “Sandbox Escape,” allows malicious actors to execute system commands as the n8n process, potentially leading to data breaches and other serious security incidents. The vulnerability lies in the way n8n’s sandboxed execution … Read more

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

Cybersecurity experts are sounding the alarm about a new wave of threats that arise from artificial intelligence (AI) models, which can identify and exploit software vulnerabilities at an unprecedented scale. This trend has serious implications for businesses and individuals alike, as it allows attackers to pinpoint weaknesses in systems and launch targeted attacks. The AI-powered … Read more