Researchers use ChatGPT to generate malware and phishing mails
Researchers used ChatGPT to write malware scripts and generate phishing emails. The AI model has since been updated to prevent abuse.
ChatGPT is in the spotlight. OpenAI, the model's developer, recently made the technology publicly available. ChatGPT generates texts and code based on queries. In... Read more
IBM discovers wormable vulnerability eerily similar to EternalBlue
Researchers have identified a Windows code execution vulnerability that has the potential to rival EternalBlue, a Windows security issue used to ignite WannaCry, which took down computer networks around the world in 2017.
The newly discovered vulnerability is listed as CVE-2022-37958. It allows ... Read more
Ransomware hits Leiden University
The internal secondment agency of Leiden University has been hit by ransomware. The Dutch university reported the attack to the national data protection authority.
An internal statement for employees reveals that the salary processing system of Job Motion, an internal university secondment agen... Read more
LogRhythm and SentinelOne integrate for greater insight
LogRhythm and SentinelOne have integrated their technology. This should give companies more insight into potential threats and allow them to respond to them immediately.
According to the partners, the collaboration produces an integrated enterprise security solution to prevent, detect and respon... Read more
NIST retires SHA-1 algorithm
The US government's National Institute of Standards and Technology (NIST) is officially retiring the Secure Hash Algorithm-1 for secure data processing. The protocol's second and third versions are more secure.
NIST has announced that the SHA-1 encryption algorithm has officially reached its en... Read more
GitHub will require two-factor authentication from all users in 2023
The new policy applies to anyone who contributes code to the platform.
GitHub announced this week that it will require all users to enable two-factor authorization (2FA) by the end of 2023. To be clear, the policy will apply not just to developers who contribute code to the GitHub website, but t... Read more
Microsoft bans crypto mining from its online services
Microsoft quietly banned crypto mining activities in Azure, Office 365, Dynamics 365 and Power Platform.
Microsoft argues that preventing crypto mining preserves the performance of services for other customers and protects users from potential malicious activity associated with crypto mining.
... Read more
Makro’s parent company expects cyberattack to cost millions in profit
Makro parent METRO remains occupied with the aftermath of October's cyberattack. The company expects a €40 million to €70 million profit loss as a result of the incident.
German wholesale chain METRO was hit by a cyberattack in October. Several IT systems failed in the process. In a recent ... Read more
NSA: cybercriminals actively exploit Citrix ADC and Gateway
US security and intelligence agency NSA warns that hackers are exploiting zero days in Citrix networking devices. The exploits abuse vulnerabilities in Citrix application delivery controller (ADC) and Citrix Gateway.
According to the NSA, cybercrime group APT5 is actively exploiting a vulnerabil... Read more
UK announces code of practice to strengthen app store security
The UK's new code of practice incentivizes developers and publishers to implement stronger security measures.
A code of practice to boost security safeguards throughout the app sector has been announced by the UK government. The new voluntary policy intends to better shield users from harmful ap... Read more