High-severity vulnerability in Passwordstate credential manager. Patch now.

Source

The maker of Passwordstate, an enterprise-grade password manager for storing companies’ most privileged credentials, is urging them to promptly install an update fixing a high-severity vulnerability that hackers can exploit to gain administrative access to their vaults. The authentication bypass allows hackers to create a URL that accesses an …

Affiliates Flock to ‘Soulless’ Scam Gambling Machine

Source

Last month, KrebsOnSecurity tracked the sudden emergence of hundreds of polished online gaming and wagering websites that lure people with free credits and eventually abscond with any cryptocurrency funds deposited by players. We’ve since learned that these scam gambling sites have proliferated thanks to a new Russian affiliate …

Cloud CISO Perspectives: How CISOs and boards can help fight cyber-enabled fraud

Source

Welcome to the second Cloud CISO Perspectives for August 2025. Today, David Stone and Marina Kaganovich, from our Office of the CISO, talk about the serious risk of cyber-enabled fraud — and how CISOs and boards can help stop it. As with all Cloud CISO Perspectives, the contents of this …

ChatGPT hates LA Chargers fans

Source

Harvard researchers find model guardrails tailor query responses to user's inferred politics and other affiliations OpenAI's ChatGPT appears to be more likely to refuse to respond to questions posed by fans of the Los Angeles Chargers football team than to followers of other teams.... [...]

The intruder is in the house: Storm-0501 attacked Azure, stole data, demanded payment via Teams

Source

Don't let it happen to you Storm-0501, a financially motivated cybercrime crew, recently broke into a large enterprise's on-premises and cloud environments, ultimately exfiltrating and destroying data within the org's Azure environment. The criminals then contacted the victim via a Microsoft Teams account that they'd also compromised in the …

Google named a Leader in IDC MarketScape: Worldwide Incident Response 2025 Vendor Assessment

Source

Today's cybersecurity landscape requires partners with expertise and resources to handle any incident. Mandiant, a core part of Google Cloud Security, can empower organizations to navigate critical moments, prepare for future threats, build confidence, and advance their cyber defense programs. We're excited to announce that Google has been named …

ZipLine attack uses 'Contact Us' forms, White House butler pic to invade sensitive industries

Source

'Many dozens' targeted in ongoing campaign, CheckPoint researcher tells The Reg Cybercriminals are targeting critical US manufacturers and supply-chain companies, looking to steal sensitive IP and other data while deploying ransomware. Their attack involves a novel twist on phishing — and a photo of White House butlers.... [...]

« newer articles | page 64 | older articles »