Application securityApple to settle claims Siri collected user data without permissionShaun NicholsJanuary 2, 2025Tech giant will be paying out a $95 million settlement over claims it exposed user data.
AI/MLGenAI cybersecurity ROI outlook shared by business leadersLaura FrenchJanuary 2, 2025Surveyed COOs reported savings of up to 7.7% of annual revenue due to GenAI use.
DevOpsNPM package poses as legit Ethereum smart contract, injects Quasar RATSteve ZurierJanuary 2, 2025Quasar RAT has circulated in cybercrime and APT campaigns since July 2014.
IdentityUS Treasury hacked by state-sponsored Chinese APT groupSteve ZurierDecember 31, 2024Government says hackers compromised a BeyondTrust API key to then access Treasury workstations and steal unclassified documents.
IdentityChrome extensions compromised in Christmas Day supply chain attackSteve ZurierDecember 30, 2024Stolen Cyberhaven employee credentials used to steal access tokens and business data from users of Facebook ads.
Network SecurityPalo Alto Networks patches DoS bug in PAN-OS softwareSteve ZurierDecember 27, 2024DoS flaw actively exploited in production. Security pros warn teams to patch right away.
Governance, Risk and ComplianceData disclosures shaped compliance landscape in 2024Shaun NicholsDecember 26, 2024Organizations faced a number of changes to reach and maintain government compliance in 2024.
Network SecurityApache fixes Traffic Control bug that attackers could exploitSteve ZurierDecember 26, 2024Security teams should immediately patch 9.9 vulnerability in web content distribution platform.
Ransomware5.6 million patients affected by Ascension Health cyberattackSteve ZurierDecember 23, 2024Attack by Black Basta sent the Ascension system reeling for several days, forcing medical staffs to reading paper charts.
AI/MLAI-fueled phishing, shadow AI, jailbreaks kept security pros busy in 2024Laura FrenchDecember 23, 2024Deepfakes, shadow AI and LLM misuse were growing concerns, while AI threat detection, malware analysis and vulnerability research showed promise for cyber defenders.
Proactive law enforcement takedowns in 2024 reshaped the cybercrime ecosystemDon Smith December 30, 2024