New AI Jailbreak Method ‘Bad Likert Judge’ Boosts Attack Success Rates by Over 60%

03/01/2025 0 Comments 0 tags

Cybersecurity researchers have shed light on a new jailbreak technique that could be used to get past a large language model’s (LLM) safety guardrails and produce potentially harmful or malicious

Apple to Pay Siri Users $20 Per Device in Settlement Over Accidental Siri Privacy Violations

03/01/2025 0 Comments 0 tags

Apple has agreed to pay $95 million to settle a proposed class action lawsuit that accused the iPhone maker of invading users’ privacy using its voice-activated Siri assistant. The development

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API

02/01/2025 0 Comments 0 tags

Details have emerged about three now-patched security vulnerabilities in Dynamics 365 and Power Apps Web API that could result in data exposure. The flaws, discovered by Melbourne-based cybersecurity company Stratus

Cross-Domain Attacks: A Growing Threat to Modern Security and How to Combat Them

02/01/2025 0 Comments 0 tags

In the past year, cross-domain attacks have gained prominence as an emerging tactic among adversaries. These operations exploit weak points across multiple domains – including endpoints, identity systems and cloud

Three Russian-German Nationals Charged with Espionage for Russian Secret Service

02/01/2025 0 Comments 0 tags

German prosecutors have charged three Russian-German nationals for acting as secret service agents for Russia. The individuals, named Dieter S., Alexander J., and Alex D., have been accused of working

Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT

02/01/2025 0 Comments 0 tags

Cybersecurity researchers have discovered a malicious package on the npm package registry that masquerades as a library for detecting vulnerabilities in Ethereum smart contracts but, in reality, drops an open-source

New “DoubleClickjacking” Exploit Bypasses Clickjacking Protections on Major Websites

01/01/2025 0 Comments 0 tags

Threat hunters have disclosed a new “widespread timing-based vulnerability class” that leverages a double-click sequence to facilitate clickjacking attacks and account takeovers in almost all major websites. The technique has

Iranian and Russian Entities Sanctioned for Election Interference Using AI and Cyber Tactics

01/01/2025 0 Comments 0 tags

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Tuesday leveled sanctions against two entities in Iran and Russia for their attempts to interfere with the November 2024

New U.S. DoJ Rule Halts Bulk Data Transfers to Adversarial Nations to Protect Privacy

31/12/2024 0 Comments 0 tags

The U.S. Department of Justice (DoJ) has issued a final rule carrying out Executive Order (EO) 14117, which prevents mass transfer of citizens’ personal data to countries of concern such

Misconfigured Kubernetes RBAC in Azure Airflow Could Expose Entire Cluster to Exploitation

31/12/2024 0 Comments 0 tags

Cybersecurity researchers have uncovered three security weaknesses in Microsoft’s Azure Data Factory Apache Airflow integration that, if successfully exploited, could have allowed an attacker to gain the ability to conduct