Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article discusses how AI is transforming security operations, emphasizing that different AI types serve distinct roles in the SOC. It separates an autonomous AI SOC layer for alert triage from AI platforms like Claude for analyst collaboration, urging leaders to avoid treating one tool as a universal solution.
An unknown Chinese-speaking threat actor is leveraging a publicly leaked version of the DarkSword exploit kit to target Apple iOS devices. The campaign runs over 100 web properties, primarily fake AWS sign-in pages, and uses watering holes to exploit patched iOS vulnerabilities and deliver GHOSTBLADE information-stealing malware.
An unknown Chinese-speaking threat actor is leveraging a publicly leaked version of the DarkSword exploit kit to target Apple iOS devices. The campaign runs over 100 web properties, primarily fake AWS sign-in pages, and uses watering holes to exploit patched iOS vulnerabilities and deliver GHOSTBLADE information-stealing malware.
This article from Unit 42 explores a novel attack surface called 'Pass the Passkey' in passwordless authentication. It highlights how implementation gaps, specifically when relying parties fail to validate the User Verified flag, can reduce multi-factor authentication to a single factor, compromising security.
This article explores how gaps in passkey implementation can undermine security when relying parties fail to validate the User Verified flag. This oversight reduces multi-factor authentication to a single factor, creating a novel attack surface in passwordless authentication.
This article from Unit 42 explores a novel attack surface called 'Pass the Passkey' in passwordless authentication. It highlights how implementation gaps, specifically when relying parties fail to validate the User Verified flag, can reduce multi-factor authentication to a single factor, compromising security.