Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article discusses how the multitude of software components in AI harnesses can have trust issues between them, which creates concerning attack vectors for potential exploitation.
This article discusses how the typical AI harness is composed of numerous software components, and the lack of trust between these components can introduce significant attack vectors, presenting potential exploit opportunities for adversaries.
Analog Devices, a semiconductor chip manufacturer based in Massachusetts, disclosed a data breach in a regulatory filing, stating that intruders had exfiltrated data from its networks earlier in the summer. The full extent of the incident remains under investigation.
In a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is still under investigation.
A North Korean-linked threat group has been deploying a sophisticated macOS malvertising campaign that tricks users into executing malware via fake software updates. The attack, part of the long-running Contagious Interview campaign (also known as UNC5342), displays a full-screen fake macOS update sequence, copying a malicious command to the clipboard and prompting victims to paste it into Terminal.
This article describes a sophisticated macOS malvertising campaign attributed to North Korean threat actors, where users are redirected to fake web pages displaying a full-screen update sequence to deliver crypto-stealing malware. The attack is part of the ongoing Contagious Interview campaign.