Geek-Guy.com

Category: Global Security News

WeTransfer’s free plan now has a monthly limit of 10 transfers

File transfer service WeTransfer is now limiting users to 10 transfers per month with its free plan. The company is already applying the new limit to users, as per a support page. At the same time, WeTransfer is adding some perks to the free plan, including increasing the overall file transfer limit from 2GB to…

A new ransomware regime is now targeting critical systems with weaker networks

The year 2024’s ransomware shake-up, fueled by law enforcement crackdowns on giants like LockBit, has shifted focus to critical operations, with major attacks this year hitting targets like Halliburton, TfL, and Arkansas water plant. A Dragos study for the third quarter of 2024 highlighted a surge in activity from new groups like RansomHub, Play, and…

APT29 Hackers Target High-Value Victims Using Rogue RDP Servers and PyRDP

The Russia-linked APT29 threat actor has been observed repurposing a legitimate red teaming attack methodology as part of cyber attacks leveraging malicious Remote Desktop Protocol (RDP) configuration files. The activity, which has targeted governments and armed forces, think tanks, academic researchers, and Ukrainian entities, entails adopting a “rogue RDP” technique that was previously

Five years later… Netflix hit with Dutch data access fine

Five years later sounds like a half-baked sequel to a well-known zombie flick franchise. But it’s a reference to how long it’s taken a data access complaint against Netflix to deliver a penalty decision in the European Union. The fine that’s — finally — been issued under the bloc’s General Data Protection Regulation (GDPR) is…

ONLY Cynet Delivers 100% Protection and 100% Detection Visibility in the 2024 MITRE ATT&CK Evaluation

Across small-to-medium enterprises (SMEs) and managed service providers (MSPs), the top priority for cybersecurity leaders is to keep IT environments up and running. To guard against cyber threats and prevent data breaches, it’s vital to understand the current cybersecurity vendor landscape and continually assess the effectiveness of available solutions. Luckily, the 2024 MITRE ATT&CK

Meta hit with $263 million fine in Europe over 2018 data breach

Meta has been fined $263.5 million (€251 million) by Ireland’s Data Protection Commission (DPC) for a 2018 Facebook security breach that exposed the sensitive data of 29 million users globally. The breach exploited a vulnerability in Facebook’s “view as” feature, which allows users to view their profiles as others would see them. The exploit enabled…

A Wake-Up Call for Australia’s Telecom Sector: Lessons from the U.S. “Salt Typhoon” Hack

GUEST OPINION:   Recent revelations about “Salt Typhoon,” the worst telecom data breach in U.S. history, serve as a stark reminder of the vulnerabilities inherent in modern telecommunications infrastructure. This state-sponsored cyber-attack, attributed to Chinese actors, not only compromised sensitive call metadata but also exposed the fragility of critical infrastructure systems. For Australian business executives, the warning…

AI is burying company web sites in search results, but Otterly.AI thinks it can help

Many sites saw their organic traffic decline in 2024, in big part due to the rise of AI-generated search results. Many queries no longer lead to click-throughs, and even when users click, it is hard for companies to get more context on searches made within apps like ChatGPT or Perplexity. The answer to this problem…

Why AI and Large Language Models (LLMs) will increasingly rely on unstructured data being more visible, organised, and accessible

GUEST OPINION:  As the modern organisation enters a new phase of technological evolution with the widespread move towards smarter systems based upon Artificial Intelligence (AI) and Large Language Models (LLMs), the volume and accessibility of data with which to feed these systems will become critical.

Threads is testing a post scheduling feature

Meta’s social network Threads is experimenting with a feature that will let you schedule posts, Instagram head Adam Mosseri said. Users who will get to test this feature won’t be able to schedule replies. “We want to balance giving people more control to plan their Threads posts while still encouraging real-time conversations,” he said. People…

‘It’s dumb to IPO this year’: Databricks CEO explains why he’s waiting to go public

Databricks just closed one of the largest funding rounds ever, raising a staggering $10 billion in fresh capital. Naturally, technology investors were quick to ask what this means for the company’s highly anticipated IPO. During an event in San Francisco on Tuesday night, Databricks CEO Ali Ghodsi explained why he’s waiting until at least 2025…

CISOs should stop freaking out about attackers getting a boost from LLMs

A common refrain from cybersecurity professionals in recent years has been the need for a diversification of the CISO role to meet the demands of increased responsibility across numerous categories. In the past year, this refrain has grown louder, specifically around the topic of generative AI. Large language models (LLMs) have added a new dimension…

Key strategies to enhance cyber resilience

The faulty CrowdStrike software update that triggered IT outages on a global scale in July was a sobering reminder of the importance of incident response and business continuity plans. The update caused more than eight million Windows devices to crash and take down with them airline reservation systems, hospital and government services, financial and banking…

India’s MobiKwik surges 82% in market debut

Shares in digital payments firm MobiKwik surged 82% to ₹507.5 ($6) on their first day of trading, as the Indian fintech company made its market debut amid fierce competition from larger rivals. The listing pushed MobiKwik’s market value to $464 million, well above its initial target of $250 million for the public offering. The valuation…

Patch Alert: Critical Apache Struts Flaw Found, Exploitation Attempts Detected

Threat actors are attempting to exploit a recently disclosed security flaw impacting Apache Struts that could pave the way for remote code execution. The issue, tracked as CVE-2024-53677, carries a CVSS score of 9.5 out of 10.0, indicating critical severity. The vulnerability shares similarities with another critical bug the project maintainers addressed in December 2023…

Data Security Posture Management: Die besten DSPM-Tools

Data Security Posture Management erfordert nicht nur die richtigen Tools, sondern auch eine entsprechende Vorbereitung. Foto: Rawpixel.com | shutterstock.com Cloud Computing ist von Natur aus dynamisch und flüchtig: Daten können schnell und einfach erstellt, gelöscht oder verschoben werden. Das sorgt dafür, dass auch die Cloud-Angriffsfläche sehr dynamisch ist – was Schutzmaßnahmen erschwert. Ein lästiges Problem…

Lesson from latest SEC fine for not completely disclosing data breach details: ‘Be truthful’

A $3.55 million civil penalty levied this week by a US financial regulator against a Michigan bank for filing misleading statements about the theft of 1.5 million people’s data is a reminder to leaders of all organizations to be upfront about cyber incidents. “The message is, ‘Be truthful with your disclosures,’” said Bob Zukis, executive…

Securing SaaS – Lessons, Trends, and Strategies for 2025 with Guest Forrester

Our guest speaker, Forrester Vice President, Principal Analyst, Andras Cser, will share key insights on the risks and trends shaping the SaaS security landscape as we move into 2025. The post Securing SaaS – Lessons, Trends, and Strategies for 2025 with Guest Forrester appeared first on AppOmni. The post Securing SaaS – Lessons, Trends, and…

CISA delivers new directive to agencies on securing cloud environments

Federal civilian agencies have a new list of cyber-related requirements to address after the Cybersecurity and Infrastructure Security Agency on Tuesday issued guidance regarding the implementation of secure practices for cloud services. CISA’s Binding Operational Directive (BOD) 25-01 instructs agencies to identify all of its cloud instances and implement assessment tools, while also making sure…

Salesforce plans to hire 2,000 people to sell its AI products

Cloud software giant Salesforce looks to hire thousands of new sales people to sell its AI tools to customers. The company plans to hire 2,000 new sales representatives, according to CNBC, which cited remarks from CEO Marc Benioff at a company event Tuesday. This doubles the hiring plans that Benioff told Bloomberg last month. Benioff…

Securing Your SaaS: How AppOmni Mitigates SaaS Risks and Protects Data

In this 20 minute session, we’ll introduce you to AppOmni, the platform designed to reduce SaaS data exposure, detect threats, and prevent data breaches. The post Securing Your SaaS: How AppOmni Mitigates SaaS Risks and Protects Data appeared first on AppOmni. The post Securing Your SaaS: How AppOmni Mitigates SaaS Risks and Protects Data appeared…

The AI Fix #29: AI on OnlyFans, and the bot that wants to be a billionaire

In episode 29 of The AI Fix, an AI company makes the bold step of urging us to “stop hiring humans”, Graham is wrong about GB AI, parents prepare their kids for the imminent Moxie-mageddon, Google releases Gemini 2.0, and a robot is found dead at work and nobody knows why. Graham inspects the AI…

OpenAI says it has no plans for a Sora API — yet

OpenAI says it has no plans to release an API for Sora, its AI model that can generate reasonably realistic videos when provided with a text description or reference image. During an AMA with members of OpenAI’s dev team, Romain Huet, head of developer experience at OpenAI, said that a Sora API isn’t in the…

Grubhub to pay $25M for ‘deceptive’ practices against customers, drivers

Grubhub will pay $25 million to settle a lawsuit from the Federal Trade Commission and Illinois Attorney General Kwame Raoul over unlawful practices, including misleading customers about delivery costs, deceiving drivers about potential earnings, and listing restaurants on its platform without their permission. The agencies claim that Grubhub hid the true cost of its delivery…

DEF CON 32 – HookChain A New Perspective For Bypassing EDR Solutions

Authors/Presenters: Helvio Carvalho Junior Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel. Permalink The post DEF CON 32 – HookChain A New Perspective For Bypassing EDR Solutions appeared…

Playbook advises federal grant managers how to build cybersecurity into their programs

Two U.S. cyber agencies released guidance Tuesday on how federal grant managers should incorporate cybersecurity in their programs for critical infrastructure projects, as well as how potential recipients can take it into account. The Office of the National Cyber Director and the Cybersecurity and Infrastructure Security Agency publication — the “Playbook for Strengthening Cybersecurity in…

That cheap webcam? HiatusRAT may be targeting it, FBI warns

Webcams have been a key part of business and home offices everywhere, especially since the COVID pandemic hit. But they are not often high-quality products, especially if used only sporadically, as many consumers and remote workers are content with a cheap one from China. This not only causes regular hardware problems, but it can also be…

Clop is back to wreak havoc via vulnerable file-transfer software

In what we can assure you is a new cybersecurity incident despite sounding incredibly similar to incidents of past notoriety: threat actors tied to a notorious ransomware and extortion group have exploited file-transfer software to carry out attacks.  Clop has claimed responsibility for attacks tied to vulnerabilities in software made by Cleo, an Illinois-based IT…

AI boom masks fundraising struggles for non-AI startups

Earlier this year, IVP general partner Tom Loverro, proclaimed that the post-pandemic downturn is over, and companies that made it this far should prioritize growth over cost-cutting. Yet, the companies still struggling to raise their next round of financing at a higher valuation or survive altogether could still be in the thousands, according to Brian…

Bob Lee verdict: Cash App creator’s killer found guilty of second-degree murder

A San Francisco jury has found Nima Momeni guilty of second-degree murder in the stabbing of Bob Lee, the Cash App creator and former CTO of Block, according to NBC News Bay Area on Tuesday. The jury found Momeni not guilty of first-degree murder, meaning jurors decided the murder of Lee was not premeditated. Lee…

How to Assess Virtual Machines Prior to Deployment with Spectra Assure

Many software development shops deliver their product releases via virtual machine (VM) disk images. Whether deployed to a cloud environment, data center, or elsewhere, delivering safe and secure images is vital. If vulnerabilities, malware, or even unhardened binaries are present in a disk image delivered to customers, they are exposed to a significant degree of…

Bridgy Fed, a project to connect the open social web, is now becoming a nonprofit

Bridgy Fed, which is working to connect the social network Bluesky with the wider fediverse (aka the open social web), which includes sites like Mastodon and others, will be the first app incubated within a new nonprofit called A New Social. The organization, announced Tuesday, aims to bring together developers, researchers, startups, and industry leaders…

Cash App creator Bob Lee’s killer found guilty of second-degree murder

A San Francisco jury has found Nima Momeni guilty of second-degree murder in the stabbing death of Bob Lee, the Cash App creator and former CTO of Block, according to NBC News Bay Area on Tuesday. The jury found Momeni not guilty of first-degree murder, meaning jurors decided the murder of Lee was not premeditated.…

This fintech processed $1B in payments through word-of-mouth

Welcome to TechCrunch Fintech! This week, we’re diving into: P.S. We’re taking time off for the holidays! TechCrunch Fintech scribe Mary Ann Azevedo will be back in your inbox on January 7. ❄️ The big story How stablecoin technology can power billions in cross-border transactions Juicyway is an African fintech that’s leveraging stablecoin technology to…

Grammarly acquires productivity startup Coda, brings on new CEO

Grammarly is acquiring productivity startup Coda, the company announced on Tuesday. As part of the deal, Coda’s CEO and co-founder Shishir Mehrotra will become the new CEO of Grammarly. The financial terms of the deal were not disclosed. The acquisition will help turn Grammarly’s AI assistant into an “AI productivity platform” thanks to the addition…

OpenAI brings its o1 reasoning model to its API — for certain developers

OpenAI is bringing o1, its “reasoning” AI model, to its API — but only for certain developers to start. Starting today, o1 will begin rolling out to devs in OpenAI’s “tier 5” usage category, the company said. To qualify for tier 5, developers have to spend at least $1,000 with OpenAI and have an account…

Classroom Manager: Online Classroom Management, Instruction, and Learning Made Easy

Technology is transforming teaching and learning in today’s classrooms by providing teachers and students with an ever-increasing array of digital tools and resources. The possibilities for innovation are endless, from video conferencing to virtual reality and artificial intelligence (AI). While implementing these tools comes with a learning curve, teachers are embracing them due to their…

Google joins $90M investment into Cassava to bolster Africa’s digital infrastructure

With cloud spend continuing to surge, tech companies are scrambling to meet demand for the necessary infrastructure, with the growing need for AI compute only adding fuel to the fire. By way of example, Microsoft and BlackRock have created a $30 billion fund to support new data centers and energy infrastructure for the burgeoning AI…

Google says customers can use its AI in ‘high-risk’ domains, so long as there’s human supervision

Google has changed its terms to clarify that customers can deploy its generative AI tools to make “automated decisions” in “high-risk” domains, like healthcare, so long as there’s a human in the loop. According to the company’s updated Generative AI Prohibited Use Policy, published on Tuesday, customers may use Google’s generative AI to make “automated…

UK consults on opt-out model for training AIs on copyrighted content

The U.K. government is consulting on an opt-out copyright regime for AI training that would require rights holders to take active steps if they don’t want their intellectual property to become free AI training fodder. The rise of generative AI models that are trained on vast quantities of data has brought intellectual property concerns to…

Cavelo CEO on Bringing Data & Security Platform Exclusively Through Channel

Data asset discovery and classification vendor Cavelo was founded in 2020 to alleviate budgetary and skill restrictions that keep businesses from securing their organizations. In 2024, the company shifted to focus entirely on operating through the channel with MSP, MSSP, and VAR relationships. Channel Insider spoke with Cavelo CEO James Mignacca to learn more about…

Video: The Good, The Bad, And The Ugly Of AI With ABM Technology Group

In Part 2 of this interview, Zac Paulson, Director of Product and Strategy at ABM Technology Group, explains to Channel Insider: Partner POV host Katie Bavoso the unfortunate trend of clients accepting a cybersecurity strategy and related solutions only after they’ve had a breach or close call. He says it’s driven his business to not…

The Cybersecurity Stories that Defined 2024 in the Channel

More than ever, cybersecurity posture is an incredibly important aspect of the IT channel, with wide-ranging implications. As we continue to generate colossal amounts of data, protecting systems and clients has become a challenging task that requires partnerships, new emerging solutions, and acquisitions to overcome such a challenge. Over the course of 2024, there have…

Code Assist, Google’s enterprise-focused coding assistant, gets third-party tools

Google on Tuesday announced support for third-party tools in Gemini Code Assist, its enterprise-focused AI code completion service. Code Assist launched in April as a rebrand of a similar service Google offered under its now-defunct Duet AI branding. Available through plug-ins for popular dev environments like VS Code and JetBrains, Code Assist is powered by Google’s Gemini…

DEF CON 32 – Leveraging Private APNs For Mobile Network Traffic Analysis

Author/Presenter: Aapo Oksman Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel. Permalink The post DEF CON 32 – Leveraging Private APNs For Mobile Network Traffic Analysis appeared first…

Next-gen cybercrime: The need for collaboration in 2025

Cybercrime is a relentless and evolving threat to organizations worldwide. However, with the right insights, we can significantly enhance our security, mitigate risks, and stay ahead of these criminals. FortiGuard Labs’ Cyberthreat Predictions for 2025 report is designed to provide exactly these insights. It identifies emerging threat trends for the coming year and offers actionable…

Slip Robotics snags $28M for its bots that can load a truck in five minutes

Drop by any given loading dock and a buzz of forklifts — loaded up with goods — can be spotted maneuvering in and out of truck trailers. This logistical dance can take up to an hour to fill a trailer, leaving truck drivers in idle limbo. The founders of Atlanta-based Slip Robotics say they’ve developed…

5 Modern Computer Safety Tips You Should Know About

Protecting your computer in the hyper-connected world of today goes beyond merely preventing bothersome viruses. Smarter, quicker, and far more invasive than ever before are modern dangers. Cybercriminals no longer depend on simple strategies; they leverage flaws, fool unsuspecting consumers, […] The post 5 Modern Computer Safety Tips You Should Know About appeared first on…

SoundCloud introduces a cheaper plan for artists

Music streaming platform SoundCloud announced Tuesday that it is introducing a new, cheaper paid plan for artists simply called Artist, while renaming its Next Pro plan to Artist Pro. The new basic tier will cost $39 per year and put some limits on features like track amplification, distribution, monetization, and AI mastering. Artists subscribing to…

FTC bans hidden junk fees in short-term lodging, live-event ticket prices

The U.S. Federal Trade Commission passed a rule on Tuesday banning hidden “junk fees” for live events, hotels, and vacation rentals. The agency says the new rule prohibits “bait-and-switch pricing,” and other practices that hide total prices and bury junk fees in the live-event ticketing and short-term lodging industries, noting that these “unfair and deceptive”…

WordPress Appliance - Powered by TurnKey Linux