[MEDIUM] – CISA Releases Updated Insider Threat Mitigation Guide
CISA released an updated guide for organizations developing or improving insider-threat mitigation programs.
Cybersecurity, AI, etc.
CISA released an updated guide for organizations developing or improving insider-threat mitigation programs.
Researchers demonstrated RF-induced side channels recovering audio and appliance states on 11 commercial devices.
CISA added a ConnectWise ScreenConnect authorization flaw enabling file transfer and execution in active sessions to its KEV catalog.
Attackers are exploiting an unauthenticated arbitrary-file-upload flaw in the WordPress Super Forms plugin.
The U.S. Justice Department says a Conti ransomware conspirator received a four-year prison sentence.
Surfshark says an unauthorized party accessed a misconfigured internal test server; customer data and VPN services were unaffected.
Mantax Otax targets Android users with ransomware, data theft, credential harvesting, and device-control capabilities.
Anthropic reports disrupting AI misuse across cyber operations, surveillance, fraud, influence, weapons, and model distillation.
GitLab released 19.3.2, 19.2.6, and 19.1.8 with critical security fixes for self-managed installations.
Proofpoint identified four espionage-focused groups using BlueMoon to chain Chrome and Windows vulnerabilities.