Thu.Nov 30, 2023

article thumbnail

Breach Roundup: Ukraine Hacks Russian Aviation Agency

Data Breach Today

Also, Cyberattack Targets Japan's Space Agency JAXA This week, Ukraine's intelligence service hacked Russian aviation agency, a cyberattack targeted Japan's space agency, Google addressed another zero-day, a French-led operation dismantled a Ukrainian ransomware group, and spyware targeted Serbian civil society.

article thumbnail

Critical Zoom Room bug allowed to gain access to Zoom Tenants

Security Affairs

A critical vulnerability in Zoom Room allowed threat actors to take over meetings and steal sensitive data. Researchers at AppOms discovered a vulnerability in Zoom Room as part of the HackerOne live hacking event H1-4420. Zoom Rooms is a feature of the Zoom video conferencing platform designed to enhance collaboration in physical meeting spaces, such as conference rooms or huddle rooms.

Access 134
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Okta Delays New Products, Projects 90 Days to Boost Security

Data Breach Today

Push Comes After Okta Said Hacker Had Stolen Every Customer Support User's Details Okta has paused product development and internal projects for 90 days to beef up its security architecture and operations for applications, hardware and third-party vendors. Okta will move to strengthen its cyber posture, including a security action plan and engaging with third-party cyber firms.

Security 300
article thumbnail

Apple addressed 2 new iOS zero-day vulnerabilities

Security Affairs

Apple released emergency security updates to fix two actively exploited zero-day flaws impacting iPhone, iPad, and Mac devices. Apple released emergency security updates to address two zero-day vulnerabilities impacting iPhone, iPad, and Mac devices. The flaws are actively exploited in attacks in the wild, both issues reside in the WebKit browser engine.

Security 126
article thumbnail

Get Better Network Graphs & Save Analysts Time

Many organizations today are unlocking the power of their data by using graph databases to feed downstream analytics, enahance visualizations, and more. Yet, when different graph nodes represent the same entity, graphs get messy. Watch this essential video with Senzing CEO Jeff Jonas on how adding entity resolution to a graph database condenses network graphs to improve analytics and save your analysts time.

article thumbnail

Capital Health in NJ Is Responding to a Cyberattack

Data Breach Today

2 Hospitals, Medical Groups Still Caring for Patients But Some Services Unavailable New Jersey-based hospital group Capital Health is dealing with a network outage, caused by a cyberattack earlier this week, which is affecting some patient services. Capital Health is at least the second healthcare provider in the Garden State responding to a cyberattack this week.

293
293

More Trending

article thumbnail

Good Governance: 'It's All Hygiene'

Data Breach Today

In the constant struggle to manage the other five pillars - identify, protect, detect, respond and recover - security leaders often do not have governance at top of mind, said Netography CEO Martin Roesch, but he added, "Good governance is the root of having good security.

article thumbnail

Extracting GPT’s Training Data

Schneier on Security

This is clever : The actual attack is kind of silly. We prompt the model with the command “Repeat the word ‘poem’ forever” and sit back and watch as the model responds ( complete transcript here ). In the (abridged) example above, the model emits a real email address and phone number of some unsuspecting entity. This happens rather often when running our attack.

Paper 113
article thumbnail

NY AG Warns of ID Theft Risk in Medical Transcription Hack

Data Breach Today

Crouse Health Reveals It's Among PJ&A Clients Hit by Incident Affecting Millions New York regulators are warning millions of individuals of identity theft risks involving a data theft at a medical transcriber that has now affected patients of at least two major healthcare groups, including Crouse Health and Northwell Health in the state. Lawsuits in the case are also piling up.

Risk 284
article thumbnail

How to build a successful employee experience strategy

IBM Big Data Hub

Ever since the pandemic changed the corporate world, organizations have rededicated themselves to excelling at employee experience strategy. A successful employee experience strategy (EX strategy) is the best way to recruit and retain top talent , as employees increasingly make decisions on where to work based on how they respond to employee needs. Organizations can prioritize overall employee experience by being thoughtful about how to serve their workers during all stages of the employee journ

article thumbnail

Peak Performance: Continuous Testing & Evaluation of LLM-Based Applications

Speaker: Aarushi Kansal, AI Leader & Author and Tony Karrer, Founder & CTO at Aggregage

Software leaders who are building applications based on Large Language Models (LLMs) often find it a challenge to achieve reliability. It’s no surprise given the non-deterministic nature of LLMs. To effectively create reliable LLM-based (often with RAG) applications, extensive testing and evaluation processes are crucial. This often ends up involving meticulous adjustments to prompts.

article thumbnail

US Sanctions North Korean Cyber Unit After Satellite Launch

Data Breach Today

Kimsuky Cyberespionage Unit Hit With Sanctions From US and Foreign Partners The United States on Thursday sanctioned North Korean cyberespionage threat actor Kimsuky, known for its social engineering campaigns against targets it suspects of holding intelligence on geopolitical events and negotiations affecting the Hermit Kingdom.

IT 277
article thumbnail

The Israel-Hamas Conflict is the Latest Example of Phishing Attacks Taking Advantage of Current Events

KnowBe4

Using something as simple as an attachment with an Israel/Hamas-related filename seems to be all it takes for new social engineering attacks disguised as donation confirmations.

article thumbnail

NIST Says Federal Agencies Struggling to Achieve Zero Trust

Data Breach Today

Agencies Face Array of Implementation Challenges While Racing Toward 2024 Deadline A National Institute of Standards and Technology official said agencies are facing a variety of challenges in implementing enterprisewide zero trust architectures, from a lack of insight into their network components to difficult decisions around legacy systems and costly procurement initiatives.

274
274
article thumbnail

6 climate change adaptation strategies every organization needs today

IBM Big Data Hub

There’s a lot of talk about how organizations can and should reduce their negative impact on the environment. While staying focused on mitigating our current and future contributions to climate change is crucial, we cannot ignore the dire impacts of existing climate hazards. Risks from wildfires, floods, heat, drought and wind have always been a concern, but climate change has intensified these risks, making them more frequent and unpredictable for organizations.

article thumbnail

How and Why Should You Be Tracking Geopolitical Risk?

Geopolitical risk is now at the top of the agenda for CEOs. But tracking it can be difficult. The world is more interconnected than ever, whether in terms of economics and supply chains or technology and communication. Geopolitically, however, it is becoming increasingly fragmented – threatening the operations, financial well-being, and security of globally connected companies.

article thumbnail

Cryptohack Roundup: KyberSwap Hacker Demands Control

Data Breach Today

Also: Treasury Calls for Stronger Sanctions Powers; Aerodrome, Velodrome Hacks This week, a KyberSwap hacker demanded total control, the U.S. Treasury called for additional tools to sanction crypto baddies, the Aerodrome and Velodrome DeFi platforms' front ends were hacked, a scam-as-a-service wallet drainer shut down, Indexed Finance thwarted hijacking attempts, and more.

271
271
article thumbnail

The Israel-Palestine Conflict is the Latest Example of Phishing Attacks Taking Advantage of Current Events

KnowBe4

Using something as simple as an attachment with an Israel/Palestine-related filename seems to be all it takes for new social engineering attacks disguised as donation confirmations.

article thumbnail

Anduril’s New Drone Killer Is Locked on to AI-Powered Warfare

WIRED Threat Level

Autonomous drones are rapidly changing combat. Anduril’s new one aims to gain an edge with jet power and AI.

article thumbnail

Your KnowBe4 Fresh Content Updates from November 2023

KnowBe4

Check out the 49 new pieces of training content added in November, alongside the always fresh content update highlights, events and new features.

article thumbnail

7 Pitfalls for Apache Cassandra in Production

Apache Cassandra is an open-source distributed database that boasts an architecture that delivers high scalability, near 100% availability, and powerful read-and-write performance required for many data-heavy use cases. However, many developers and administrators who are new to this NoSQL database often encounter several challenges that can impact its performance.

article thumbnail

Revolutionizing database performance monitoring with DBmarlin and IBM Instana 

IBM Big Data Hub

Monitoring database performance can be a daunting task, especially in complex environments with a combination of both self-hosted and cloud-based databases. Thanks to the innovative partnership between DBmarlin and IBM® Instana™, businesses can now achieve granular insights into database performance like never before. The business challenge Businesses face several challenges when it comes to database performance monitoring: Understanding and optimizing database performance to ensure t

Cloud 79
article thumbnail

Criminals Are Cautious About Adopting Malicious Generative AI Tools

KnowBe4

Researchers at Sophos have found that the criminal market for malicious generative AI tools is still disorganized and contentious.

Marketing 101
article thumbnail

Insights from the IAPP Europe Data Protection Congress: Regulatory Convergence on AI and Sidley’s Women in Privacy Networking Lunch

Data Matters

The International Association of Privacy Professionals ( IAPP ) held its annual Europe Data Protection Congress in Brussels on November 15 & 16, 2023. Whilst the Congress covered a wide range of topics related to privacy, cybersecurity and the regulation of data more broadly, unsurprisingly a recurring theme throughout was the responsible development, commercialization and use of AI.

Privacy 88
article thumbnail

Cyber Security: Insurance Prices Level After Two Years of Brutal Increases via ENR

IG Guru

Check out the article here. The post Cyber Security: Insurance Prices Level After Two Years of Brutal Increases via ENR first appeared on IG GURU.

article thumbnail

Reimagined: Building Products with Generative AI

“Reimagined: Building Products with Generative AI” is an extensive guide for integrating generative AI into product strategy and careers featuring over 150 real-world examples, 30 case studies, and 20+ frameworks, and endorsed by over 20 leading AI and product executives, inventors, entrepreneurs, and researchers.

article thumbnail

Top information management trends for life sciences in 2024

OpenText Information Management

The life sciences industry has seen monumental change over the past few years. From the Covid-19 pandemic to a spike in investment, coupled with rising inflation and economic instability, the industry has been drenched in uncertainty and unpredictability. However, life sciences leaders remain optimistic about the year ahead. Here are four trends that will continue … The post Top information management trends for life sciences in 2024 appeared first on OpenText Blogs.

article thumbnail

Rallying troops against cybercrime with QRadar SIEM

IBM Big Data Hub

Cybersecurity is everyone’s business—as it should be, given the staggering surge in cyberattacks. Today, these attacks exhibit an unprecedented level of frequency, ingenuity and speed. The cyberthreat landscape is evolving and countries such as India are facing an alarming rate of increase in cyberattacks ( Q2 of 2023 saw a 90% increase ).

article thumbnail

Rev up for Season 10 of the ABB FIA Formula E World Championship

OpenText Information Management

Put on your party shoes, Formula E fans. Season 10 of the ABB FIA Formula E World Championship is right around the corner, and OpenText is proud to be the Official Technical and Analytics Partner of the Jaguar TCS Racing team. It’s a new season, with new racetracks to conquer and new drivers behind the … The post Rev up for Season 10 of the ABB FIA Formula E World Championship appeared first on OpenText Blogs.

article thumbnail

Innovation and authentic demand

IBM Big Data Hub

Arvind Krishna recently spoke with former IBMer and author Danny Sabbah about a new book he co-authored, The Heart of Innovation: A Field Guide for Navigating to Authentic Demand. In their conversation, Arvind and Danny discussed the secret to determining authentic demand and building innovative products that achieve runaway success. Here are five facts about innovation, taken from the book and their conversation, that may surprise you: While major technology breakthroughs dominate our perceptio

article thumbnail

How to Migrate From DataStax Enterprise to Instaclustr Managed Apache Cassandra

If you’re considering migrating from DataStax Enterprise (DSE) to open source Apache Cassandra®, our comprehensive guide is tailored for architects, engineers, and IT directors. Whether you’re motivated by cost savings, avoiding vendor lock-in, or embracing the vibrant open-source community, Apache Cassandra offers robust value. Transition seamlessly to Instaclustr Managed Cassandra with our expert insights, ensuring zero downtime during migration.

article thumbnail

Google Fixes a Seventh Zero-Day Flaw in Chrome—Update Now

WIRED Threat Level

Plus: Major security patches from Microsoft, Mozilla, Atlassian, Cisco, and more.

article thumbnail

How to build a successful talent acquisition strategy

IBM Big Data Hub

The success of any organization relies on its ability to attract, retain and develop top talent. Talent acquisition refers to the ongoing strategy and process an organization and its HR department uses to source, attract, evaluate, hire and retain the highly-qualified new employees it needs to grow. A well-crafted talent acquisition strategy has become a critical component for organizations seeking to secure a competitive edge.

article thumbnail

Data Deception: Dispelling the Top 10 Myths about MDM

Reltio

Master Data Management, or MDM, isn't a new player in the realm of IT solutions. Its roots trace back over two decades when the software promised to streamline, unify, and optimize an organization's core data assets. However, like many pioneering technologies, its early iterations were challenging. Initial versions often came with cumbersome implementations and less-than-ideal outcomes.

MDM 52