Latest Technology News

HEAT attacks: A new spin on browser exploit techniques

HEAT attacks

It is no secret that the web browser is becoming an increasingly popular target for cybercriminals looking to compromise an endpoint to gain entry to a network. The increased business use of the browser (remote work) on networks that lack the perimeter security infrastructure of traditional campus networks has made them easier to exploit. In recent months, we have seen an increase in cyberattacks and data leaks caused by browser-related security incidents, including a data breach caused by a phishing attack on Dropbox that gained the hacker access to over 100 of the company’s code repositories in November, and December’s CircleCi breach resulting from an infection of information-stealing malware.

Highly Evasive Adaptive Threats, or HEAT attacks, are a new spin on existing browser exploit techniques that make them much more dangerous. These attacks exploit browsers by leveraging features and tools to bypass traditional security controls and then attack from within, including compromising credentials or deploying ransomware. Comprised of known tactics such as phishing messages, HTML smuggling and dynamic drive-by downloads, these attacks frequently target SaaS applications and other web-based tools that are critical to productivity.

Continue reading

Reactive approach to cybersecurity is a problem for organizations

A new survey shows respondents feel a reactive approach to security is problematic for their organizations. 90 percent of them say they struggle with challenges when they react to cyber security problems as they arise.

The study, conducted by Forrester Consulting for WithSecure, shows most organizations currently approach cyber security on a reactive basis, with 60 percent of respondents saying they react to individual cyber security problems as they arise.

Continue reading

Microsoft is preparing to bring ads to AI-powered Bing Chat

Bing Chat

In a move that will come as a surprise to just about no one, Microsoft has announced that it is "exploring" the idea of adding advertising to its GPT-4-based Bing Chat.

The company is framing the addition of ads to the AI-powered chat bot as a means of "driving more traffic and value to publishers from the new Bing". Microsoft says that it is seeking to do this by, among other things, "pioneering the future of advertising".

Continue reading

Microsoft Defender caught issuing false warnings about safe URLs

Microsoft Defender on a laptop

Microsoft has confirmed an issue with Defender which resulted in users being shown warnings about URLs that were entirely safe. The emails advised admins that "a potentially malicious URL click was detected", with affected users complaining that legitimate URLs, such as Zoom meeting links, were being flagged up as dangerous.

In addition to the false positives, the "View alerts" link included in the warning emails sent out to admins failed to provide any further information that could prove useful.

Continue reading

WinSnap 6.01 unveils modern facelift, major reorganization of tools

NTWind Software has unveiled a major new version of its powerful shareware screen capture tool for Windows. WinSnap 6.0.1 comes with a Windows 11-friendly facelift, a reorganization of its major tools and some useful improvements.

The biggest improvement is immediately apparent when the program first opens -- it now boasts a modern UI in keeping with the Windows 11 desktop, complete with support for automatic switching between dark and light modes.

Continue reading

The Last of Us Part 1 bombs on PC

The long awaited first part of the previously PlayStation exclusive The Last of Us game has been released on March 28, 2023 on Steam. The remastered version of the game has received praising reviews for PlayStation, but when you check the Steam ratings one day after release, you notice that they are mostly negative on the site.

In numbers, more than 4,200 of the 5,740 reviews are mostly negative, and this leads to the question how this could have happened. From Game of the Year to one that sits at the bottom of Steam’s ranking charts.

Continue reading

Get 'Difficult Decisions' (worth $18) for FREE

What do you do when the algorithm doesn’t have the answer?

Countless tools and frameworks claim to make decisions objective and bias-free. But in reality, the defining decisions that leaders face are complex ones with subjective information sources and conflicting courses of action. That’s why the toughest choices are left to the leaders, and that’s why formulas won’t answer them.

Continue reading

System76 refreshes Gazelle Linux laptop with Intel Core i9-13900H CPU and NVIDIA GeForce RTX 3050 GPU

Today, System76 unveils the latest generation of its Gazelle laptop. The Gazelle is a powerful and versatile laptop that is perfect for a wide range of users. It is a great choice for creative professionals, gamers, and anyone who needs a powerful laptop for work or play.

The Gazelle is powered by the 14-core Intel Core i9-13900H processor, which offers a max clock speed of 5.4Ghz. This new CPU provides up to 8 percent better performance compared to the previous generation of the Gazelle laptop. The computer also features an NVIDIA GeForce RTX 3050 GPU, which delivers exceptional performance for both gaming and graphics-intensive tasks.

Continue reading

Amid ChatGPT's rise to fame, how can enterprises work to eliminate AI bias?

Artificial Intelligence Bias

Artificial intelligence continues to hog the headlines, as more people discover the power of tools like OpenAI’s DALL-E 2 and especially ChatGPT. These futuristic-seeming tools work by taking a human’s query or prompt and returning an intelligent textual or visual response.

From an enterprise perspective, AI adoption is growing rapidly. According to Forrester, spending on AI software is set to accelerate from $33 billion in 2021 to $64 billion in 2025 -- growing twice as fast as the overall software market. But while tools like ChatGPT may seem like magic, it’s important to understand these solutions aren’t perfect.

Continue reading

60 percent of organizations have had authentication breaches in the last year

Passwordless authentication - Inscription on Blue Keyboard Key.

Insecure authentication is a primary cause of cyber breaches and cumbersome login methods take an unacceptable toll on employees and business productivity, according to a new report.

The 2023 State of Passwordless Security Report, released by HYPR and Vanson Bourne, shows that 60 percent of organizations have reported authentication breaches over the last 12 months and that three out of the top four attack vectors are connected to authentication.

Continue reading

Get 'Cloud Native Security' (worth $24) for FREE

Cloud Native Security delivers a detailed study into minimizing the attack surfaces found on today's Cloud Native infrastructure.

Throughout the work, hands-on examples walk through mitigating threats and the areas of concern that need to be addressed. The book contains the information that professionals need in order to build a diverse mix of the niche knowledge required to harden Cloud Native estates.

Continue reading

Smaller means safer as bigger businesses see more endpoint infections

Computer security

Of businesses with between 21 and 100 protected endpoints, only five percent encountered a malware infection in 2022. For smaller firms with one to 20 endpoints, the rate is 6.4 percent, but as companies grow so do infections.

For businesses between 101 and -500 endpoints the rate rises to 58.7 percent and over 500 it's 85.8 percent. These findings are from a new report by OpenText Cybersecurity which looks at the latest threats and risks to the small and medium business (SMB) and consumer segments.

Continue reading

Phishing emails soar as messages bypass standard email security solutions

A new report shows that 2022 saw a 569 percent increase in malicious phishing emails and a 478 percent increase in credential phishing-related threat reports published.

The report from Cofense also looks at emails bypassing SEGs and hitting users' inboxes and highlights that delivery methods for carrying out phishing campaigns continue to keep up with the advancement of technology. Cofense has witnessed a continued blending of tactics to make detection and mitigation even more difficult for organizations.

Continue reading

API attacker activity up 400 percent in six months

api

The latest State of API Security Report from Salt Security shows a 400 percent increase in unique attackers in the last six months.

In addition, around 80 percent of attacks happened over authenticated APIs. Not surprisingly, nearly half (48 percent) of respondents now say that API security has become a C-level discussion within their organization.

Continue reading

Getting the most value out of your data [Q&A]

folder stack

The past few years have seen a boom in digital transformation as enterprises have sought to modernize their operations to take advantage of a new, more flexible world of work.

But this change has often led to unwieldy data structures that are difficult to manage, which means that extracting value from the data is harder than it should be.

Continue reading

© 1998-2024 BetaNews, Inc. All Rights Reserved. Privacy Policy - Cookie Policy.