Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

Arch Linux freezes AUR package adoptions after malware wave

Arch Linux freezes AUR package adoptions after malware wave
Arch Linux has temporarily frozen package adoptions in the Arch User Repository (AUR) after attackers used maintainer takeovers and orphaned packages to push malicious updates. The campaign reportedly affects dozens of packages and delivers a Linux infostealer with remote access and SSH-worm capabilities.

Source

Security and AI expert dismisses concerns about autonomous AI hacking as exaggerated

Security and AI expert dismisses concerns about autonomous AI hacking as exaggerated
Snehal Antani, CEO of Horizon3.ai, a cybersecurity firm that uses AI to autonomously probe organizations for real-world vulnerabilities, argues that claims of AI models hacking companies on their own are overstated. Currently, these systems perform well in controlled cyber range tests but face challenges against defended and deceptive production networks. Their limitations include greedy decision-making, poor adaptation in protected environments, overdependence on limited training data, and a tendency to interact with suspicious decoys even after recognizing them as traps. Nonetheless, the threat continues to grow as human hackers have access to virtually unlimited "AI interns" for uncovering vulnerabilities. Additionally, the rapid rise of vibe-coded applications and AI agents is expanding the pool of insecure systems vulnerable to attack.

Source

Azure makes CIS auditing native for Linux VMs

Azure makes CIS auditing native for Linux VMs
Microsoft has made native CIS Benchmark auditing generally available for Linux virtual machines, eliminating the need for separate compliance tools. Azure Machine Configuration now continuously checks Azure and Azure Arc-enabled Linux systems against CIS-certified benchmarks and surfaces the results through Azure management services.

Source

Google says AI helped Chrome fix 1,072 bugs

Google says AI helped Chrome fix 1,072 bugs
Google says AI-assisted security tools helped Chrome 149 and Chrome 150 fix 1,072 vulnerabilities—more than the 1,036 fixed across the previous 23 stable releases combined. The company is now using AI across Chrome’s vulnerability workflow and plans more frequent security updates, including a pilot for twice-weekly releases.

Source

Elastic and OpenAI use Elasticsearch to cut AI token use by 75%

Elastic and OpenAI use Elasticsearch to cut AI token use by 75%
Elastic says its expanded collaboration with OpenAI can reduce AI input-token consumption by up to 75% while increasing benchmark accuracy from 60% to 92%. The partnership uses Elasticsearch as a governed context layer for AI agents working with unstructured enterprise data, including documents, tickets, logs, metrics, traces, and security alerts.

Source

Hermes, powered by DeepSeek, launched autonomous cyberattacks

Hermes, powered by DeepSeek, launched autonomous cyberattacks
A threat actor used DeepSeek inside the open-source Hermes Agent framework to autonomously discover and attack internet-facing systems through Telegram commands. The operation was ultimately exposed when the agent started an HTTP file server that revealed API keys, exploit code, target lists, shell history, and session logs.

Source

Two-minute Teams calls can trigger Chaos ransomware attacks

Two-minute Teams calls can trigger Chaos ransomware attacks
A Microsoft Teams voice-phishing campaign tracked as STAC4749 is turning brief fake IT-support calls into ransomware incidents. Attackers used remote-access tools and custom `.top` domains to compromise dozens of organizations in the United States and Canada, with one attack reaching ransomware deployment in under 17 hours.

Source

❌