In late September 2024, reporting surfaced that a China state-linked group, later widely known as Salt Typhoon, had deeply compromised major broadband and telecommunications providers. The […]
In August 2024, researchers demonstrated that Slack’s AI assistant could be manipulated through prompt injection to surface information from private channels the requesting user should not […]
In August 2024, details emerged about a breach at National Public Data, a background-check data broker, exposing a vast trove of personal records including names, addresses, […]
At Black Hat USA in August 2024, a researcher presented Windows Downdate, a technique that abuses the Windows Update process to roll a fully patched system […]
On July 19, 2024, a faulty content update to CrowdStrike’s Falcon sensor caused millions of Windows machines worldwide to crash into a boot loop. Airlines, hospitals, […]
By mid-July 2024, the scope of the attacks against Snowflake customer accounts had grown, with more organizations disclosing that data had been exported from cloud environments […]
On July 1, 2024, researchers disclosed regreSSHion, tracked as CVE-2024-6387, an unauthenticated remote code execution flaw in OpenSSH on glibc-based Linux systems. OpenSSH is one of […]
In mid-June 2024, a ransomware attack against CDK Global, the dealer management platform used by thousands of car dealerships across North America, forced the company to […]
In June 2024, Microsoft faced a sharp backlash over Recall, a feature for its AI-enabled PCs that periodically captures screenshots of user activity so it can […]