BankInfoSecurity.com
Mopping Up the Mess: Best Practices for Data Hygiene | Masterclass Series
1 week 4 days ago
Supply Chain Attack Targets GitHub Repositories and Secrets
1 week 4 days ago
Over 23,000 Code Repositories at Risk After Malicious Code Added to GitHub Actions
Attackers subverted a widely used tool for software development environment GitHub, potentially allowing them to steal secrets from thousands of private code repositories as well as compromise other widely used "open source libraries, binaries and artifacts" that use the tool, experts warned.
Attackers subverted a widely used tool for software development environment GitHub, potentially allowing them to steal secrets from thousands of private code repositories as well as compromise other widely used "open source libraries, binaries and artifacts" that use the tool, experts warned.
Rethinking Insider Risk in an AI-Driven Workplace
1 week 4 days ago
Carnegie Mellon CERT's Dan Costa on Addressing Root Causes of Insider Risk
As layoffs and AI-driven workflows reshape workplace security, insider risk is becoming more complex. Dan Costa, technical manager for the CERT division at Carnegie Mellon University's Software Engineering Institute, outlines proactive strategies to manage insider risk effectively.
As layoffs and AI-driven workflows reshape workplace security, insider risk is becoming more complex. Dan Costa, technical manager for the CERT division at Carnegie Mellon University's Software Engineering Institute, outlines proactive strategies to manage insider risk effectively.
Google, OpenAI Push Urges Trump to Ease AI Export Controls
1 week 4 days ago
AI Giants Also Like 'Fair Use' Exemptions for Copyrighted Material
OpenAI and Google laid out visions for regulation in response to the Trump administration's AI Action Plan, which aims to help the United States maintain technological lead over China. Both companies want Biden-era export controls lightened.
OpenAI and Google laid out visions for regulation in response to the Trump administration's AI Action Plan, which aims to help the United States maintain technological lead over China. Both companies want Biden-era export controls lightened.
Accounting Firm Notifying 217,000 of Health Data Hack
1 week 4 days ago
CPA Says Clients' Employee Benefit Plan Information Compromised in 2024 Incident
A certified public accounting firm that provides services to labor unions, non-profits and other organizations for employee benefit plans is notifying nearly 217,000 people of a 2024 hack. The firm is already facing at least five proposed federal class action lawsuits related to the breach.
A certified public accounting firm that provides services to labor unions, non-profits and other organizations for employee benefit plans is notifying nearly 217,000 people of a 2024 hack. The firm is already facing at least five proposed federal class action lawsuits related to the breach.
Beyond Defense: Active Directory Recovery and Business Resilience
1 week 5 days ago
DeepSeek-R1 Can Almost Generate Malware
2 weeks ago
DeepSeek Comes Very Close to Producing a Keylogger and Ransomware
Security researchers used the Chinese DeepSeek-R1 artificial intelligence reasoning model to come close to developing ransomware variants and keyloggers with evasion capabilities. The model needs prompt engineering and its output requires code editing.
Security researchers used the Chinese DeepSeek-R1 artificial intelligence reasoning model to come close to developing ransomware variants and keyloggers with evasion capabilities. The model needs prompt engineering and its output requires code editing.
360 Privacy Raises $36M to Expand Threat Protection Services
2 weeks ago
Investment to Scale Engineering, Expansion From Data Deletion to Threat Reduction
Executive digital protection firm 360 Privacy raised $36 million to expand its engineering team and boost its ability to remove sensitive data from brokers. The company is shifting from a data deletion focus to broader threat mitigation, tackling risks from digital tracking and location data leaks.
Executive digital protection firm 360 Privacy raised $36 million to expand its engineering team and boost its ability to remove sensitive data from brokers. The company is shifting from a data deletion focus to broader threat mitigation, tackling risks from digital tracking and location data leaks.
Insurer Notifying 335,500 Customers, Agents, Others of Hack
2 weeks ago
Texas Incident Is the Largest Breach Reported by a Health Plan So Far in 2025
A Texas-based insurance firm is notifying more than 335,500 people of a December 2024 hack involving their sensitive personal and health information. The breach affects many - but not all - of the company's policyholders, agents and insurance carrier partners in multiple states.
A Texas-based insurance firm is notifying more than 335,500 people of a December 2024 hack involving their sensitive personal and health information. The breach affects many - but not all - of the company's policyholders, agents and insurance carrier partners in multiple states.
Federal Judges Block Trump's Mass Firings of Federal Workers
2 weeks ago
Restraining Order Allows Dismissed Cyber Defense Agency Employees to Return to Work
A temporary restraining order against the Trump administration's efforts to shrink the size of the federal workforce will allow thousands of probationary employees to return to work as experts warn the purge threatens national cybersecurity.
A temporary restraining order against the Trump administration's efforts to shrink the size of the federal workforce will allow thousands of probationary employees to return to work as experts warn the purge threatens national cybersecurity.
Groups From China, Russia, Iran Hitting OT Systems Worldwide
2 weeks 1 day ago
Threat Groups Are Mapping OT Networks for Future Targeting, Warns Dragos
A China-linked threat group called Voltzite is targeting operational technology systems at critical infrastructure organizations worldwide to steal network diagrams, OT operating instructions and information about geographic information systems, said cybersecurity firm Dragos.
A China-linked threat group called Voltzite is targeting operational technology systems at critical infrastructure organizations worldwide to steal network diagrams, OT operating instructions and information about geographic information systems, said cybersecurity firm Dragos.
Radiology Clinic, Hospital Among Latest Rural Cyber Victims
2 weeks 1 day ago
IT Outages Are Affecting Patient Services, NC Practice Is 'Temporarily Closed'
A small North Carolina radiology practice and a 25-bed Pennsylvania hospital and are among the latest rural healthcare providers struggling to recover from recent cyberattacks that are disrupting their technology operations and affecting patient care services. How will this end up?
A small North Carolina radiology practice and a 25-bed Pennsylvania hospital and are among the latest rural healthcare providers struggling to recover from recent cyberattacks that are disrupting their technology operations and affecting patient care services. How will this end up?
Sola Security Debuts AI-Powered SOAR Product with $30M Boost
2 weeks 1 day ago
Funds Will Support Next-Gen Security Orchestration and Response, Eliminate Complexity
With $30 million in funding, Sola Security is launching an AI-driven, self-service SOAR platform designed for easy adoption across security, IT, and DevOps teams. The Israeli startup aims to disrupt traditional security automation by lowering technical barriers.
With $30 million in funding, Sola Security is launching an AI-driven, self-service SOAR platform designed for easy adoption across security, IT, and DevOps teams. The Israeli startup aims to disrupt traditional security automation by lowering technical barriers.
EU Seeks US Assurances on Trans-Atlantic Data Flows
2 weeks 1 day ago
Worries Grow Over Data Privacy Framework Stability
A European official said he received assurances the U.S. is committed to preserving the legal framework underpinning commercial data flows across the Atlantic. The Data Privacy Framework already faces legal challenges in Europe, but fears of its durability compounded with the Trump administration.
A European official said he received assurances the U.S. is committed to preserving the legal framework underpinning commercial data flows across the Atlantic. The Data Privacy Framework already faces legal challenges in Europe, but fears of its durability compounded with the Trump administration.
Curbing Fraud With Stronger Digital Identity Proofing
2 weeks 1 day ago
Reuben Stewart of PNC Discusses Ways to Move Away from Using Static Data
Digital identity proofing is a major challenge for banks and financial services firms. Many organizations rely on static data, such as Social Security numbers, which fraudsters can easily steal and misuse, said Reuben Stewart, digital identity lead at PNC Bank.
Digital identity proofing is a major challenge for banks and financial services firms. Many organizations rely on static data, such as Social Security numbers, which fraudsters can easily steal and misuse, said Reuben Stewart, digital identity lead at PNC Bank.
Lawmakers Take Another Stab to Improve Patient ID Matching
2 weeks 2 days ago
Bipartisan 'Match IT Act' Aims to Reduce Risk of Medical Mistakes, Privacy Mishaps
Two Congressmen are taking another bipartisan stab at passing legislation aimed at improving patient identity matching to help reduce mistakes that put patient privacy and safety at risk. The lawmakers have introduced similar provisions in the past. Will the proposals gain traction this time?
Two Congressmen are taking another bipartisan stab at passing legislation aimed at improving patient identity matching to help reduce mistakes that put patient privacy and safety at risk. The lawmakers have introduced similar provisions in the past. Will the proposals gain traction this time?
Zut Alors! Cyberattacks Targeting France Surged in 2024
2 weeks 2 days ago
The Edge Device Hacking Wave Hasn't Spared French Companies
France playing host to the Olympics resulted in a surge of cyberattacks requiring intervention of the state cybersecurity agency, it said in an annual report also flagging an uptick in attacks levied against network edge devices. The games went smoothly.
France playing host to the Olympics resulted in a surge of cyberattacks requiring intervention of the state cybersecurity agency, it said in an annual report also flagging an uptick in attacks levied against network edge devices. The games went smoothly.
Pentera Secures $60M to Boost AI-Powered Security Validation
2 weeks 2 days ago
Series D Funding to Drive U.S. Growth and AI Advancements in Cybersecurity
Pentera has raised $60 million in Series D funding to expand its presence in the U.S. and accelerate AI-driven innovations in security validation. CEO Amitai Ratzon says the company is focused on advancing automated testing and strengthening its leadership in exposure validation.
Pentera has raised $60 million in Series D funding to expand its presence in the U.S. and accelerate AI-driven innovations in security validation. CEO Amitai Ratzon says the company is focused on advancing automated testing and strengthening its leadership in exposure validation.
CISA Defunds Threat-Sharing Hubs for States and Elections
2 weeks 2 days ago
Cyber Defense Agency Axes Funding for Key ISACs as Trump Shifts Federal Priorities
The Cybersecurity and Infrastructure Security Agency is eliminating $10 million in annual funding for two key cybersecurity hubs supporting states and local elections as agency officials tell Information Security Media Group the move is aimed at eliminating waste and realigning priorities.
The Cybersecurity and Infrastructure Security Agency is eliminating $10 million in annual funding for two key cybersecurity hubs supporting states and local elections as agency officials tell Information Security Media Group the move is aimed at eliminating waste and realigning priorities.
Checked
6 hours 30 minutes ago
BankInfoSecurity.com RSS News Feeds on bank information security news, regulations, blogs and education
BankInfoSecurity.com feed