Tag Archives: Biz & IT

Claude published malicious code to the Internet and attacked 3 real companies

Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities. The events, which Anthropic revealed Thursday, are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks,… Read More: Claude published malicious code to the Internet and attacked 3… »

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday. Proofpoint and the… Read More: Max-severity Exchange server flaw under active exploitation by Kremlin hackers »

Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

Mythos helped to find a new meet-in-the-middle technique that relies on a Möbius Bridge, a more sophisticated fingerprinting algorithm used in meet-in-the-middle attacks. Using it, Green said, the code Mythos produced was able to reduce the number of required inputs to 289. Anthropic said that savings can reduce the time required for such attacks by… Read More: Mythos attack on 3rd-round PQC algorithm candidate puts it out… »

We now have a better understanding how OpenAI hacked into Hugging Face

Last week’s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product’s developer, said Monday. In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted… Read More: We now have a better understanding how OpenAI hacked into… »

Microsoft unveils AI security tools it says outperform competing platforms

Microsoft said MDASH with MAI-Cyber-1-Flash received a 96 percent score on CyberGYM, a standard benchmark test. The rating is 12 points higher than Anthropic’s Mythos and also beats Google Gemini and OpenAI GPT. The new MDASH costs half as much to use as the previous MDASH offering. The second tool Microsoft announced on Monday is… Read More: Microsoft unveils AI security tools it says outperform competing platforms »

TreeSize won’t renew perpetual-license support unless users subscribe

Making these available for download indefinitely and without restriction is something we consider a risk to our customers, particularly in business environments. There’s also the technical and organizational overhead of maintaining and supporting old versions and their associated keys indefinitely. Although TreeSize says this is a long-standing policy, the backlash highlights the disconnect between what… Read More: TreeSize won’t renew perpetual-license support unless users subscribe »

HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs

The agency also fined 21 HP resellers 35.2 million rupees (about $365,335). In a separate order, the CCI said that WhatsApp records showed that HP and 16 of its Tier-2 reseller partners operated “in a collusive arrangement” and that the messages show the companies engaging in “bid rigging, including cover bidding, price fixation, and customer… Read More: HP fined 1.4 billion rupees for “cartelization” of ink cartridges,… »

Now, even Russia’s most elite hackers are using Clickfix to infect devices

One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning. Clickfix has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites… Read More: Now, even Russia’s most elite hackers are using Clickfix to… »

Energy IPOs surge as investors hunt for ways to play AI boom

Investor interest in these IPOs comes amid growing concerns over whether hyperscalers, whose shares have soared in recent years, will be able to convert their huge spending into profits. Many traders are instead starting to look at smaller companies or those in other sectors that are likely to benefit from this wave of investment. Fervo… Read More: Energy IPOs surge as investors hunt for ways to play… »

Sheetz is quitting VMware, migrating 11,000 virtual machines

Automation and [SvHCI’s VMware] VM Import Utility were absolutely vital to scaling this migration. Operating in a 24/7/365 retail environment meant that minimizing business disruption was critical. It required meticulous planning and heavy automation to ensure our store operations ran as smoothly as possible throughout the entire transition. SvHCI product maturity in relation to APIs… Read More: Sheetz is quitting VMware, migrating 11,000 virtual machines »