SAP security patches released this month address critical flaws in SQL Anywhere and Solution Manager. The updates mitigate risks that could enable system compromise if ignored. SAP customers …
CSC News
-
-
News & Resources
Pentagon Enforces New CMMC Requirements For Defense Contractors
by CSC Newsby CSC News 3 minutes readCMMC requirements are moving from promises to proof as the Pentagon advances its Cybersecurity Maturity Model Certification program. The Defense Department wants verified safeguards across the defense industrial …
-
News & Resources
Whisper-Leak LLM Side Channel Attack Exposes User Prompt Topics
by CSC Newsby CSC News 3 minutes readLLM side channel attack research known as Whisper-Leak shows attackers can infer prompt topics without viewing the text. The technique uses inference time signals to classify user intent …
-
News & Resources
Whisper-Leak: New LLM Side Channel Attack Targets User Prompts
by CSC Newsby CSC News 3 minutes readLLM side channel attack research is in the spotlight after a technique called Whisper-Leak showed that attackers can infer user prompt topics without direct access. Researchers demonstrated that …
-
News & Resources
Forbes AI Companies GitHub Secrets Exposed In Massive Security Breach
by CSC Newsby CSC News 3 minutes readAI companies GitHub secrets are under scrutiny after SecurityWeek reported exposed credentials across multiple Forbes AI 50 firms. Public repositories contained cloud keys and tokens. Researchers found access …
-
News & Resources
Critical RunC Container Escape Vulnerabilities Expose Docker Security Flaws
by CSC Newsby CSC News 3 minutes readrunC container escape vulnerabilities allow attackers to break isolation and reach the host. SecurityWeek reported multiple issues that affect runC users across platforms. The most severe issue, the …
-
News & Resources
OWASP Top 10 2021 Adds Two New Web Application Risk Categories
by CSC Newsby CSC News 3 minutes readOWASP Top 10 2021 adds two new risk categories that reset priorities for web application security. The update reflects testing data and observed attack behavior. It also clarifies …
-
News & Resources
CL0P Names 30 Victims In Massive Oracle EBS Ransomware Attack
by CSC Newsby CSC News 3 minutes readOracle EBS ransomware attack disclosures are mounting as the CL0P group names nearly 30 alleged victims tied to Oracle E-Business Suite. The activity centers on data theft and …
-
News & Resources
Australia Sanctions North Korea Hackers Supporting Weapons Program Development
by CSC Newsby CSC News 3 minutes readAustralia sanctions North Korea hackers in a new enforcement action targeting revenue that funds Pyongyang’s prohibited weapons programs. The measures designate individuals and entities tied to state backed …
-
News & Resources
Landfall Android Spyware Campaign Exploits Samsung Zero-Day Vulnerability
by CSC Newsby CSC News 3 minutes readAndroid spyware resurfaced in a campaign called Landfall that exploited a Samsung zero-day vulnerability to penetrate phones and siphon data. Researchers observed privilege escalation, stealthy persistence, and command …