Should we be worried about malicious use of AI language models?

More and more evidence is emerging into how large language models, such as Generative Pre-trained Transformer 3 (GPT-3) used by the likes of OpenAI’s advanced ChatGPT chatbot, seem to be highly vulnerable... Read more »

Microsoft fixes EoP zero-day on January Patch Tuesday

Security teams face a busy few days after Microsoft’s first monthly Patch Tuesday drop of 2023, which contains fixes for 98 distinct vulnerabilities, 11 of them rated as critical, and one zero-day... Read more »

Davos 2023: Pervasive cyber crime and cyber security gaps pose severe risk to organisations

The threat of widespread cyber crime and vulnerabilities in cyber security are among the most severe risks facing businesses, governments and the public over the next decade. Cyber attacks will disrupt critical... Read more »

What’s happening with quantum-safe cryptography?

Just weeks after US president Joe Biden signed into law the Quantum Computing Cybersecurity Preparedness Act, there are reports that Chinese researchers have cracked RSA 2048 bit encryption. Given that quantum computers... Read more »

Insurer Beazley introduces catastrophe bond to ease cyber risk

In a move that it hopes will safeguard its balance sheet from the increasing risks associated with cyber insurance, business insurance company Beazley is to launch a cyber catastrophe bond worth $45m... Read more »

JPMorgan ordered to face lawsuit over cyber attack on Ray-Ban maker

JPMorgan will face a lawsuit over whether it ignored the warning signs of a cyber attack on manufacturer Essilor, which saw $272m taken by criminals. Essilor, which manufactures Ray-Ban sunglasses, sued JPMorgan... Read more »

Vulnerable organisations to get free Cyber Essentials support

The UK’s National Cyber Security Centre (NCSC) is to fund free Cyber Essentials accreditation for some of the most vulnerable small organisations in the country, including charities and firms offering legal aid.... Read more »

Proposed digital fraud refund rules risk excluding many victims

Proposals by the Payment Systems Regulator (PSR) to establish a new fraud refund mechanism risks excluding many victims of authorised push payment (APP) fraud and other forms of digitally enabled fraud by... Read more »

Russia’s Turla falls back on old malware C2 domains to avoid detection

Organisations that fell victim to Andromeda, a commodity malware that dates back 12 years, seem to be at risk of compromise by the Moscow-backed advanced persistent threat (APT) group tracked variously as... Read more »

Vice Society cyber gang targeted multiple UK schools

The Vice Society ransomware crew has leaked a large volume of personally identifiable information (PII) on pupils and staff at 14 UK schools and universities, including children’s special educational needs (SEN) information,... Read more »