Agregátor RSS
Baterie elektromobilů vydrží mnohem déle, než se čekalo před 10 lety. Obavy z jejich stárnutí ztrácejí smysl
Architektura GCN po 15 letech končí, CDNA 5 již vychází z RDNA
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts
Traveling enterprise employees beware: Think twice before you log onto that oh-so-convenient public Wi-Fi.
Since at least June, threat actors have been compromising “captive” Wi-Fi gateways and other portal appliances at hotels, conference centers, and similar shared venues to hijack users’ Microsoft 365 accounts, according to the ReliaQuest Threat Research team.
Once a threat actor controls a gateway, they can silently redirect a user’s traffic to their own infrastructure and steal their Microsoft 365 credentials without ever touching the user’s device, compromising endpoints, or sending phishing links or malicious attachments.
“The most dangerous element is that it operates at the network gateway, which sits beneath most of the trust assumptions users and devices make,” ReliaQuest told CSO Online. “It’s not necessarily an enterprise breach level event on its own, but it’s a very real risk to individual accounts.”
Exploiting a ‘fundamental trust’Domain Name System (DNS) poisoning, in which false data is injected to redirect regular web traffic to fraudulent domains, has previously been observed on small office routers, but attackers are now expanding the technique to higher-level targets, the ReliaQuest researchers explained in a blog post.
Attackers likely gain access to the gateways through weak or reused admin credentials in combination with exposed interfaces like Secure Shell (SSH), Simple Network Management Protocol (SNMP), and other web consoles, they pointed out.
Admin access to the gateway is all that malicious actors need, because devices are designed to inherently trust DNS, which translates domain names like login.microsoftonline[.]com into IP addresses to route them. Therefore, a single gateway compromise gives the attacker the ability to redirect traffic for every guest logging into the network, providing IP addresses it controls in response to DNS requests, rather than the legitimate ones, without touching a single endpoint.
“Captive portal appliances sit at the network perimeter for every guest on that network,” the researchers wrote. “Detection is inherently difficult because the attack happens gateway-side, outside the endpoint’s visibility.”
In the campaign tracked by ReliaQuest, four attacker-registered domains, m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com, were used for Microsoft-impersonation lures.
The compromised Wi-Fi gateways were discovered across multiple US cities as well as in India and Saudi Arabia, and impacted users were from companies in professional and financial services, legal, retail, health care, and energy, indicating that the method isn’t sector-specific.
“We’ve seen enough SharePoint exfiltration cases to know that a single popped account can cascade into meaningful data loss,” ReliaQuest noted. Meanwhile, for the network operators, there’s a “reputational dimension”; user compromise is a “serious trust and brand problem, regardless of how sophisticated’ the underlying attack is.”
Safe services, DNSSEC not enoughLocking network configurations to a ‘safe’ DNS provider such as Google (8.8.8.8), Cloudflare (1.1.1.1), or the cloud-based OpenDNS isn’t a sufficient tactic, because it doesn’t change the path that queries actually travel over, ReliaQuest contended.
By default, devices send DNS queries as unencrypted protocol traffic, and those packets still have to traverse the hotel’s network to reach Google, Cloudflare, or OpenDNS, the company explained. Since the gateway sits directly in that path, it can inspect, block, or redirect the query before it ever reaches the chosen resolver.
“Specifying a trusted DNS server changes the intended destination, not who controls the road to get there,” ReliaQuest noted.
Further, Domain Name System Security Extensions (DNSSECs), which use digital signatures and public-key cryptography, only “partially” address the problem. DNSSEC provides authentication and integrity for signed domains, which means a validating resolver can detect and reject forged or tampered responses.
“What it does not do is provide confidentiality or availability,” the company said. “It does not encrypt DNS traffic or stop an attacker from intercepting, blocking, or redirecting requests.”
So while DNSSEC can defeat certain response-forgery attacks against signed zones, an on-path gateway can still see queries, drop them, or force fallback behavior. However, this protection layer only helps when domains are actually signed, and then only when the client or resolver performs validation, which “many stub resolvers do not,” according to ReliaQuest.
Full-tunnel VPNs requiredTo combat the problem, enterprises should require all corporate devices to use a full-tunnel VPN for network connection. Controls should prevent internet access until a tunnel is active, ReliaQuest advised.
This will route all of a device’s traffic, including DNS, through an encrypted connection to a trusted VPN server before it travels anywhere else, the company explained, thus preventing local networks like hotel gateways from seeing or modifying DNS and internet traffic.
“In effect, it takes the untrusted network out of the trust equation,” ReliaQuest noted.
However, full-tunnel configuration is not the default for VPNs, because it comes with “real trade-offs,” the researchers noted: It adds cost, latency, and bandwidth demands, since every packet has to travel through company infrastructure. Thus, forcing all traffic through the corporate backbone is “not always practical” for distributed or bandwidth-heavy workforces.
Enterprises should also enforce conditional access in Entra ID to block device-code authentication flow, which has few legitimate use cases for most users in most environments, ReliaQuest noted.
Additional precautionsThe company also advised:
- Restricting Proxy Auto-Configuration (PAC) file retrieval to approved internal hosts;
- Disabling automatic Web Proxy Auto-Discovery (WPAD) via Group Policy to (this is often enabled by default in Windows);
- Deploying encrypted DNS such as DoH or DoT in strict mode as a “complement or alternative” to full-tunnel VPN. This is particularly important for organizations where always-on VPN is not feasible.
- Training employees to verify the URL and certificate of any page requesting credentials before entering them, particularly on public Wi-Fi networks.
Prevention is more important than detection here, ReliaQuest pointed out: while in tools like Microsoft Defender for Endpoint, ‘DnsConnectionInspected’ events showing queries to attacker-controlled domains are a primary endpoint-level signal, “by the time those events fire, the redirect has typically already occurred. In other words, endpoint telemetry confirms what happened more than it prevents it.”
This is exactly why methods like encrypted transport, Conditional Access, and WPAD and PAC hardening matter more than detection alone, the researchers emphasized.
This article originally appeared on CSOonline.
Samsung’s AI-powered glasses could be looking at your data
Now that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple, Google, Meta, and others, CISOs and IT leaders are again having to think through whether it makes sense to establish enterprise restrictions on such devices, given the likely data leakage and privacy and compliance issues.
And even if those tech leaders decide that such policies might make sense, the logistical hurdles to universally enforcing them outside the office are all but insurmountable.
For example, it is up to individual wearers to choose their device’s settings, making it difficult for IT policies around data acquisition and usage to be enforced. Worse, AI devices have a history of ignoring guardrails. That means that a setting that limits how data is used may not necessarily be obeyed.
One possible mitigating factor is that smart glasses typically have a light on the frame that activates when the device is recording, but there are also many easy ways for workers to defeat or cover up those lights to conceal their activities.
Enforcement is virtually impossibleHowever, said independent technology analyst Carmi Levy, “although some organizations have tried to physically ban smart glasses from their in-person and virtual workplaces, the sad reality for corporate technological gatekeepers is there is no way to completely keep any device out of the workplace.”
There is nothing stopping employees from wearing eyewear of any type, smart or not, he noted, “and attempting to do so might put employers on the wrong side of a disability lawsuit launched by a worker who needs prescription smart glasses to accommodate vision issues.”
As well, Jitesh Ubrani, an IDC director focusing on worldwide device trackers, pointed out that the biggest challenge in creating rules around usage of smart glasses is that the data leakage problem with devices is both not new and certainly not limited to glasses.
“The instinct to ban AI smart glasses outright is understandable, but it misses that the underlying risk isn’t new. A smartphone has been able to record a whiteboard, a screen, or a conversation for close to two decades,” he said. “What’s changed is the friction. Glasses make covert capture nearly effortless and far harder to notice because there’s no phone being visibly raised or pointed. That’s a real escalation in ease of misuse, but it’s a difference of degree rather than a fundamentally new capability.”
In fact, Ubrani argued, “where this gets hard for CISOs is enforcement. A ban on paper is easy to write. Enforcing it inside a corporate office is already difficult, since most current-generation devices, including Meta’s Ray-Bans, are visually indistinguishable from ordinary eyewear.”
And, he added, “enforcing it in a hybrid or work-from-home setting is close to impossible. IT has no practical way to confirm what someone is wearing on a home Zoom call, and even in-office detection options, like scanning for Bluetooth or BLE advertising signals tied to known manufacturer IDs, only catch devices that haven’t been reconfigured or that happen to be broadcasting at the time.”
Additional riskConnected glasses have a history going back decades, but enterprises didn’t take them seriously until this year.
But Anshel Sag, principal analyst at Moor Insights & Strategy, characterized the problem as more psychological than technological.
“People want to ban it because they don’t know how to handle it. But that just creates more problems than it solves. It’s a very kneejerk fear reaction,” Sag said. “We live in an era where cameras are everywhere.”
Meghan Hollis, a senior principal analyst for Gartner, agreed that the focus on smart glasses is misplaced, given that even headphones can today capture audio for translation and transcription. The change is not in the data capture, Hollis said, but the fact that it is adding video.
This creates additional risk, with the new capability brought into the corporate environment causing “a potential exposure for corporate intellectual property,” Hollis said.
One other often-overlooked issue is data sovereignty. Even if the glasses manufacturer agrees to store data only in specific countries, it could easily change that policy or simply switch third-party vendors.
“There could be export control issues, possibly violating regulatory controls in transmitting information,” Hollis noted.
However, Hollis said, threatening to punish workers if they are caught using unauthorized devices “is your last line of defense,” and that the best initial approach should not be enforcement, but education.
“You need to be educating your end-users, with constant reinforcement, telling them, ‘If you do this, here’s how you can harm the company and our clients/customers.’ Combine that with, ‘And if you do this, we will take action against you.’”
Tiered policies requiredHollis noted that the risk goes beyond an employee initially recording something they shouldn’t. Consider, for example, a technical meeting where an employee asks the rest of the attendees for permission to record the discussion. They agree and he starts to record.
At the end of the meeting, he leaves to return to his office, fully intending to turn off the recording function when he gets there. But on the way, he has a brief hallway meeting with an SVP who tells him, without warning, “FYI, but the board just decided to greenlight our hostile takeover of Smith Corp. We’ll explore the specifics at a 10 a.m. tomorrow. Have your team there.” The executive then walks off.
With the recording still running, that ultra-sensitive data has just been transmitted to the cloud.
IDC’s Ubrani pointed out that situations like this make smart glasses governance more challenging. “Enterprise IT and security leaders need to stop framing this as ‘ban versus allow,’ and instead build a tiered policy based on where the actual risk sits,” he said. “Boardrooms, R&D labs, and any space where trade secrets or regulated data are visible or discussed out loud deserve strict no-wearables rules, enforced the same way phone bans already are in those rooms.”
Open floor plans and general office space probably don’t need that level of restriction, he said, but meeting policies should require disclosure when a device capable of recording is present, similar to the way in which some companies already handle personal recording devices in sensitive briefings.
“Companies that try to write one blanket rule for every environment are going to find it’s either unenforceable or so restrictive it interferes with accessibility, since some employees rely on these devices as assistive technology,” he said.
However, Brian Jackson, a principal research director at Info-Tech Research Group, argued that enterprise CISOs and IT Directors need to take a far more strict position.
“Organizations should update their acceptable use policies for personal technology ASAP,” he said. “Look back about 15 years ago at how smartphones moved from consumer life into the workplace, and we may be at the beginning of a redefinition of BYOD here. But it needs to start with an extremely restrictive policy against the use of AI wearables and similar devices.”
He added, “organizations need to hold the line against making personal recordings in the workplace and maintain not only their compliance standards, but their workplace culture. This restriction cannot go as far as an outright ban; look at how Walt Disney World got caught up in a lawsuit after telling an employee she could not use Meta glasses. Still, this exception can be made narrow, and it should be made clear that other employees must be alerted when they are being recorded.”
This article originally appeared on CSOonline.
Hackers target US firms in FastJson RCE zero-day attacks
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Finanční zajištění nekončí důchodem. Často zapomínáme vyřešit věc, která pak výrazně ovlivní peněženku
Koupili jste družstevní byt s vadami? Náhradu po družstvu nechtějte
Tvorba interaktivních aplikací s GUI s využitím projektu GoGPU
Hrůzoptáci se dožili poslední doby ledové
Zdravotné riziká pri horúčavách, na ktoré sa vždy nemyslí
Poptávka po čínských pamětech je taková, že CXMT zdražila nad úroveň Samsungu
Microsoft unveils AI security tools it says outperform competing platforms
Microsoft is introducing new AI tools designed to help customers continuously streamline and automate the process of identifying and reducing their exposure to security risks.
The new tools come less than a week after OpenAI lost control of two of its security models when they infiltrated the servers of startup Hugging Face. The hack, Hugging Face added, involved “a swarm of tens of thousands of automated actions” that stole internal Hugging Face credentials. The OpenAI models achieved this feat by exploiting a zero-day flaw in Hugging Face’s data-processing pipeline to run malicious code that escalated the models’ access to the company’s high-value cloud and server clusters.
Microsoft’s announcements on Monday made no reference to the event, which OpenAI said was “unprecedented.” The company also didn’t say what would prevent the new tools from similarly going rogue.
Open Secure AI Alliance
ČSOB mění podmínky. Přidá okamžité SEPA platby, upraví Kate Coiny a služby pro děti
New Dysphoria DDoS botnet spreads to 200k devices worldwide
New Certighost PoC exploit lets attackers hijack Windows domains
Weak AI Regulation Could Be Worse Than None at All
A Cornell University study uses game theory to model how poorly designed AI regulation could backfire.
Governments around the world are racing to regulate AI before it becomes too deeply embedded in society. But new research suggests poorly designed rules could make AI systems less safe than having no regulation at all.
Regulatory disagreements in the US are leading to a patchwork of approaches as states take matters into their own hands. A key question is who should be responsible for the safety of AI products—the big tech companies building the underlying models or the firms that adapt them for a particular task, such as a customer service chatbot or an AI tutor.
Working this out is trickier than it looks. While it might seem logical to put the bulk of the burden on downstream companies directly serving these tools to customers, a new study in Proceedings of the National Academy of Sciences finds that could be worse than having no rules at all.
“There’s a free-riding behavior that occurs,” Benjamin Laufer from Cornell University, who led the research, said in a press release. “The regulation acts as a tool for the general provider to offload the safety burden onto the downstream specialist.”
The researchers’ analysis relied on a model based on game theory—a mathematical approach to studying decision making. It treated AI development as a two-step game, in which a “generalist” developer first invests in building a broadly capable AI model before a “specialist” adapts it for a specific domain and takes it to market.
In the game, a regulator sets a minimum safety standard for both players, and the models see this in advance. They then invest in both the performance and safety of their product, and the revenue is split between them. Investments in both get progressively higher, while the extra revenue each improvement brings in stays flat.
The problem, the researchers found, is that the generalist moves first and knows exactly what the specialist will be legally required to do afterwards. This creates problems when the generalist is set a low bar for safety, or none at all, and safety standards for the downstream specialist are also fairly weak.
In the absence of any rules, both firms invest in safety, because the model assumes a safer product earns more revenue. But if the specialist is forced to invest a certain amount into safety to meet regularity requirements, the generalist can cut its own spending and let the downstream firm close the gap.
That’s because the generalist’s revenue depends on the final safety level of the shipped product, not on its own contribution, so it can get a revenue boost from improved safety without paying for it from its own pocket. The specialist, for its part, has no reason to do more than the rule demands, so total safety settles at the legal minimum, which is below what would have occurred had there been no regulation at all.
On a more positive note, the researchers found that if safety levels on both the generalist and the specialist are set high enough, regulation can actually improve safety while leaving both companies more profitable than they were in an unregulated market.
“Appropriately designed AI regulation can make it possible for different firms involved in the AI development pipeline to collectively arrive at good outcomes for consumers, knowing that the regulation is designed to help each firm operate in a way that the others can more reasonably predict,” co-author Jon Kleinberg from Cornell University said in the press release.
However, the researchers’ model relies on the market setting a real price on safety. As the gap widens between what customers will pay for performance and what they’ll pay for safety, the range of circumstances in which weak rules backfire gets narrower.
The authors also note that the model’s two-player setup is a simplification of real AI supply chains where multiple competing specialists and base-model providers operate across different jurisdictions with different rules.
“People think of AI as a single object, but actually AI involves a very complicated set of stakeholders and actors that each have their own contributions to the technology,” said Laufer. “To regulate in a thoughtful way, we need to consider the whole supply chain, not just a single provider or entity.”
Still, the results suggest that taking an overly simplistic and light-handed approach to AI regulation may end up achieving the opposite of what law makers intend.
The post Weak AI Regulation Could Be Worse Than None at All appeared first on SingularityHub.
Hugging Face CEO wants transparency after OpenAI’s AI incident
Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test.
In a post on X, Delangue wrote that, among other things, he wants OpenAI to publish logs and traces from the autonomous AI agent so researchers can analyze what happened. He also called for better defensive tools and urged OpenAI to allocate $100 million worth of computing capacity to help the Hugging Face community develop stronger cybersecurity solutions.
“The first cyberattack by an autonomous AI agent is an unprecedented event. It deserves an unprecedented response,” Delangue wrote.
- « první
- ‹ předchozí
- …
- 49
- 50
- 51
- 52
- 53
- 54
- 55
- 56
- 57
- …
- následující ›
- poslední »



